All posts by jzb

An update to the malicious crate notification policy (Rust Blog)

Post Syndicated from jzb original https://lwn.net/Articles/1059338/

Adam Harvey, on behalf of the crates.io
team
has published a blog
post
to inform users of a change in their practice of publishing
information about malicious Rust crates:

The crates.io team will no longer publish a blog post each time a
malicious crate is detected or reported. In the vast majority of cases
to date, these notifications have involved crates that have no
evidence of real world usage, and we feel that publishing these blog
posts is generating noise, rather than signal.

We will always publish a RustSec
advisory when a crate is removed for containing malware. You can
subscribe to the RustSec
advisory RSS feed
to receive updates.

Crates that contain malware and are seeing real usage or
exploitation will still get both a blog post and a RustSec
advisory. We may also notify via additional communication channels
(such as social media) if we feel it is warranted.

Security updates for Wednesday

Post Syndicated from jzb original https://lwn.net/Articles/1059333/

Security updates have been issued by Debian (ceph, gimp, gnutls28, and libpng1.6), Fedora (freerdp, libpng, libssh, mingw-libpng, mingw-libsoup, mingw-python3, pgadmin4, python-pillow, thunderbird, and vim), Mageia (postgresql15), Red Hat (python-urllib3), SUSE (cdi-apiserver-container, cdi-cloner-container, cdi- controller-container, cdi-importer-container, cdi-operator-container, cdi- uploadproxy-container, cdi-uploadserver-container, cont, frr, gpg2, kubernetes, kubernetes-old, libsodium, libsoup-2_4-1, libssh, libtasn1, libxml2, nodejs22, openCryptoki, openssl-3, and python311-pip), and Ubuntu (frr, linux-aws, linux-aws-6.8, linux-gkeop, linux-nvidia, linux-nvidia-6.8, linux-oracle, linux-oracle-6.8, linux-aws-fips, linux-fips, linux-gcp-5.15, linux-kvm, linux-oracle, linux-oracle-5.15, linux-gcp-fips, linux-nvidia, linux-nvidia-tegra-igx, linux-oem-6.17, linux-realtime, linux-raspi-realtime, nova, and pillow).

[$] Do androids dream of accepted pull requests?

Post Syndicated from jzb original https://lwn.net/Articles/1058643/

Various forms of tools, colloquially known as “AI”, have been
rapidly pervading all aspects of open-source development. Many
developers are embracing LLM tools for code creation and review. Some
project maintainers complain about suffering from a deluge of slop-laden pull
requests, as well as fabricated bug and security
reports
. Too many projects are reeling from scraperbot attacks that
effectively DDoS important infrastructure. But an AI bot flaming an
open-source maintainer was not on our bingo card for 2026; that seemed
a bit too far-fetched. However, it appears that is just what happened
recently after a project rejected a bot-driven pull request.

Plasma 6.6.0 released

Post Syndicated from jzb original https://lwn.net/Articles/1059187/

Version
6.6.0
of KDE’s Plasma desktop environment has been
released. Notable additions in this release include the ability to
create global themes for Plasma, an “extract text” feature in the Spectacle screenshot
utility, accessibility improvements, and a new on-screen keyboard. See
the changelog
for a full list of new features, enhancements, and bug fixes.

The release is dedicated to the memory of Björn Balazs, a KDE
contributor who passed away in September 2025. “Björn’s drive to
help people achieve the privacy and control over technology that he
believed they deserved is the stuff FLOSS legends are made of.
“

An update on upki

Post Syndicated from jzb original https://lwn.net/Articles/1059184/

In December 2025, Canonical announced a plan to
develop a universal Public Key Infrastructure called upki. Jon Seager has published
an update
about the project with instructions on trying it
out.

In the few weeks since we announced upki, the core revocation engine
has been established and is now functional, the CRLite mirroring tool
is working and a production deployment in Canonical’s datacentres is
ongoing. We’re now preparing for an alpha release and remain on track
for an opt-in preview for Ubuntu 26.04 LTS.

Security updates for Tuesday

Post Syndicated from jzb original https://lwn.net/Articles/1059176/

Security updates have been issued by AlmaLinux (gimp, go-toolset:rhel8, and golang), Debian (roundcube), Fedora (gnupg2, libpng, and rsync), Mageia (dcmtk and usbmuxd), Oracle (gcc-toolset-14-binutils, gimp, gnupg2, go-toolset:ol8, golang, kernel, and openssl), Slackware (libssh, lrzip, and mozilla), SUSE (abseil-cpp, chromium, curl, elemental-toolkit, elemental-operator, expat, freerdp, iperf, libnvidia-container, libsoup, libxml2, net-snmp, openCryptoki, openssl-3, patch, protobuf, python-urllib3, python-xmltodict, python311, screen, systemd, and util-linux), and Ubuntu (alsa-lib, gnutls28, and linux-aws, linux-oracle).

[$] Open source security in spite of AI

Post Syndicated from jzb original https://lwn.net/Articles/1058266/

The curl project has found AI-powered tools to be a mixed bag when
it comes to security reports. At FOSDEM 2026, curl creator and
lead developer Daniel Stenberg used his keynote session to discuss his
experience receiving a slew of low-quality reports and, at the same
time, realizing that large language model (LLM) tools can sometimes
find flaws that other tools have missed.

Security updates for Monday

Post Syndicated from jzb original https://lwn.net/Articles/1058989/

Security updates have been issued by Debian (chromium, pdns-recursor, python-django, and wireshark), Fedora (gnutls, linux-sgx, mingw-expat, nginx, nginx-mod-brotli, nginx-mod-fancyindex, nginx-mod-headers-more, nginx-mod-modsecurity, nginx-mod-naxsi, nginx-mod-vts, p11-kit, python-aiohttp, vim, and xen), Red Hat (kernel, kernel-rt, python-s3transfer, python-urllib3, and resource-agents), SUSE (aaa_base, abseil-cpp, build-20260202, cargo-auditable, cargo-c, chromedriver, cockpit, cockpit-packages, cockpit-subscriptions, curl, elemental-toolkit, elemental-operator, gnome-remote-desktop, go1.24, go1.25, gpg2, haproxy, himmelblau, htmldoc, ImageMagick, iperf, java-1_8_0-openjdk, kernel, krb5, kubevirt, libowncloudsync-devel, libpng16-16, libsodium, libsoup, libsoup2, micropython, net-snmp, opencryptoki, openjfx, openssl1, ovmf, postgresql14, postgresql15, postgresql16, protobuf, python-aiohttp, python-brotli, python-maturin, python-pip, python-urllib3, python310, python311, python-rpm-macros, python311-cryptography, python314, screen, systemd, u-boot, util-linux, and vim), and Ubuntu (dotnet8, dotnet10, expat, freerdp2, freerdp3, and python-aiohttp).

New delegation for Debian’s data protection team

Post Syndicated from jzb original https://lwn.net/Articles/1058663/

Debian Project Leader (DPL) Andreas Tille has announced
a new delegation for Debian’s data projection team:

Following the end of the previous delegation, Debian was left
without an active Data Protection team. This situation has
understandably drawn external attention and highlighted the importance
of having a clearly identified point of contact for data protection
matters within the project.

I am therefore very pleased to announce that new volunteers have
stepped forward, allowing us to re-establish the Debian Data
Protection team with a fresh delegation.

Tille had put out a call for
volunteers
in January after all previous members of the team had
stepped down. He has appointed Aigars Mahinovs, Andrew M.A. Cater,
Bart Martens, Emmanuel Arias, Gunnar Wolf, Kiran S Kunjumon, and Salvo
Tomaselli as the new members of the team. The team provides a central
coordination and advisory function around Debian’s data handling,
retention, dealing with deletion requests, and more.

[$] Open-source mapping for disaster response

Post Syndicated from jzb original https://lwn.net/Articles/1057691/

At FOSDEM 2026 Petya
Kangalova, a senior tech partnership and engagement manager for the Humanitarian OpenStreetMap
Team
(HOT) spoke about how
the project helps people map their surroundings to assist in
disaster response and humanitarian aid. The project has
developed a stack of technology to help volunteers collectively map an
area and add in local knowledge metadata. “One of the core things
that we believe is that when we speak about disaster response or
people having access to data is that they really need accessible
technology that’s free and open for anyone to use
.”

Security updates for Friday

Post Syndicated from jzb original https://lwn.net/Articles/1058642/

Security updates have been issued by AlmaLinux (firefox, gcc-toolset-14-binutils, nodejs:20, nodejs:22, nodejs:24, php:7.4, and python3.12), Debian (haproxy, nginx, postgresql-15, and postgresql-17), Fedora (libssh), Oracle (glib2, libsoup, nodejs:20, nodejs:22, and php:7.4), SUSE (assimp, gnutls, helm, kernel, kubevirt, virt-api-container, virt-controller-container, virt-exportproxy-container, virt-exportserver-container, virt-handler-container, virt-launcher-container, virt-libguestfs-t, libmunge2, libsodium, libsoup, micropython, munge, openCryptoki, python-azure-core, rust-keylime, rustup, sccache, snpguest, tcpreplay, xorg-x11-server, xrdp, and zabbix), and Ubuntu (dnsdist, dotnet8, dotnet9, dotnet10, haproxy, libpng1.6, linux-aws-5.15, linux-azure, linux-azure-fips, linux-oracle, linux-oracle-5.4, munge, nginx, and node-dottie).

Debian DFSG Team announces new dashboard and queue processes

Post Syndicated from jzb original https://lwn.net/Articles/1058480/

Reinhard Tartler of Debian’s new DFSG,
Licensing & New Packages Team
, or simply “DFSG Team”, has announced
that the team is now operational and is deploying new tooling to
improve the NEW queue experience for Debian developers and
maintainers.

Our primary and immediate goal is simple: get the queue down.

We are currently settling in and refining our processes to ensure
stability and consistency. While our focus right now is on clearing
the backlog, our long-term vision is to enable all Debian Developers
to meaningfully contribute to DFSG reviewing activities, distributing
the workload and knowledge more effectively across the project.

The announcement includes information on the new dashboard for
packages in the NEW queue
, the rationale for the new tooling, and
an introduction to the members of the team.

Security updates for Thursday

Post Syndicated from jzb original https://lwn.net/Articles/1058473/

Security updates have been issued by AlmaLinux (brotli, git-lfs, image-builder, kernel, keylime, libsoup3, and pcs), Fedora (chromium, gnutls, osslsigncode, and p11-kit), Mageia (golang, libpng, thunderbird, and xrdp), Red Hat (git-lfs, go-toolset:rhel8, golang, golang-github-openprinting-ipp-usb, osbuild-composer, and toolbox), Slackware (gnutls and libpng), SUSE (apptainer, cockpit, cockpit-packages, cockpit-subscriptions, freerdp2, gimp, glib2, go, go1.24, go1.25, gpg2, ImageMagick, java-1_8_0-openjdk, kernel, keylime-config, keylime-ima-policy, lemon, libp11-kit0, libsoup, libsoup-2_4-1, libxml2, libxml2-16, munge, nodejs20, nvidia-modprobe.cuda, nvidia-open-driver-G06-signed, nvidia-persistenced.cuda, openQA, orthanc, gdcm, orthanc-authorization,, python-brotlipy, python-Django, python-maturin, python-pyasn1, python-urllib3, python-wheel, python313-wheel, qemu, rust-keylime, sqlite3, uriparser, wicked2nm, and xrdp), and Ubuntu (libtasn1-6, libwebsockets, libxmltok, linux, linux-aws, linux-gcp, linux-gke, linux-gkeop, linux-hwe-5.15, linux-ibm, linux-ibm-5.15, linux-lowlatency, linux-lowlatency-hwe-5.15, linux, linux-raspi, linux, linux-raspi, linux-realtime, linux-aws, linux-aws-6.8, linux-gcp, linux-gcp-6.8, linux-ibm,
linux-ibm-6.8, linux-lowlatency-hwe-6.8, linux-aws-5.15, linux-gcp-5.15, linux-nvidia-tegra-igx, linux-oracle-5.15,
linux-xilinx-zynqmp, linux-aws-fips, linux-fips, linux-gcp-fips, linux-gcp, linux-gcp-6.8, linux-gcp-fips, linux-intel-iot-realtime, linux-realtime, linux-nvidia-tegra, linux-nvidia-tegra-5.15, linux-realtime-6.8, linux-xilinx-zynqmp, and python-multipart).

[$] Evolving Git for the next decade

Post Syndicated from jzb original https://lwn.net/Articles/1057561/

Git is ubiquitous; in the last two decades, the version-control
system has truly achieved world domination. Almost every developer
uses it and the vast majority of open-source projects are hosted in
Git repositories. That does not mean, however, that it is
perfect. Patrick Steinhardt used his main-track session at FOSDEM 2026
to discuss some of its shortcomings and how they are being
addressed to prepare Git for the next decade.

postmarketOS FOSDEM 2026 and hackathon recap

Post Syndicated from jzb original https://lwn.net/Articles/1058285/

The postmarketOS project
has published
a recap from FOSDEM 2026, including the FOSS on
Mobile devroom
, and a summary of its post-FOSDEM
hackathon
. This includes decisions on governance and the project’s
AI policy:

AI policy: our current AI
policy
does not state that we forbid the use of generative AI in
postmarketOS, so far this document just lists why we think it is a bad
idea and misaligned with the project values. We discussed this and
will soon change it (via merge request) to clearly state that we don’t
want generative AI to be used in the project. It was also noted that
currently the policy is too long, it would make sense to split it into
the actual policy and still keep, but separate the reasoning from
it.

[…] Power delegation and teams: in over two
hours we discussed how to move forward with [postmarketOS change
request] PMCR 0008 to organize
ourselves better, and how it fits with soon having a legal entity. We
figured that we need to rename “The Board” (which is currently for
financial oversight) to “Financial Team”, as we will soon have a new
board for the legal entity. In the end our idea was to have the new
board refer to an “assembly” for all important decisions, and this
“assembly” would just be all Trusted Contributors in postmarketOS. The
Core Contributors team would be dissolved in favor of having several
topic-specific teams (a lot of which we already have, such as the
infra team). This way we would have a very flat decision
structure. The PMCR will be updated soon and discussed further
there. Casey
also asked on fedi for further feedback and got a lot of input.

Other topics include reaching out to resellers to sell phones with
postmarketOS preinstalled, security, and more.

Security updates for Wednesday

Post Syndicated from jzb original https://lwn.net/Articles/1058265/

Security updates have been issued by Debian (kernel, linux-6.1, munge, and tcpflow), Fedora (accel-ppp, atuin, babl, bustle, endless-sky, envision, ettercap, fapolicy-analyzer, firefox, glycin, gnome-settings-daemon, go-fdo-client, greenboot-rs, greetd, helix, hwdata, keylime-agent-rust, kiwi, libdrm, maturin, mirrorlist-server, ntpd-rs, ogr2osm, open-vm-tools, perl-App-Cme, perl-Net-RDAP, perl-rdapper, polymake, python-requests-ratelimiter, python-tqdm, rust-add-determinism, rust-afterburn, rust-ambient-id, rust-app-store-connect, rust-bat, rust-below, rust-btrd, rust-busd, rust-bytes, rust-cargo-c, rust-cargo-deny, rust-coreos-installer, rust-crypto-auditing-agent, rust-crypto-auditing-client, rust-crypto-auditing-event-broker, rust-crypto-auditing-log-parser, rust-dua-cli, rust-eif_build, rust-git-delta, rust-git-interactive-rebase-tool, rust-git2, rust-gst-plugin-dav1d, rust-gst-plugin-reqwest, rust-heatseeker, rust-ingredients, rust-jsonwebtoken, rust-lsd, rust-monitord, rust-monitord-exporter, rust-muvm, rust-nu, rust-num-conv, rust-onefetch, rust-oo7-cli, rust-pleaser, rust-pore, rust-pretty-git-prompt, rust-procs, rust-rbspy, rust-rbw, rust-rd-agent, rust-rd-hashd, rust-redlib, rust-resctl-bench, rust-resctl-demo, rust-routinator, rust-sccache, rust-scx_layered, rust-scx_rustland, rust-scx_rusty, rust-sequoia-chameleon-gnupg, rust-sequoia-keystore-server, rust-sequoia-octopus-librnp, rust-sequoia-sq, rust-sevctl, rust-shadow-rs, rust-sigul-pesign-bridge, rust-speakersafetyd, rust-tealdeer, rust-time, rust-time-core, rust-time-macros, rust-tokei, rust-weezl, rust-wiremix, rust-ybaas, rustup, sad, strawberry, systemd, tbtools, transmission, trustedqsl, tuigreet, uv, and vdr-extrecmenung), Oracle (brotli, git-lfs, java-1.8.0-openjdk, kernel, libsoup, libsoup3, nodejs:24, python3.12, and thunderbird), Red Hat (fence-agents, python-urllib3, python3.11-urllib3, python3.12-urllib3, and resource-agents), SUSE (avahi, cups, freerdp, golang-github-prometheus-prometheus, java-11-openjdk, java-17-openjdk, libsoup2, libxml2, and python-pip), and Ubuntu (expat, glib2.0, and imagemagick).