All posts by jzb

Changes to Kubernetes Slack (Kubernetes Contributors blog)

Post Syndicated from jzb original https://lwn.net/Articles/1025634/

The Kubernetes project has announced
that it will be losing its “special status” with the Slack communication platform and will be
downgraded to the free tier in a matter of days:

On Friday, June 20, we will be subject to the feature
limitations of free Slack
. The primary ones which will affect us
will be only retaining 90 days of history, and having to disable
several apps and workflows which we are currently using. The Slack
Admin team will do their best to manage these limitations.

The project has a FAQ
covering the change, its impacts, and more. The CNCF projects staff
has proposed
a move to the Discord service as
the best option to handle the more than 200,000 users and thousands of
posts per day from the Kubernetes community. The Kubernetes Steering
Committee will be making its decision “in the next few weeks“.

Radicle Desktop released

Post Syndicated from jzb original https://lwn.net/Articles/1025405/

The Radicle peer-to-peer code
collaboration project has released Radicle
Desktop
: a graphical interface designed to simplify more complex
parts of using Radicle such as issue management and patch reviews.

Radicle Desktop is not trying to replace your terminal, IDE, or code
editor – you already have your preferred tools for code browsing. It
won’t replace our existing app.radicle.xyz and search.radicle.xyz for
finding and exploring projects. It also doesn’t run a node for
you. Instead, it communicates with your existing Radicle node,
supporting your current workflow and encourages gradual adoption.

LWN covered Radicle
in March, 2024.

[$] FAIR package management for WordPress

Post Syndicated from jzb original https://lwn.net/Articles/1024486/

The last year has been a rocky one for the WordPress community. Matt
Mullenweg—WordPress co-founder and
CEO of WordPress hosting company Automattic—started a messy public spat with
WP Engine in September and
has proceeded to use his control of the project’s WordPress.org
infrastructure as weapons against the company, with the community
caught in the crossfire. It is not surprising, then, that on
June 6 a group of WordPress community participants announced the
Federated
and Independent Repositories Package Manager
(FAIR.pm) project. It
is designed to be a decentralized alternative to WordPress.org with a
goal of building “public digital infrastructure that is both
resilient and fair
“.

Security updates for Wednesday

Post Syndicated from jzb original https://lwn.net/Articles/1024939/

Security updates have been issued by AlmaLinux (glibc, grafana, kernel-rt, libjpeg-turbo, libxslt, and thunderbird), Debian (curl), Fedora (dtk6core, dtk6gui, dtk6log, dtk6widget, fcitx5-qt, gammaray, kddockwidgets, kwin, LabPlot, libqtxdg, nheko, plasma-integration, python-pyqt6, python-pyside6, qt-creator, roundcubemail, zeal, and a large number of qt6 packages), Oracle (firefox, glibc, grafana, kernel, libxslt, perl-FCGI, python3.12-cryptography, thunderbird, and zlib), SUSE (glib2, libjxl, libsoup2, nbdkit, nodejs22, perl-Crypt-OpenSSL-RSA, perl-YAML-LibYAML, python3, tomcat, and transfig), and Ubuntu (dotnet8, dotnet9 and samba).

Ubuntu 25.10 to drop support for X11 in GNOME

Post Syndicated from jzb original https://lwn.net/Articles/1024758/

Jean Baptiste Lallement, a member of Canonical’s desktop team, has
announced
that Ubuntu will drop support for GNOME on X11 in the 25.10
(“Questing Quokka”) release set for October. GNOME plans to remove
X11 support in GNOME 49, which is scheduled for September, so
Ubuntu is looking to be proactive:

Ubuntu 25.10 is the last interim release before our next LTS (Ubuntu
26.04). By moving now, we give developers and users a full cycle to
adapt before the next LTS, align with GNOME 49 and reduce
fragmentation while simplifying our support matrix heading into the
LTS.

Fedora decided in
early May
to drop X11 support for GNOME in Fedora 43, which
is also due in October.

[$] Improving Fedora’s documentation

Post Syndicated from jzb original https://lwn.net/Articles/1024259/

At Flock,
Fedora’s annual developer conference, held in Prague from June 5
to June 8, two members of the Fedora
documentation team
, Petr Bokoč and Peter Boy, led a
session
on the state of Fedora documentation. The pair covered a
brief history of the project’s documentation since the days of Fedora Core 1,
challenges the documentation team faces, as well as plans to improve Fedora’s
documentation by enticing more people to contribute.

[$] Nyxt: the Emacs-like web browser

Post Syndicated from jzb original https://lwn.net/Articles/1001773/

Nyxt is an unusual web
browser that tries to answer the question, “what if Emacs was a
good web browser?”. Nyxt is not an Emacs package, but a full
web browser written in Common Lisp and available under the BSD
three-clause license. Its target audience is developers who want a
browser that is keyboard-driven and extensible; Nyxt is also developed
for Linux first, rather than Linux being an afterthought or just a
sliver of its audience. The philosophy (as described in its FAQ)
behind the project is that users should be able to customize all of
the browser’s functionality.

Strategy 2028 update (Fedora Community Blog)

Post Syndicated from jzb original https://lwn.net/Articles/1023837/

Outgoing Fedora Project Leader Matthew Miller has posted an update
on Fedora’s high-level plan through 2028:

[Fedora] Council members identified potential Initiatives that we
believe are important to work on next. We came up with a list of
thirteen — which is way more than we can handle at once. We previously
set a limit of four Initiatives at a time. We decided to keep to that
rule, and are planning to launch four initiatives in the next months

The initiatives are: making Fedora releases block on accessibility
issues, experimenting with a “GitOps” workflow for packaging,
migrating from Pagure to Forgejo, and “making sure Fedora
Linux is ready for people who want to work on machine learning and AI
development
“.

Security updates for Wednesday

Post Syndicated from jzb original https://lwn.net/Articles/1023793/

Security updates have been issued by AlmaLinux (git, krb5, perl-CPAN, and rsync), Debian (tcpdf), Fedora (libmodsecurity, lua-http, microcode_ctl, and nextcloud), Red Hat (osbuild-composer), SUSE (389-ds, avahi, ca-certificates-mozilla, docker, expat, freetype2, glib2, gnuplot, gnutls, golang-github-teddysun-v2ray-plugin, golang-github-v2fly-v2ray-core, govulncheck-vulndb, helm, iperf, kernel, kernel-livepatch-MICRO-6-0_Update_2, kernel-livepatch-MICRO-6-0_Update_4, krb5, libarchive, libsoup, libsoup2, libtasn1, libX11, libxml2, libxslt, orc, podman, python-Jinja2, python-requests, python3-setuptools, python310, python311, python39, rubygem-rack, sslh, SUSE Manager Client Tools, SUSE Manager Client Tools and Salt Bundle, ucode-intel, util-linux, and wget), and Ubuntu (libvpx, linux, linux-aws, linux-aws-hwe, linux-gcp, linux-gcp-4.15, linux-hwe, linux-kvm, linux-oracle, linux, linux-aws, linux-azure, linux-gcp, linux-gke, linux-gkeop, linux-ibm, linux-intel-iotg, linux-kvm, linux-lowlatency, linux-nvidia-tegra, linux-oracle, linux, linux-aws, linux-kvm, linux-aws, linux-lts-xenial, linux-aws-fips, linux-azure-fips, linux-fips, linux-gcp-fips, linux-aws-fips, linux-gcp-fips, linux-azure-fde, linux-fips, and linux-intel-iot-realtime, linux-realtime).

[$] OpenH264 induces headaches for Fedora

Post Syndicated from jzb original https://lwn.net/Articles/1023088/

Software patents and workarounds for them are, once again,
causing headaches for open-source projects and users. This time
around, Fedora users have been vulnerable to a serious flaw in the OpenH264 library for
months—not for want of a fix, but because of the Rube
Goldberg machine
methodology of distributing the library to Fedora
users. The software is open source under a two-clause BSD license; the RPMs are built and
signed by Fedora, but the final product is distributed by Cisco, so
the company can pick up the tab for license fees. Unfortunately, a
breakdown in the process of handing RPMs to Cisco for distribution has
left Fedora users vulnerable, and inaction on Fedora’s part has left
users unaware that they are at risk.

[$] Out of Pocket and into the wallabag

Post Syndicated from jzb original https://lwn.net/Articles/1022399/

Mozilla has decided to throw in
the towel
on Pocket, a social-bookmarking
service that it acquired in 2017. This has left many users scrambling
for a replacement for Pocket before its shutdown in July. One possible
option is wallabag, a
self-hostable, MIT-licensed project for saving web content for later
reading. It can import saved data from services like Pocket, share
content on the web, export to various formats, and more. Even better,
it puts users in control of their data long-term.

Local vulnerabilities in Kea DHCP

Post Syndicated from jzb original https://lwn.net/Articles/1023093/

The SUSE Security Team has published a detailed
report
about security vulnerabilities it discovered in the Kea DHCP server suite from the Internet Systems Consortium
(ISC).

Since SUSE is also going to ship Kea DHCP in its products, we
performed a routine review of its code base. Even before checking the
network security of Kea, we stumbled over a range of local security
issues, among them a local root exploit which is possible in many
default installations of Kea on Linux and BSD distributions. […]

This report is based on Kea release 2.6.1. Any source code
references in this report relate to this version. Many systems still
ship older releases of Kea, but we believe they are all affected as
well by the issues described in this report.

The report details seven security issues including
local-privilege-escalation
and arbitrary file overwrite
vulnerabilities. Security fixes for the vulnerabilities have been
published in all of the currently supported release series of Kea: 2.4.2,
2.6.3,
and the 2.7.9
development release were all released on May 28. Kea has assigned CVE-2025-32801,
CVE-2025-32802,
and CVE-2025-32803 to the vulnerabilities. Note that some of the CVEs
cover multiple security flaws.

[$] Glibc project revisits infrastructure security

Post Syndicated from jzb original https://lwn.net/Articles/1021837/

The GNU C Library
(glibc) is the core C library for most Linux distributions, so it is a
crucial part of the open-source ecosystem—and an attractive
target for any attackers looking to carry out supply-chain
attacks. With that being the case, securing the project’s
infrastructure using industry best practices and improving the
security of its development practices are a frequent topic among glibc
developers. A recent discussion suggests that improvements are not
happening as quickly as some would like.