All posts by jzb

Debian Project Leader election underway

Post Syndicated from jzb original https://lwn.net/Articles/1063115/

Kurt Roeckx has announced
that Debian has moved to the campaigning period for the 2026 Debian
Project Leader (DPL) election. This year there is only one candidate,
Sruthi Chandran, so Debian voters will have a choice between Chandran
as DPL or “None of the above”. The campaign period will run through
April 3, and the voting period will run from April 4 to
April 17. Chandran has not yet posted a platform for the 2026
election, but her 2024
platform
is available on the Debian wiki.

Security updates for Monday

Post Syndicated from jzb original https://lwn.net/Articles/1063095/

Security updates have been issued by AlmaLinux (.NET 10.0, .NET 8.0, .NET 9.0, delve, git-lfs, gnutls, kernel, mingw-libpng, nfs-utils, opentelemetry-collector, python3.11, python3.12, python3.9, and vim), Debian (chromium, gimp, kernel, linux-6.1, and wireless-regdb), Fedora (alertmanager, chromium, freerdp, glab, golang-github-openprinting-ipp-usb, gst-devtools, gst-editing-services, gstreamer1, gstreamer1-doc, gstreamer1-plugin-libav, gstreamer1-plugins-bad-free, gstreamer1-plugins-base, gstreamer1-plugins-good, gstreamer1-plugins-ugly-free, gstreamer1-rtsp-server, insight, pcs, pgadmin4, python-gstreamer1, python3.10, python3.11, python3.6, qgis, SDL2_sound, SDL3_sound, systemd, and wireshark), Mageia (python-nltk, tomcat, and vim), Oracle (.NET 10.0, .NET 8.0, .NET 9.0, compat-openssl11, dtrace, python3.12, and vim), Red Hat (buildah, git-lfs, golang-github-openprinting-ipp-usb, opentelemetry-collector, podman, and runc), and SUSE (amazon-ssm-agent, busybox, clamav, firefox, giflib-devel-32bit, glibc, heroic-games-launcher, himmelblau, kubelogin, libpng15, libsoup, libsoup2, mingw32-binutils, mingw64-binutils, osc, obs-scm-bridge, python, python-black, python3, qemu, ruby4.0-rubygem-actioncable, ruby4.0-rubygem-actiontext, ruby4.0-rubygem-activejob, ruby4.0-rubygem-activemodel, tomcat, and tomcat10).

Security updates for Friday

Post Syndicated from jzb original https://lwn.net/Articles/1062775/

Security updates have been issued by Debian (chromium, kernel, and multipart), Fedora (dnf5, dr_libs, easyrpg-player, libmaxminddb, python3.12, strongswan, task, and udisks2), Oracle (.NET 10.0, .NET 8.0, .NET 9.0, gnutls, ImageMagick, kernel, libvpx, mingw-libpng, nginx:1.26, python3.11, and uek-kernel), Red Hat (delve, git-lfs, mingw-libpng, osbuild-composer, and rhc-worker-playbook), SUSE (cjson, curl, dnsdist, libsoup2, postgresql16, postgresql17, postgresql18, python-lxml_html_clean, python-pypdf2, python36, and thunderbird), and Ubuntu (dotnet8, dotnet9, dotnet10, freetype, golang-github-go-git-go-git, golang-golang-x-net, openssh, python-cryptography, sudo, and util-linux).

Security updates for Thursday

Post Syndicated from jzb original https://lwn.net/Articles/1062570/

Security updates have been issued by AlmaLinux (gimp, git-lfs, grafana-pcp, kernel, mysql8.4, nfs-utils, opentelemetry-collector, osbuild-composer, postgresql:16, and python3.12), Debian (imagemagick and netty), Fedora (dr_libs and python-lxml-html-clean), Slackware (libarchive and libxml2), SUSE (busybox, coredns, firefox, freerdp, ghostty, gnutls, go1.25, go1.26, GraphicsMagick, grype, helm, helm3, ImageMagick, perl-Compress-Raw-Zlib, python, python311-lxml_html_clean, python311-PyPDF2, tomcat11, and traefik), and Ubuntu (curl, gimp, and libpng).

[$] LWN.net Weekly Edition for March 12, 2026

Post Syndicated from jzb original https://lwn.net/Articles/1061465/

Inside this week’s LWN.net Weekly Edition:

  • Front: Chardet; Linux and age verification; Debian AI; Python lazy imports; Python type-system PEP; PQC HTTPS certificates; MGLRU; Fedora strategy.
  • Briefs: LLM vulnerability; NTP security; OpenWrt 25.12.0; SUSE sale; Buildroot 2026.02; digiKam 9.0.0; Rust 1.94.0; Quotes; …
  • Announcements: Newsletters, conferences, security updates, patches, and more.

[$] California’s Digital Age Assurance Act and Linux distributions

Post Syndicated from jzb original https://lwn.net/Articles/1062112/

A recently enacted law in California imposes an age-verification requirement on
operating-system providers beginning next year. The language of the Digital
Age Assurance Act
does not restrict its requirements to proprietary or commercial
operating systems; projects like Debian, FreeBSD, Fedora, and others seem to be on
the hook just as much as Apple or Microsoft. There is some hope that the law will be
amended, but there is no guarantee that it will be. This means that the developer
communities behind Linux distributions are having to discuss whether and how to
comply with the law with little time and even less legal guidance.

Introducing Moonforge: a Yocto-based Linux OS (Igalia Blog)

Post Syndicated from jzb original https://lwn.net/Articles/1062451/

Igalia has announced
the Moonforge Linux
distribution, based on OpenEmbedded
and Yocto.

Moonforge is an operating system framework for Linux devices that
simplifies the process of building and maintaining custom operating
systems.

It provides a curated collection of Yocto layers and configuration
files that help developers generate immutable, maintainable, and
easily updatable operating system images.

The goal is to offer the best possible developer experience for
teams building embedded Linux products. Moonforge handles the complex
aspects of operating system creation, such as system integration,
security, updates, and infrastructure, so developers can focus on
building and deploying their applications or devices.

Security updates for Wednesday

Post Syndicated from jzb original https://lwn.net/Articles/1062403/

Security updates have been issued by AlmaLinux (kernel, kernel-rt, libvpx, nfs-utils, nginx:1.26, osbuild-composer, postgresql, postgresql:12, postgresql:13, postgresql:15, postgresql:16, and python-pyasn1), Debian (imagemagick), Fedora (perl-Crypt-SysRandom-XS and systemd), Mageia (yt-dlp), Oracle (delve, gimp, git-lfs, go-rpm-macros, image-builder, kernel, libpng, libvpx, mysql8.4, nfs-utils, osbuild-composer, postgresql16, postgresql:12, postgresql:13, postgresql:15, postgresql:16, python-pyasn1, python3, python3.12, python3.9, and thunderbird), SUSE (python-aiohttp, python-maturin, python311-pymongo, rclone, and util-linux), and Ubuntu (linux-nvidia, linux-nvidia, linux-nvidia-6.8, linux-nvidia-lowlatency, and python-geopandas).

SUSE may be for sale, again

Post Syndicated from jzb original https://lwn.net/Articles/1062316/

Reuters is reporting
that private-equity firm EQT may be looking to sell SUSE:

EQT has hired investment bank Arma Partners to sound out a group of
private equity investors for a possible sale of the company, said the
sources, who requested anonymity to discuss confidential matters. The
​deliberations are at an early stage and there is no certainty that EQT
will ​proceed with a transaction, the sources said.

SUSE has traded hands a number of times over the years. Most
recently it was acquired by
EQT in 2018, was listed
on the Frankfurt Stock Exchange in 2021, and then taken
private
again by EQT in August 2023.

[$] Debian decides not to decide on AI-generated contributions

Post Syndicated from jzb original https://lwn.net/Articles/1061544/

Debian is the latest in an ever-growing list of projects to wrestle (again)
with the question of LLM-generated contributions; the latest debate stared in
mid-February, after
Lucas Nussbaum opened a
discussion
with a draft general resolution (GR) on whether Debian should
accept AI-assisted contributions. It seems to have, mostly, subsided without a GR
being put forward or any decisions being made, but the conversation was illuminating
nonetheless.

Security updates for Tuesday

Post Syndicated from jzb original https://lwn.net/Articles/1062260/

Security updates have been issued by Debian (imagemagick), Fedora (chromium, matrix-synapse, mingw-zlib, perl-Net-CIDR, polkit, and rust-pythonize), Mageia (coturn, firefox, and thunderbird), Oracle (delve, git-lfs, gnutls, go-rpm-macros, image-builder, kernel, libsoup, nfs-utils, nginx:1.24, osbuild-composer, postgresql, thunderbird, udisks2, and valkey), Red Hat (grafana, image-builder, and opentelemetry-collector), SUSE (c3p0 and mchange-commons, corepack24, go1, ImageMagick, python-Flask, tomcat, tomcat10, tomcat11, virtiofsd, and weblate), and Ubuntu (apache2 and yara).

digiKam 9.0.0 released

Post Syndicated from jzb original https://lwn.net/Articles/1062105/

Version
9.0.0
of the digiKam photo-management system has been
released. “This major version introduces groundbreaking
improvements in performance, usability, and workflow efficiency, with
a strong focus on modernizing the user interface, enhancing metadata
management, and expanding support for new camera models and file
formats.
” Some of the changes include a
new survey tool
, more advanced search and sorting options, as well
as bulk
editing of geolocation coordinates
.

Security updates for Monday

Post Syndicated from jzb original https://lwn.net/Articles/1062103/

Security updates have been issued by AlmaLinux (delve, git-lfs, and postgresql16), Fedora (cef, chezmoi, chromium, coturn, erlang-hex_core, firefox, gh, gimp, k9s, keylime, keylime-agent-rust, libsixel, microcode_ctl, nextcloud, nss, perl-Crypt-URandom, pgadmin4, php-zumba-json-serializer, postgresql16-anonymizer, prometheus, python-asyncmy, python3.10, python3.11, python3.9, staticcheck, valkey, and vim), SUSE (chromedriver, chromium, coredns, expat, freetype2-devel, gitea-tea, go1.24-openssl, go1.25-openssl, grpc, gstreamer-rtsp-server, gstreamer-plugins-ugly,, helm, jetty-annotations, kubeshark-cli, libaec, libblkid-devel, libsoup, libxml2, libxslt, NetworkManager-applet-strongswan, podman, python-joserfc, python-Markdown, python-pypdf2, python-tornado, python-uv, python311-Django, python311-joserfc, python311-nltk, roundcubemail, and valkey), and Ubuntu (python3.4, python3.5, python3.6, python3.7, python3.8, python3.9, python3.10, python3.11, python3.12, python3.13, python3.14).

[$] Fedora shares strategy updates and “weird research university” model

Post Syndicated from jzb original https://lwn.net/Articles/1060190/

In early February, members of the Fedora Council met in Tirana,
Albania to discuss and set the strategic direction for the Fedora Project. The
council has published
summaries
from its strategy summit, and Fedora Project Leader (FPL) Jed Spaleta,
as well as some of the council members, held a video meeting to discuss outcomes from
the summit on February 25. Topics included a plan to experiment with Open Collective to raise
funds for specific Fedora projects, tools to build image-based editions, and
more. Spaleta also explained his model for Fedora governance.

Security updates for Friday

Post Syndicated from jzb original https://lwn.net/Articles/1061738/

Security updates have been issued by Debian (chromium), Fedora (freerdp, libsixel, opensips, and yt-dlp), Mageia (python-django, rsync, and vim), Red Hat (go-rpm-macros and osbuild-composer), SUSE (7zip, assertj-core, autogen, c3p0, cockpit-machines, cockpit, cockpit-repos, containerized-data-importer, cpp-httplib, docker, docker-stable, expat, firefox, gnutls, go1.25-openssl, golang-github-prometheus-prometheus, haproxy, ImageMagick, incus, kernel, kubevirt, libsoup, libsoup2, mchange-commons, ocaml, openCryptoki, openvpn, php-composer2, postgresql14, postgresql15, python-Authlib, python-azure-core, python-nltk, python-urllib3_1, python311-Django4, python311-pillow-heif, python311-PyPDF2, python313, python313-Django6, qemu, rhino, roundcubemail, ruby4.0-rubygem-rack, sdbootutil, and wicked2nm), and Ubuntu (less, nss, python-bleach, qtbase-opensource-src, and zutty).

Buildroot 2026.02 released

Post Syndicated from jzb original https://lwn.net/Articles/1061543/

Peter Korsgaard has
announced version 2026.02
of Buildroot, a tool for generating
embedded Linux systems through cross-compilation. Notable changes
include added support for HPPA, use of the 6.19.x kernel headers by
default, better SBOM generation, and more.

Again a very active cycle with more than 1500 changes from 97 unique
contributors. I’m once again very happy to see so many “new” people next
to the “oldtimers”.

See the changelog
for full details. Thanks to Julien Olivain for pointing us to the announcement.

Security updates for Thursday

Post Syndicated from jzb original https://lwn.net/Articles/1061464/

Security updates have been issued by AlmaLinux (go-rpm-macros, libpng, thunderbird, udisks2, and valkey), Fedora (coturn, php-zumba-json-serializer, valkey, and yt-dlp), Red Hat (delve, go-rpm-macros, grafana, grafana-pcp, image-builder, osbuild-composer, and postgresql), Slackware (nvi), SUSE (firefox, glibc, haproxy, kernel, kubevirt, libsoup, libsoup2, libxslt, mozilla-nss, ocaml, python, python-Django, python-pip, util-linux, virtiofsd, wicked2nm,suse-migration-services,suse-migration- sle16-activation,SLES16-Migration,SLES16-SAP_Migration, and wireshark), and Ubuntu (gimp, linux-aws, linux-lts-xenial, linux-aws-fips, linux-azure, linux-azure-fips, linux-fips, nss, postgresql-14, postgresql-16, postgresql-17, and qemu).