Bug 1224165 - AUDIT-0: openSUSE Leap 15.6 Gold Master security audit
Summary: AUDIT-0: openSUSE Leap 15.6 Gold Master security audit
Status: RESOLVED FIXED
Alias: None
Product: openSUSE Distribution
Classification: openSUSE
Component: Security (show other bugs)
Version: Leap 15.6
Hardware: Other Other
: P5 - None : Normal (vote)
Target Milestone: ---
Assignee: Security Team bot
QA Contact: E-mail List
URL:
Whiteboard:
Keywords:
Depends on: 1215172 CVE-2024-23837 1225350 1225537
Blocks:
  Show dependency treegraph
 
Reported: 2024-05-13 11:50 UTC by Lubos Kocman
Modified: 2024-06-07 09:52 UTC (History)
1 user (show)

See Also:
Found By: ---
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Lubos Kocman 2024-05-13 11:50:54 UTC
Hello team

this is a request to audit openSUSE:Leap:15.6 GoldMaster code deadline is same as for SLES 15 SP6 GM (May 16th).

Our roadmap says:

Wed, May 16, 2022 Gold Master code submission deadline built should be within a week from there. However it's all driven by GMC acceptance for SUSE Linux Enterprise 15 SP6




The poo tracker: https://progress.opensuse.org/issues/131864

Leap 15.6 Schedule
https://en.opensuse.org/openSUSE:Roadmap#Schedule_for_openSUSE_Leap_15.6
Comment 1 Johannes Segitz 2024-05-17 13:04:53 UTC
sorry that wasn't enough time for us to schedule this. I usually do these, but I'll be on FTO the next two weeks, so I also can't do it now

SLES 15 SP6 was reviewed, so much should be covered by that.
Comment 2 Lubos Kocman 2024-05-20 11:22:07 UTC
Ack, it is what it is. We'll have to track this as rejected then.

Lubos
Comment 3 Andreas Stieger 2024-05-27 20:44:09 UTC
Could you maybe please run at least the following easy things:

* Packages that were added to openSUSE:Backports:SLE-15-SP6 but since dropped from Factory due to security issues: bug 1215172

* Packages that were updated in openSUSE:Backports:SLE-15-SP5:Update but not submitted to openSUSE:Backports:SLE-15-SP6 in the same or a newer version? Also containing known security issues like bug 1225350.

These are particularity dangerous as the issues are never re-evaluated again.
Comment 4 Andreas Stieger 2024-05-28 21:46:55 UTC
See bugs linked to bug 1224165. We should not ship security regressions.
Also bug 1225540 for version downgrades.
Comment 6 Lubos Kocman 2024-05-29 08:19:20 UTC
Wrong bug, sorry Stefan
Comment 7 Lubos Kocman 2024-05-30 10:48:20 UTC
Oky all issues should be addressed in the current build.

Thank you!
Comment 8 Lubos Kocman 2024-06-07 09:52:52 UTC
Closing