Oval Definition:oval:org.opensuse.security:def:66185
Revision Date:2020-12-01Version:1
Title:Security update for skopeo (Moderate)
Description:

This update for skopeo fixes the following issues:

Update to skopeo v0.1.41 (bsc#1165715):

- Bump github.com/containers/image/v5 from 5.2.0 to 5.2.1 - Bump gopkg.in/yaml.v2 from 2.2.7 to 2.2.8 - Bump github.com/containers/common from 0.0.7 to 0.1.4 - Remove the reference to openshift/api - vendor github.com/containers/image/v5@v5.2.0 - Manually update buildah to v1.13.1 - add specific authfile options to copy (and sync) command. - Bump github.com/containers/buildah from 1.11.6 to 1.12.0 - Add context to --encryption-key / --decryption-key processing failures - Bump github.com/containers/storage from 1.15.2 to 1.15.3 - Bump github.com/containers/buildah from 1.11.5 to 1.11.6 - remove direct reference on c/image/storage - Makefile: set GOBIN - Bump gopkg.in/yaml.v2 from 2.2.2 to 2.2.7 - Bump github.com/containers/storage from 1.15.1 to 1.15.2 - Introduce the sync command - openshift cluster: remove .docker directory on teardown - Bump github.com/containers/storage from 1.14.0 to 1.15.1 - document installation via apk on alpine - Fix typos in doc for image encryption - Image encryption/decryption support in skopeo - make vendor-in-container - Bump github.com/containers/buildah from 1.11.4 to 1.11.5 - Travis: use go v1.13 - Use a Windows Nano Server image instead of Server Core for multi-arch testing - Increase test timeout to 15 minutes - Run the test-system container without --net=host - Mount /run/systemd/journal/socket into test-system containers - Don't unnecessarily filter out vendor from (go list ./...) output - Use -mod=vendor in (go {list,test,vet}) - Bump github.com/containers/buildah from 1.8.4 to 1.11.4 - Bump github.com/urfave/cli from 1.20.0 to 1.22.1 - skopeo: drop support for ostree - Don't critically fail on a 403 when listing tags - Revert 'Temporarily work around auth.json location confusion' - Remove references to atomic - Remove references to storage.conf - Dockerfile: use golang-github-cpuguy83-go-md2man - bump version to v0.1.41-dev - systemtest: inspect container image different from current platform arch

Changes in v0.1.40:

- vendor containers/image v5.0.0 - copy: add a --all/-a flag - System tests: various fixes - Temporarily work around auth.json location confusion - systemtest: copy: docker->storage->oci-archive - systemtest/010-inspect.bats: require only PATH - systemtest: add simple env test in inspect.bats - bash completion: add comments to keep scattered options in sync - bash completion: use read -r instead of disabling SC2207 - bash completion: support --opt arg completion - bash-completion: use replacement instead of sed - bash completion: disable shellcheck SC2207 - bash completion: double-quote to avoid re-splitting - bash completions: use bash replacement instead of sed - bash completion: remove unused variable - bash-completions: split decl and assignment to avoid masking retvals - bash completion: double-quote fixes - bash completion: hard-set PROG=skopeo - bash completion: remove unused variable - bash completion: use `||` instead of `-o` - bash completion: rm eval on assigned variable - copy: add --dest-compress-format and --dest-compress-level - flag: add optionalIntValue - Makefile: use go proxy - inspect --raw: skip the NewImage() step - update OCI image-spec to 775207bd45b6cb8153ce218cc59351799217451f - inspect.go: inspect env variables - ostree: use both image and & storage buildtags



Update to skopeo v0.1.39 (bsc#1159530):

- inspect: add a --config flag - Add --no-creds flag to skopeo inspect - Add --quiet option to skopeo copy - New progress bars - Parallel Pulls and Pushes for major speed improvements - containers/image moved to a new progress-bar library to fix various issues related to overlapping bars and redundant entries. - enforce blocking of registries - Allow storage-multiple-manifests - When copying images and the output is not a tty (e.g., when piping to a file) print single lines instead of using progress bars. This avoids long and hard to parse output - man pages: add --dest-oci-accept-uncompressed-layers - completions: - Introduce transports completions - Fix bash completions when a option requires a argument - Use only spaces in indent - Fix completions with a global option - add --dest-oci-accept-uncompressed-layers
Family:unixClass:patch
Status:Reference(s):1133534
1141861
1141862
1146098
1146105
1146107
1149943
1149944
1159530
1165715
CVE-2019-10214
CVE-2019-9848
CVE-2019-9849
CVE-2019-9850
CVE-2019-9851
CVE-2019-9852
CVE-2019-9854
CVE-2019-9855
SUSE-SU-2019:2402-1
SUSE-SU-2020:0712-1
Platform(s):SUSE Linux Enterprise Module for Server Applications 15 SP1
SUSE Linux Enterprise Workstation Extension 15 SP1
Product(s):
Definition Synopsis
  • SUSE Linux Enterprise Module for Server Applications 15 SP1 is installed
  • AND skopeo-0.1.41-4.11 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Workstation Extension 15 SP1 is installed
  • AND Package Information
  • libreoffice-6.2.7.1-8.10 is installed
  • OR libreoffice-base-6.2.7.1-8.10 is installed
  • OR libreoffice-base-drivers-postgresql-6.2.7.1-8.10 is installed
  • OR libreoffice-branding-upstream-6.2.7.1-8.10 is installed
  • OR libreoffice-calc-6.2.7.1-8.10 is installed
  • OR libreoffice-calc-extensions-6.2.7.1-8.10 is installed
  • OR libreoffice-draw-6.2.7.1-8.10 is installed
  • OR libreoffice-filters-optional-6.2.7.1-8.10 is installed
  • OR libreoffice-gnome-6.2.7.1-8.10 is installed
  • OR libreoffice-gtk3-6.2.7.1-8.10 is installed
  • OR libreoffice-icon-themes-6.2.7.1-8.10 is installed
  • OR libreoffice-impress-6.2.7.1-8.10 is installed
  • OR libreoffice-l10n-af-6.2.7.1-8.10 is installed
  • OR libreoffice-l10n-ar-6.2.7.1-8.10 is installed
  • OR libreoffice-l10n-as-6.2.7.1-8.10 is installed
  • OR libreoffice-l10n-bg-6.2.7.1-8.10 is installed
  • OR libreoffice-l10n-bn-6.2.7.1-8.10 is installed
  • OR libreoffice-l10n-br-6.2.7.1-8.10 is installed
  • OR libreoffice-l10n-ca-6.2.7.1-8.10 is installed
  • OR libreoffice-l10n-cs-6.2.7.1-8.10 is installed
  • OR libreoffice-l10n-cy-6.2.7.1-8.10 is installed
  • OR libreoffice-l10n-da-6.2.7.1-8.10 is installed
  • OR libreoffice-l10n-de-6.2.7.1-8.10 is installed
  • OR libreoffice-l10n-dz-6.2.7.1-8.10 is installed
  • OR libreoffice-l10n-el-6.2.7.1-8.10 is installed
  • OR libreoffice-l10n-en-6.2.7.1-8.10 is installed
  • OR libreoffice-l10n-eo-6.2.7.1-8.10 is installed
  • OR libreoffice-l10n-es-6.2.7.1-8.10 is installed
  • OR libreoffice-l10n-et-6.2.7.1-8.10 is installed
  • OR libreoffice-l10n-eu-6.2.7.1-8.10 is installed
  • OR libreoffice-l10n-fa-6.2.7.1-8.10 is installed
  • OR libreoffice-l10n-fi-6.2.7.1-8.10 is installed
  • OR libreoffice-l10n-fr-6.2.7.1-8.10 is installed
  • OR libreoffice-l10n-ga-6.2.7.1-8.10 is installed
  • OR libreoffice-l10n-gl-6.2.7.1-8.10 is installed
  • OR libreoffice-l10n-gu-6.2.7.1-8.10 is installed
  • OR libreoffice-l10n-he-6.2.7.1-8.10 is installed
  • OR libreoffice-l10n-hi-6.2.7.1-8.10 is installed
  • OR libreoffice-l10n-hr-6.2.7.1-8.10 is installed
  • OR libreoffice-l10n-hu-6.2.7.1-8.10 is installed
  • OR libreoffice-l10n-it-6.2.7.1-8.10 is installed
  • OR libreoffice-l10n-ja-6.2.7.1-8.10 is installed
  • OR libreoffice-l10n-kk-6.2.7.1-8.10 is installed
  • OR libreoffice-l10n-kn-6.2.7.1-8.10 is installed
  • OR libreoffice-l10n-ko-6.2.7.1-8.10 is installed
  • OR libreoffice-l10n-lt-6.2.7.1-8.10 is installed
  • OR libreoffice-l10n-lv-6.2.7.1-8.10 is installed
  • OR libreoffice-l10n-mai-6.2.7.1-8.10 is installed
  • OR libreoffice-l10n-ml-6.2.7.1-8.10 is installed
  • OR libreoffice-l10n-mr-6.2.7.1-8.10 is installed
  • OR libreoffice-l10n-nb-6.2.7.1-8.10 is installed
  • OR libreoffice-l10n-nl-6.2.7.1-8.10 is installed
  • OR libreoffice-l10n-nn-6.2.7.1-8.10 is installed
  • OR libreoffice-l10n-nr-6.2.7.1-8.10 is installed
  • OR libreoffice-l10n-nso-6.2.7.1-8.10 is installed
  • OR libreoffice-l10n-or-6.2.7.1-8.10 is installed
  • OR libreoffice-l10n-pa-6.2.7.1-8.10 is installed
  • OR libreoffice-l10n-pl-6.2.7.1-8.10 is installed
  • OR libreoffice-l10n-pt_BR-6.2.7.1-8.10 is installed
  • OR libreoffice-l10n-pt_PT-6.2.7.1-8.10 is installed
  • OR libreoffice-l10n-ro-6.2.7.1-8.10 is installed
  • OR libreoffice-l10n-ru-6.2.7.1-8.10 is installed
  • OR libreoffice-l10n-si-6.2.7.1-8.10 is installed
  • OR libreoffice-l10n-sk-6.2.7.1-8.10 is installed
  • OR libreoffice-l10n-sl-6.2.7.1-8.10 is installed
  • OR libreoffice-l10n-sr-6.2.7.1-8.10 is installed
  • OR libreoffice-l10n-ss-6.2.7.1-8.10 is installed
  • OR libreoffice-l10n-st-6.2.7.1-8.10 is installed
  • OR libreoffice-l10n-sv-6.2.7.1-8.10 is installed
  • OR libreoffice-l10n-ta-6.2.7.1-8.10 is installed
  • OR libreoffice-l10n-te-6.2.7.1-8.10 is installed
  • OR libreoffice-l10n-th-6.2.7.1-8.10 is installed
  • OR libreoffice-l10n-tn-6.2.7.1-8.10 is installed
  • OR libreoffice-l10n-tr-6.2.7.1-8.10 is installed
  • OR libreoffice-l10n-ts-6.2.7.1-8.10 is installed
  • OR libreoffice-l10n-uk-6.2.7.1-8.10 is installed
  • OR libreoffice-l10n-ve-6.2.7.1-8.10 is installed
  • OR libreoffice-l10n-xh-6.2.7.1-8.10 is installed
  • OR libreoffice-l10n-zh_CN-6.2.7.1-8.10 is installed
  • OR libreoffice-l10n-zh_TW-6.2.7.1-8.10 is installed
  • OR libreoffice-l10n-zu-6.2.7.1-8.10 is installed
  • OR libreoffice-mailmerge-6.2.7.1-8.10 is installed
  • OR libreoffice-math-6.2.7.1-8.10 is installed
  • OR libreoffice-officebean-6.2.7.1-8.10 is installed
  • OR libreoffice-pyuno-6.2.7.1-8.10 is installed
  • OR libreoffice-writer-6.2.7.1-8.10 is installed
  • OR libreoffice-writer-extensions-6.2.7.1-8.10 is installed
  • OR libreofficekit-6.2.7.1-8.10 is installed
  • BACK