Skip to content

Weekly portage-stable package updates 2026-07-06#4131

Merged
tormath1 merged 261 commits into
mainfrom
buildbot/weekly-portage-stable-package-updates-2026-07-06
Jul 23, 2026
Merged

Weekly portage-stable package updates 2026-07-06#4131
tormath1 merged 261 commits into
mainfrom
buildbot/weekly-portage-stable-package-updates-2026-07-06

Conversation

@github-actions

@github-actions github-actions Bot commented Jul 6, 2026

Copy link
Copy Markdown

CI: https://jenkins.flatcar.org/job/container/job/sdk/109/cldsv/

Related PRs / interesting stuffs:

Fixes flatcar/Flatcar#2193
Fixes flatcar/Flatcar#2061
Fixes flatcar/Flatcar#2063
Fixes flatcar/Flatcar#2122
Fixes flatcar/Flatcar#2083
Fixes flatcar/Flatcar#2154
Fixes flatcar/Flatcar#2174
Fixes flatcar/Flatcar#2058
Fixes flatcar/Flatcar#1999
Fixes flatcar/Flatcar#2194
Fixes flatcar/Flatcar#1944
Fixes flatcar/Flatcar#2055
Fixes flatcar/Flatcar#2188
Fixes flatcar/Flatcar#2123
Fixes flatcar/Flatcar#2221

Partially addresses flatcar/Flatcar#2084
Partially addresses flatcar/Flatcar#2142

--

Copilot AI review requested due to automatic review settings July 6, 2026 08:43
@github-actions github-actions Bot added the main label Jul 6, 2026

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot can't review bot-authored pull requests automatically. A user with Copilot access can request a review manually.

Copilot AI review requested due to automatic review settings July 7, 2026 14:15
@tormath1
tormath1 force-pushed the buildbot/weekly-portage-stable-package-updates-2026-07-06 branch from 5bf9093 to e5d4a79 Compare July 7, 2026 14:15

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot wasn't able to review this pull request because it exceeds the maximum number of files (300). Try reducing the number of changed files and requesting a review from Copilot again.

Copilot AI review requested due to automatic review settings July 8, 2026 18:20
@krnowak
krnowak force-pushed the buildbot/weekly-portage-stable-package-updates-2026-07-06 branch from e5d4a79 to d7f3ff9 Compare July 8, 2026 18:20

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot wasn't able to review this pull request because it exceeds the maximum number of files (300). Try reducing the number of changed files and requesting a review from Copilot again.

Copilot AI review requested due to automatic review settings July 10, 2026 09:01

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot wasn't able to review this pull request because it exceeds the maximum number of files (300). Try reducing the number of changed files and requesting a review from Copilot again.

Copilot AI review requested due to automatic review settings July 10, 2026 09:39

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot wasn't able to review this pull request because it exceeds the maximum number of files (300). Try reducing the number of changed files and requesting a review from Copilot again.

Copilot AI review requested due to automatic review settings July 10, 2026 10:24

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot wasn't able to review this pull request because it exceeds the maximum number of files (300). Try reducing the number of changed files and requesting a review from Copilot again.

Copilot AI review requested due to automatic review settings July 10, 2026 16:23

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot wasn't able to review this pull request because it exceeds the maximum number of files (300). Try reducing the number of changed files and requesting a review from Copilot again.

krnowak and others added 13 commits July 23, 2026 15:26
Signed-off-by: Krzesimir Nowak <knowak@microsoft.com>
Signed-off-by: Krzesimir Nowak <knowak@microsoft.com>
Signed-off-by: Krzesimir Nowak <knowak@microsoft.com>
…sc/curl

Signed-off-by: Krzesimir Nowak <knowak@microsoft.com>
Signed-off-by: Krzesimir Nowak <knowak@microsoft.com>
Signed-off-by: Krzesimir Nowak <knowak@microsoft.com>
Signed-off-by: Krzesimir Nowak <knowak@microsoft.com>
Signed-off-by: Krzesimir Nowak <knowak@microsoft.com>
…x-* packages

Signed-off-by: Krzesimir Nowak <knowak@microsoft.com>
Signed-off-by: Krzesimir Nowak <knowak@microsoft.com>
This reverts commit 43b5ea1.

Signed-off-by: Mathieu Tortuyaux <mtortuyaux@microsoft.com>
Our dev-lang/rust build is configured for cross-compiling, while
dev-lang/rust-bin is not. The latter will be pulled in because of
RUST_NEEDS_LLVM=1, but we don't need LLVM for our build. The env change
avoids using rust-bin, but it cannot avoid pulling it in. The ebuild
change does that. It might get undone by the next resync, but we might
as well avoid it for a little while.

Signed-off-by: James Le Cuirot <jlecuirot@microsoft.com>
This has to be upstreamed.

Signed-off-by: Mathieu Tortuyaux <mtortuyaux@microsoft.com>
@tormath1
tormath1 force-pushed the buildbot/weekly-portage-stable-package-updates-2026-07-06 branch from e6155d5 to a73bfd7 Compare July 23, 2026 13:26
@tormath1
tormath1 marked this pull request as ready for review July 23, 2026 13:27
@tormath1
tormath1 requested a review from a team as a code owner July 23, 2026 13:27
Copilot AI review requested due to automatic review settings July 23, 2026 13:27

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot wasn't able to review this pull request because it exceeds the maximum number of files (300). Try reducing the number of changed files and requesting a review from Copilot again.

@dongsupark dongsupark left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks good, see below:

- nghttp2 ([CVE-2026-27135](https://www.cve.org/CVERecord?id=CVE-2026-27135))
- curl ([CVE-2026-4873](https://www.cve.org/CVERecord?id=CVE-2026-4873), [CVE-2026-5545](https://www.cve.org/CVERecord?id=CVE-2026-5545), [CVE-2026-5773](https://www.cve.org/CVERecord?id=CVE-2026-5773), [CVE-2026-6253](https://www.cve.org/CVERecord?id=CVE-2026-6253), [CVE-2026-6276](https://www.cve.org/CVERecord?id=CVE-2026-6276), [CVE-2026-6429](https://www.cve.org/CVERecord?id=CVE-2026-6429), [CVE-2026-7009](https://www.cve.org/CVERecord?id=CVE-2026-7009), [CVE-2026-7168](https://www.cve.org/CVERecord?id=CVE-2026-7168), [CVE-2026-8286](https://www.cve.org/CVERecord?id=CVE-2026-8286), [CVE-2026-8458](https://www.cve.org/CVERecord?id=CVE-2026-8458), [CVE-2026-8924](https://www.cve.org/CVERecord?id=CVE-2026-8924), [CVE-2026-8925](https://www.cve.org/CVERecord?id=CVE-2026-8925), [CVE-2026-8926](https://www.cve.org/CVERecord?id=CVE-2026-8926), [CVE-2026-8927](https://www.cve.org/CVERecord?id=CVE-2026-8927), [CVE-2026-8932](https://www.cve.org/CVERecord?id=CVE-2026-8932), [CVE-2026-9079](https://www.cve.org/CVERecord?id=CVE-2026-9079), [CVE-2026-9080](https://www.cve.org/CVERecord?id=CVE-2026-9080), [CVE-2026-9545](https://www.cve.org/CVERecord?id=CVE-2026-9545), [CVE-2026-9546](https://www.cve.org/CVERecord?id=CVE-2026-9546), [CVE-2026-9547](https://www.cve.org/CVERecord?id=CVE-2026-9547), [CVE-2026-10536](https://www.cve.org/CVERecord?id=CVE-2026-10536), [CVE-2026-11352](https://www.cve.org/CVERecord?id=CVE-2026-11352), [CVE-2026-11564](https://www.cve.org/CVERecord?id=CVE-2026-11564), [CVE-2026-11586](https://www.cve.org/CVERecord?id=CVE-2026-11586), [CVE-2026-11856](https://www.cve.org/CVERecord?id=CVE-2026-11856), [CVE-2026-12064](https://www.cve.org/CVERecord?id=CVE-2026-12064))
- sed ([CVE-2026-5958](https://www.cve.org/CVERecord?id=CVE-2026-5958))
- perl ([CVE-2026-4176](https://www.cve.org/CVERecord?id=CVE-2026-4176), [CVE-2026-13221](https://www.cve.org/CVERecord?id=CVE-2026-13221), [CVE-2026-57432](https://www.cve.org/CVERecord?id=CVE-2026-57432))

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

While perl 5.42.2 fixes CVE-2026-4176, it does not fix CVE-2026-13221, CVE-2026-57432.
I have also fixed flatcar/Flatcar#2084.

- base, dev: dracut ([111](https://github.com/dracut-ng/dracut/releases/tag/111))
- base, dev: ethtool ([7.0](https://git.kernel.org/pub/scm/network/ethtool/ethtool.git/plain/NEWS?h=v7.0))
- base, dev: expat ([2.8.2](https://blog.hartwork.org/posts/expat-2-8-2-released/))
- base, dev: gcc (15.3.0)

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

- base, dev: gcc ([15.3.0](https://gcc.gnu.org/gcc-15/changes.html))

([1.52.1](https://github.com/libuv/libuv/releases/tag/v1.52.1) (includes
[1.52.0](https://github.com/libuv/libuv/releases/tag/v1.52.0)))
- base, dev: mit-krb5 ([1.22.2](https://web.mit.edu/kerberos/krb5-1.22/krb5-1.22.2.html))
- base, dev: openldap (2.6.13)

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

- base, dev: openldap ([2.6.13](https://www.openldap.org/software/release/changes_lts.html))

- nghttp2 ([CVE-2026-27135](https://www.cve.org/CVERecord?id=CVE-2026-27135))
- curl ([CVE-2026-4873](https://www.cve.org/CVERecord?id=CVE-2026-4873), [CVE-2026-5545](https://www.cve.org/CVERecord?id=CVE-2026-5545), [CVE-2026-5773](https://www.cve.org/CVERecord?id=CVE-2026-5773), [CVE-2026-6253](https://www.cve.org/CVERecord?id=CVE-2026-6253), [CVE-2026-6276](https://www.cve.org/CVERecord?id=CVE-2026-6276), [CVE-2026-6429](https://www.cve.org/CVERecord?id=CVE-2026-6429), [CVE-2026-7009](https://www.cve.org/CVERecord?id=CVE-2026-7009), [CVE-2026-7168](https://www.cve.org/CVERecord?id=CVE-2026-7168), [CVE-2026-8286](https://www.cve.org/CVERecord?id=CVE-2026-8286), [CVE-2026-8458](https://www.cve.org/CVERecord?id=CVE-2026-8458), [CVE-2026-8924](https://www.cve.org/CVERecord?id=CVE-2026-8924), [CVE-2026-8925](https://www.cve.org/CVERecord?id=CVE-2026-8925), [CVE-2026-8926](https://www.cve.org/CVERecord?id=CVE-2026-8926), [CVE-2026-8927](https://www.cve.org/CVERecord?id=CVE-2026-8927), [CVE-2026-8932](https://www.cve.org/CVERecord?id=CVE-2026-8932), [CVE-2026-9079](https://www.cve.org/CVERecord?id=CVE-2026-9079), [CVE-2026-9080](https://www.cve.org/CVERecord?id=CVE-2026-9080), [CVE-2026-9545](https://www.cve.org/CVERecord?id=CVE-2026-9545), [CVE-2026-9546](https://www.cve.org/CVERecord?id=CVE-2026-9546), [CVE-2026-9547](https://www.cve.org/CVERecord?id=CVE-2026-9547), [CVE-2026-10536](https://www.cve.org/CVERecord?id=CVE-2026-10536), [CVE-2026-11352](https://www.cve.org/CVERecord?id=CVE-2026-11352), [CVE-2026-11564](https://www.cve.org/CVERecord?id=CVE-2026-11564), [CVE-2026-11586](https://www.cve.org/CVERecord?id=CVE-2026-11586), [CVE-2026-11856](https://www.cve.org/CVERecord?id=CVE-2026-11856), [CVE-2026-12064](https://www.cve.org/CVERecord?id=CVE-2026-12064))
- sed ([CVE-2026-5958](https://www.cve.org/CVERecord?id=CVE-2026-5958))
- perl ([CVE-2026-4176](https://www.cve.org/CVERecord?id=CVE-2026-4176), [CVE-2026-13221](https://www.cve.org/CVERecord?id=CVE-2026-13221), [CVE-2026-57432](https://www.cve.org/CVERecord?id=CVE-2026-57432))

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Another missing entry:

- docker ([CVE-2024-25621](https://www.cve.org/CVERecord?id=CVE-2024-25621), [CVE-2025-52881](https://www.cve.org/CVERecord?id=CVE-2025-52881))

tormath1 added 2 commits July 23, 2026 17:01
Signed-off-by: Mathieu Tortuyaux <mtortuyaux@microsoft.com>
It has to be upstreamed

Signed-off-by: Mathieu Tortuyaux <mtortuyaux@microsoft.com>
@tormath1
tormath1 force-pushed the buildbot/weekly-portage-stable-package-updates-2026-07-06 branch from a73bfd7 to 64690d9 Compare July 23, 2026 15:02
@tormath1

Copy link
Copy Markdown
Contributor

@tormath1
tormath1 merged commit 26eabab into main Jul 23, 2026
4 of 5 checks passed
@tormath1
tormath1 deleted the buildbot/weekly-portage-stable-package-updates-2026-07-06 branch July 23, 2026 15:08
@github-project-automation github-project-automation Bot moved this from ✅ Testing / in Review to Implemented in Flatcar tactical, release planning, and roadmap Jul 23, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

Development

Successfully merging this pull request may close these issues.

update: crun update: glib update: nghttp2 update: bind update: libmicrohttpd

5 participants