Packages changed: MicroOS-release (20260822 -> 20260825) baloo-widgets (26.04.3 -> 26.08.0) c-ares (1.34.6 -> 1.34.8) dolphin (26.04.3 -> 26.08.0) expat (2.8.1 -> 2.8.2) falkon (26.04.3 -> 26.08.0) ffmpegthumbs (26.04.3 -> 26.08.0) kaccounts-integration (26.04.3 -> 26.08.0) kaccounts-providers (26.04.3 -> 26.08.0) kate (26.04.3 -> 26.08.0) kdegraphics-mobipocket (26.04.3 -> 26.08.0) kdegraphics-thumbnailers (26.04.3 -> 26.08.0) kdenetwork-filesharing (26.04.3 -> 26.08.0) kdialog (26.04.3 -> 26.08.0) kernel-source (7.1.8 -> 7.2.0) kio-extras (26.04.3 -> 26.08.0) kio-gdrive (26.04.3 -> 26.08.0) konsole (26.04.3 -> 26.08.0) kpmcore (26.04.3 -> 26.08.0) kwalletmanager (26.04.3 -> 26.08.0) libevdev (1.13.6 -> 1.13.7) libkdcraw (26.04.3 -> 26.08.0) libkexiv2-qt6 (26.04.3 -> 26.08.0) libkgapi6 (26.04.3 -> 26.08.0) libopenmpt (0.8.7 -> 0.8.9) libsoup liburing (2.14 -> 2.15) libva (2.24.0 -> 2.24.1) libwacom (2.19.0 -> 2.19.1) llvm22 partitionmanager (26.04.3 -> 26.08.0) plasma6-browser-integration python-pyzmq (27.1.0 -> 27.2.0) python-tornado6 (6.5.7 -> 6.5.8) python-typing_extensions qrca (26.04.3 -> 26.08.0) signon-kwallet-extension (26.04.3 -> 26.08.0) ucode-intel (20260512 -> 20260812) === Details === ==== MicroOS-release ==== Version update (20260822 -> 20260825) Subpackages: MicroOS-release-appliance MicroOS-release-dvd - automatically generated by openSUSE-release-tools/pkglistgen ==== baloo-widgets ==== Version update (26.04.3 -> 26.08.0) - Update to 26.08.0 * New feature release * For more details please see: * https://kde.org/announcements/gear/26.08.0/ - No code change since 26.07.90 - Update to 26.07.90 * New feature release - No code change since 26.07.80 - Update to 26.07.80 * New feature release - Changes since 26.04.3: * Revert "filemetadatawidget: remove TextInteractionFlag" * tagsfileitemaction: fix crash on empty selection (kde#521325) * Remove FileMetaDataConfigWidget, deprecated since 23.08 * Use default DEFAULT_SEVERITY for logging * Remove pointless path check for indexed files * autotests: Fix leak of test widget * filemetadatawidget: remove TextInteractionFlag (kde#515867) ==== c-ares ==== Version update (1.34.6 -> 1.34.8) - c-ares 1.36.8: * CVE-2026-33630: Fixes use-after-free/double-free in c-ares query-completion handling, remotely triggerable via ares_getaddrinfo() over TCP (bsc#1270416) * CVE-2026-69184: CPU-exhaustion denial of service via unbounded DNS name compression pointer chains (bsc#1276290) * CVE-2026-69186: Memory-amplification denial of service via unvalidated DNS header record counts (bsc#1276291) - README.md: Add readme with build status For details, see https://c-ares.org/changelog.html ==== dolphin ==== Version update (26.04.3 -> 26.08.0) Subpackages: dolphin-part libdolphinvcs6 - Update to 26.08.0 * New feature release * For more details please see: * https://kde.org/announcements/gear/26.08.0/ - Changes since 26.07.90: * selectionmode: Show Delete action in trash (kde#523348) * dolphinview,dolphinviewactionhandler: split create folder into two actions * dolphinmainwindow: use base url fallback on slotSelectionChanged * tests: build dolphinquerytest only when HAVE_BALOO - Update to 26.07.90 * New feature release - Changes since 26.07.80: * Make inline-rename re-triggering robust and add a regression test (kde#514401) - Update to 26.07.80 * New feature release - Too many changes since 26.04.3, only listing bugfixes: * kitemviews: Draw icon overlays at a fixed size instead of baking them into the thumbnail (kde#498211) * Allow grouping by a separate criterion (kde#416134) * DolphinNavigatorsWidgetAction: Let non-Breeze QStyles style the non-toolbar navbar how they want (kde#518285) * KItemListWidget: Add pressedChanged (kde#508329) * viewproperties: respect saved properties for special folders with global view props enabled (kde#520089) * kfileitemmodelrolesupdater: fix directory item count for large folders (kde#509150) * dolphintabpage: drop swapActiveView in RightView close path (kde#520002) * userfeedback: prevent dangling pointer access in SettingsDataSource (kde#519876) * Restore session if this is the first instance (kde#464693) * Fix occasional UAF crashes in KConfig::sync() during exit * terminalpanel: allow refreshing the terminal location (kde#510557) * dolphincontextmenu: move "Empty Trash" to where you expect destructive actions to be (kde#518713) * dolphinmainwindow: use directly ShowMenubar action to change menuBar visibility (kde#492298) * kfileitemmodel: sort dotted numeric names naturally (kde#411707) * Refresh shortcut: Ignore repeat events (kde#514209) * KItemListWidget: Use primitives instead of custom painting (kde#508294) * kitemviews: Preserve inline rename when item scrolls out of view (kde#506884) * DolphinTabPage: Prevent re-entrant signal activation for slotViewActivated (kde#508554, kde#512011, kde#508405, kde#511076, kde#503576) * dolphinviewcontainer: Avoid adding an extra history entry when leaving search results (kde#515236) * animatedheightwidget: prevent viewport scrolling (kde#510469) * informationpanel: ignore gestures on media slider (kde#431307) * Fix incorrect app id for Kfind (kde#510370) * information/pixmapviewer: handle hdipi for animated images (kde#510829) * kitemviews: add "Folder Name" column to details view (kde#433937) * kitemlistview: when editing file name set anchored selection (kde#453262) ==== expat ==== Version update (2.8.1 -> 2.8.2) - update to 2.8.2 ( bsc#1267631, CVE-2026-50219, bsc#1268572, CVE-2026-56131, bsc#1268573, CVE-2026-56132, bsc#1275096, CVE-2026-56403, CVE-2026-56404, CVE-2026-56405, CVE-2026-56406, CVE-2026-56407, CVE-2026-56408, CVE-2026-56409, CVE-2026-56410, CVE-2026-56411, CVE-2026-56412): * #1246 CVE-2026-50219 -- Disallow calls to functions * `XML_GetBuffer`, `XML_Parse`, `XML_ParseBuffer`, * `XML_ParserFree`, `XML_ParserReset` to guard e.g. * Expat bindings from memory corruption; * #1267 CVE-2026-56131 -- Protect XML_ResumeParser from being called from a handler, plugging a hole in the fix to CVE-2026-50219 * #1272 CVE-2026-56132 -- Fix out-of-bound scaffolding index store in `doProlog` * #1229 #1232 CVE-2026-56403 -- Integer overflow in `storeAtts` * #1249 CVE-2026-56404 -- Integer overflow in `addBinding` * #1251 CVE-2026-56405 -- Integer overflow in `getAttributeId` * #1255 CVE-2026-56406 -- Integer overflow in `XML_ParseBuffer` * #1262 CVE-2026-56407 -- Integer overflow in `textLen` handling * #565 CVE-2026-56408 -- Integer overflow in `copyString` * #1259 CVE-2026-56409 -- xmlwf: Integer overflow in output path join * #1252 CVE-2026-56410 -- xmlwf: Integer overflow in `resolveSystemId` * #1263 CVE-2026-56411 -- xmlwf: Integer overflow in notation list allocation * #1278 CVE-2026-56412 -- Guard XML_TOK_DATA_CHARS handler calls in `doCdataSection`, plugging a hole in the fix to CVE-2026-50219 ==== falkon ==== Version update (26.04.3 -> 26.08.0) Subpackages: falkon-kde - Update to 26.08.0 * New feature release * For more details please see: * https://kde.org/announcements/gear/26.08.0/ - No code change since 26.07.90 - Update to 26.07.90 * New feature release - No code change since 26.07.80 - Update to 26.07.80 * New feature release - Changes since 26.04.3: * Add '[]' suffix to current instance window title * AdBlock: Use struct for AdBlockedRequest * Adblock: Specify resource type as MainFrame for popups * Adblock: Specify RequestType enum as a class * Add first-party url and increase adblock counter * Fix include order * Try to redo it with a bridge class * AdBlock: Add support for popup blocking * SuperMenu: Add SavePageAs action * Drop QTEST_DISABLE_KEYPAD_NAVIGATION from tests * TabManager: Remove handling of "State_Editing" * LocationCompleter: Allow numpad UP and DOWN arrows (kde#515403) * Always check return value when opening files * Check result of malloc * Do not allow contextless connects * Add missing context to the connects * Fix logic in createMenuAction to handle null QmlEngine case * Spell check prefs UI: expand list of languages instead of empty spacer * Remove duplicate call to qputenv() * adressProgressSettings -> addressProgressSettings * Correct spelling for "request" ==== ffmpegthumbs ==== Version update (26.04.3 -> 26.08.0) - Update to 26.08.0 * New feature release * For more details please see: * https://kde.org/announcements/gear/26.08.0/ - No code change since 26.07.90 - Update to 26.07.90 * New feature release - No code change since 26.07.80 - Update to 26.07.80 * New feature release - Changes since 26.04.3: * Fix OSS-Fuzz build ==== kaccounts-integration ==== Version update (26.04.3 -> 26.08.0) Subpackages: libkaccounts6-2 - Update to 26.08.0 * New feature release * For more details please see: * https://kde.org/announcements/gear/26.08.0/ - No code change since 26.07.90 - Update to 26.07.90 * New feature release - No code change since 26.07.80 - Update to 26.07.80 * New feature release - No code change since 26.04.3 ==== kaccounts-providers ==== Version update (26.04.3 -> 26.08.0) - Update to 26.08.0 * New feature release * For more details please see: * https://kde.org/announcements/gear/26.08.0/ - No code change since 26.07.90 - Update to 26.07.90 * New feature release - No code change since 26.07.80 - Update to 26.07.80 * New feature release - No code change since 26.04.3 ==== kate ==== Version update (26.04.3 -> 26.08.0) Subpackages: kate-plugins - Update to 26.08.0 * New feature release * For more details please see: * https://kde.org/announcements/gear/26.08.0/ - No code change since 26.07.90 - Update to 26.07.90 * New feature release - No code change since 26.07.80 - Update to 26.07.80 * New feature release - Too many changes since 26.04.3, only listing bugfixes: * only add processId if we are not sandboxed (kde#522883) * use Utils::absoluteUrl to have same normalization as via the KateDocManager (kde#519737) * improve handling of view change with search bars & Co. (kde#488164) * ensure we work on a local copy of the session config (kde#520168) * Add missing include (kde#520771) * ensure we hide the buttons in the view space if no tabs & nav bar there (alternative implementation) (kde#515133) * Use proper working directory when invoking git (kde#519685) * Fix middle click on tab doesn't work when close button disabled (kde#519325) * add filename to location copy (kde#519077) * try to add suffix that matches the document mime-type (kde#518537) * Fix possible out of bound read (kde#515975) * Check for index validity (kde#513191) * Fix possible out of bound read (kde#518496) * Remove custom prettier formatter (kde#517926) * add hint that missing char means ignore for spell checking (kde#517428) ==== kdegraphics-mobipocket ==== Version update (26.04.3 -> 26.08.0) - Update to 26.08.0 * New feature release * For more details please see: * https://kde.org/announcements/gear/26.08.0/ - Changes since 26.07.90: * DocumentPrivate::init: return early if dec is not valid * Protect against malformed header size - Update to 26.07.90 * New feature release - No code change since 26.07.80 - Update to 26.07.80 * New feature release - Changes since 26.04.3: * Don't check for size of parseEXTH twice * Harden bounds validation in DocumentPrivate::parseEXTH * Prevent integer underflow in DocumentPrivate::parseEXTH * ecm_generate_export_header: fix spurious } to USE_VERSION_HEADER arg ==== kdegraphics-thumbnailers ==== Version update (26.04.3 -> 26.08.0) - Update to 26.08.0 * New feature release * For more details please see: * https://kde.org/announcements/gear/26.08.0/ - No code change since 26.07.90 - Update to 26.07.90 * New feature release - No code change since 26.07.80 - Update to 26.07.80 * New feature release - Changes since 26.04.3: * Fix invalid memory access * Fix off by one access * Fix memory leak ==== kdenetwork-filesharing ==== Version update (26.04.3 -> 26.08.0) - Update to 26.08.0 * New feature release * For more details please see: * https://kde.org/announcements/gear/26.08.0/ - No code change since 26.07.90 - Update to 26.07.90 * New feature release - No code change since 26.07.80 - Update to 26.07.80 * New feature release - Changes since 26.04.3: * filepropertiesplugin: fix build without systemd * Handle service being an alias ==== kdialog ==== Version update (26.04.3 -> 26.08.0) - Update to 26.08.0 * New feature release * For more details please see: * https://kde.org/announcements/gear/26.08.0/ - No code change since 26.07.90 - Update to 26.07.90 * New feature release - No code change since 26.07.80 - Update to 26.07.80 * New feature release - No code change since 26.04.3 ==== kernel-source ==== Version update (7.1.8 -> 7.2.0) - update to 7.2 final - refresh configs - commit bf2526a - Refresh patches.suse/x86-alternative-exclude-text-poking-against-change_page_at.patch. - Refresh patches.suse/x86-mm-pat-acquire-init_mm-read-lock-on-attribute-change-t.patch. - Refresh patches.suse/x86-mm-pat-acquire-init_mm-write-lock-on-collapse-to-avoid.patch. - Refresh patches.suse/x86-mm-pat-allocate-split-page-tables-as-kernel-page-table.patch. - Refresh patches.suse/x86-mm-pat-fix-effective-RW-computation-in-lookup_address_.patch. - Refresh patches.suse/x86-alternative-dump-more-on-failure-in-__text_poke.patch. Update to v2 and refresh the debug patch on top. - commit d99c08e - Update patches.kernel.org/7.1.8-435-drm-amd-display-check-GRPH_FLIP-status-before-s.patch (bsc#1012628 bsc#1259453). - Update patches.kernel.org/7.1.8-436-drm-amd-display-Exit-idle-optimizations-before-.patch (bsc#1012628 bsc#1259453). Add a reference. - commit 067e5f8 ==== kio-extras ==== Version update (26.04.3 -> 26.08.0) Subpackages: libkioarchive6-6 trash_kcm - Update to 26.08.0 * New feature release * For more details please see: * https://kde.org/announcements/gear/26.08.0/ - Changes since 26.07.90: * kcmtrash.cpp: fix trash settings not detecting multiple mounts (kde#469598) - Update to 26.07.90 * New feature release - Changes since 26.07.80: * workers: fill UDSEntry one value type at a time * smb: fix DFS namespace authentication (kde#510902) - Update to 26.07.80 * New feature release - Changes since 26.04.3: * Fix incorrect display aspect ratio on SVG thumbnails with height > width * kio_thumbnail: poll wasKilled() in the directory thumbnail loops * Poll wasKilled() in worker transfer and listing loops * kio_filenamesearch: Skip content searches in /dev, /proc and /sys * Restore original "None" string in accordance with review comments * Update help tooltip in accordance with review comments * Web Search Keywords: Update tool tips and reduce duplication * Web Search Keywords: Show provider domain as tool tip for name column * Web Search Keywords: Allow the "Preferred" column to be sorted * Web Search Keywords: Add icons to action buttons * man: Accept a case insensitive or fuzzy match for the page name * sftp: avoid copying captured variables to pass to qScopeGuard * sftp: added an autotest suite using a paramiko-based sftp server * sftp: fixes for mime type detection and resuming files * proxykcm: fix auto configuration help button spacing * Use default DEFAULT_SEVERITY for logging * mtp: only handle portable media players that explicitly support MTP * D-Bus spec doesn't allow hyphens in object paths, exchanged for underscores, which are allowed (kde#516856) * Drop MinimumKeepSize from KCM * Drop MinimumKeepSize config from workers * filenamesearch: Treat any url with non empty path as invalid ==== kio-gdrive ==== Version update (26.04.3 -> 26.08.0) - Update to 26.08.0 * New feature release * For more details please see: * https://kde.org/announcements/gear/26.08.0/ - No code change since 26.07.90 - Update to 26.07.90 * New feature release - No code change since 26.07.80 - Update to 26.07.80 * New feature release - No code change since 26.04.3 ==== konsole ==== Version update (26.04.3 -> 26.08.0) Subpackages: konsole-part - Update to 26.08.0 * New feature release * For more details please see: * https://kde.org/announcements/gear/26.08.0/ - Changes since 26.07.90: * Drop bogus ZLIB dependency * ViewManager: Add container loading back to createSession * EscapeSequenceUrlHotSpot: add Copy & Open actions (kde#520743) * Fix kitty graphics byteCount overflow - Update to 26.07.90 * New feature release - Changes since 26.07.80: * Revert "Fix warnings from PreviewJob" - Update to 26.07.80 * New feature release - Too many changes since 26.04.3, only listing bugfixes: * ViewSplitter: make sure restoreAll and hideRecurse set container visibility (kde#520395) * Implement Kitty keyboard protocol (kde#519627) * EditProfileMousePage: reword the open links setting (kde#481115) * Add automatic profile switching based on system theme (kde#449235) * Prevent QTabBar from closing tabs on middle mouse clicks * we could arrive here with already destructed currentTerminalDisplay() (kde#519274) * Fix duplicated Copy entry in Configure Keyboard Shortcuts dialog (kde#513011) ==== kpmcore ==== Version update (26.04.3 -> 26.08.0) Subpackages: libkpmcore13 - Update to 26.08.0 * New feature release * For more details please see: * https://kde.org/announcements/gear/26.08.0/ - Changes since 26.07.90: * Rewrite NTFS updateBootSector code. (kde#523706) - Update to 26.07.90 * New feature release - No code change since 26.07.80 - Update to 26.07.80 * New feature release - Changes since 26.04.3: * kpmcore: list Qt6::Widgets in public interface, for public QWidget classes * Drop duplicated listing of one fs header * Add take ownership operation * Allow chown in external command whitelist * partwidget: ensure dark text on filesystem color * Change LUKS2 default sector size to 4096 considering most of user devices (SSDs and HDDs operate in 4K sectors). ==== kwalletmanager ==== Version update (26.04.3 -> 26.08.0) - Update to 26.08.0 * New feature release * For more details please see: * https://kde.org/announcements/gear/26.08.0/ - Changes since 26.07.90: * Disable UI for access control when unavailable - Update to 26.07.90 * New feature release - No code change since 26.07.80 - Update to 26.07.80 * New feature release - Changes since 26.04.3: * kwalletconfig.json: fix BugReportUrl * Bump KF_MIN_VERSION to 6.13 * Set a sensible default window size on first launch ==== libevdev ==== Version update (1.13.6 -> 1.13.7) - update to 1.13.7: * Refuse devices with more than 256 slots * Fix off-by-one in slot_value() bounds check * include: sync with kernel 7.0 ==== libkdcraw ==== Version update (26.04.3 -> 26.08.0) Subpackages: libKDcrawQt6-5 libkdcraw-qt6 - Update to 26.08.0 * New feature release * For more details please see: * https://kde.org/announcements/gear/26.08.0/ - No code change since 26.07.90 - Update to 26.07.90 * New feature release - No code change since 26.07.80 - Update to 26.07.80 * New feature release - Changes since 26.04.3: * Use KDE_INSTALL_TARGETS_DEFAULT_ARGS, KF_ one reserved for KF * Inline now one-value-only CMake variables * Remove no longer needed passing of namespace to KDcrawTargets export ==== libkexiv2-qt6 ==== Version update (26.04.3 -> 26.08.0) Subpackages: libKExiv2Qt6-0 - Update to 26.08.0 * New feature release * For more details please see: * https://kde.org/announcements/gear/26.08.0/ - No code change since 26.07.90 - Update to 26.07.90 * New feature release - No code change since 26.07.80 - Update to 26.07.80 * New feature release - Changes since 26.04.3: * Use KDE_INSTALL_TARGETS_DEFAULT_ARGS, KF_ one reserved for KF * Remove duplicated and unused OUTPUT_NAME arg for KExiv2 properties * Inline now one-value-only CMake variables * Remove no longer needed passing of namespace to KExiv2Targets export * Remove no longer used deprecation version ==== libkgapi6 ==== Version update (26.04.3 -> 26.08.0) Subpackages: libKPim6GAPICore6 libKPim6GAPIDrive6 libkgapi6-sasl2-kdexoauth2 - Update to 26.08.0 * New feature release * For more details please see: * https://kde.org/announcements/gear/26.08.0/ - No code change since 26.07.90 - Update to 26.07.90 * New feature release - No code change since 26.07.80 - Update to 26.07.80 * New feature release - Changes since 26.04.3: * CMAKE_CXX_SCAN_FOR_MODULES is already defined in ecm * Add method to set person from kcontacts addressee * Improve addressee edit details handling * Fix conversions for addresses * Add conversion test * Fix qstring comparisons * Fix wrong data insert that breaks recurrent event exceptions * Don't leak auth jobs * Delete network replies * Delete jobs created by unit tests * src/core/CMakeLists.txt - remove unused/uninitialized variables ==== libopenmpt ==== Version update (0.8.7 -> 0.8.9) - Update to version 0.8.9: * [Sec] Possible heap out-of-bounds write when loading SymMOD files containing WAV IMA ADPCM samples. See also https://github.com/OpenMPT/openmpt/security/advisories/GHSA-fxf7-wc37-p2cx * [Sec] Possible heap out-of-bounds read when loading custom tunings from MPTM files. - Charges in version 0.8.8: * IT: Due to an Impulse Tracker bug in Compatible Gxx mode, Envelope Carry may not resume the envelope from the correct position when there is both an instrument number and tone portamento next to a note. * XM: NitroTracker ignores instrument numbers where there is no note next to them, so they are no longer imported. Fixes various NitroTracker-made XMs such as notominous-a19.xm. * STK: Loosen heuristics a bit to allow STK.CRB-GreatMuzaxs6 to load. * GT2: Loading file versions 6 and later was broken since libopenmpt 0.8.0. ==== libsoup ==== - Fix runtime dependency of libsoup-tests, correctly requiring libsoup-3_0-0 - Add libsoup-CVE-2026-12548.patch: Fix heap out-of-bounds read flaw when parsing multipart HTTP messages. (bsc#1272196, glgo#GNOME/libsoup!524) - Add libsoup-tests subpackage with installed tests for gnome-desktop-testing-runner ==== liburing ==== Version update (2.14 -> 2.15) - exclude more tests: they fail on 7.2 so far - update to 2.15 * Classic BPF (cBPF) filter support. * New register helpers: io_uring_register_query() and io_uring_register_zcrx_ctrl() * Out-of-source build support. * Many other improvements, see: https://github.com/axboe/liburing/releases/tag/liburing-2.15 - disable some new tests for SLE 15 and 16 - keyring updated ==== libva ==== Version update (2.24.0 -> 2.24.1) Subpackages: libva-drm2 libva-wayland2 libva-x11-2 libva2 - update to 2.24.1: * va: include for getuid/getgid in secure_getenv fallback ==== libwacom ==== Version update (2.19.0 -> 2.19.1) Subpackages: libwacom-data libwacom9 - update to 2.19.1: * Build fixes for older systems and other arches ==== llvm22 ==== - Remove soft limit on open files. Depending on the number of jobs, linking can sometimes open more than 1024 files (boo#1261761). ==== partitionmanager ==== Version update (26.04.3 -> 26.08.0) - Update to 26.08.0 * New feature release * For more details please see: * https://kde.org/announcements/gear/26.08.0/ - Changes since 26.07.90: * Be a tiny bit more lenient with KPMcore versions - Update to 26.07.90 * New feature release - No code change since 26.07.80 - Update to 26.07.80 * New feature release - Changes since 26.04.3: * Add FreeBSD swap to kcfg file and UI config. (kde#522308) * Add "Take Ownership" action for mounted partitions * Updated description and button label for better UX (kde#504670) * Fixed position of "Label" Radio button (kde#514705) * Change the default preferred capacity to GiB ==== plasma6-browser-integration ==== - Place native-messaging-hosts files in /usr/lib in addition to /usr/lib64 (boo#1275979) ==== python-pyzmq ==== Version update (27.1.0 -> 27.2.0) - update to 27.2.0: * Lots of new type coverage. * Add `python3 -m zmq.curve_keygen` entrypoint for creating curve key pairs * Require Python 3.9 (drops Python 3.8) * Stop building wheels for free-threaded CPython 3.13 (cp313t) * Add wheels for free-threaded CPython 3.15 (cp315t) * Fix builds on Windows with Visual Studio 2026 * Fix builds with upcoming Cython release * Add more type coverage, fix some typing, typing compatibility with mypy 2.1 ==== python-tornado6 ==== Version update (6.5.7 -> 6.5.8) - update to 6.5.8 (bsc#1276210, bsc#1276211): * Form-encoded POST bodies are now subject to a limit of 1000 arguments by default. This prevents a CPU and memory denial of service attack. This limit can be overridden via the set_parse_body_config function. Thanks to Arpit Jain for reporting this issue. * Multipart parsing now rejects requests with an excessive number of parts earlier in the parsing process, limiting memory consumption. Thanks to afldl for reporting this issue. * The deprecated mixed-case arguments to RequestHandler.set_cookie now enforce the same restrictions on invalid characters that were introduced in Tornado 6.5.5 for the standard lowercase arguments. Thanks to sec-reex and Arpit Jain for reporting this issue. - drop python-tornado6-Fix-test_strip_headers_on_redirects.patch (upstream) ==== python-typing_extensions ==== - permit flit-core 4 ==== qrca ==== Version update (26.04.3 -> 26.08.0) - Update to 26.08.0 * New feature release * For more details please see: * https://kde.org/announcements/gear/26.08.0/ - No code change since 26.07.90 - Update to 26.07.90 * New feature release - No code change since 26.07.80 - Update to 26.07.80 * New feature release - Changes since 26.04.3: * Tidy Readme and update copyright year * Use Kirigami Addons from the Flatpak runtime * Use KDE_INSTALL_TARGETS_DEFAULT_ARGS, KF_ one reserved for KF * Fix Android build with Qt 6.11 ==== signon-kwallet-extension ==== Version update (26.04.3 -> 26.08.0) - Update to 26.08.0 * New feature release * For more details please see: * https://kde.org/announcements/gear/26.08.0/ - No code change since 26.07.90 - Update to 26.07.90 * New feature release - No code change since 26.07.80 - Update to 26.07.80 * New feature release - No code change since 26.04.3 ==== ucode-intel ==== Version update (20260512 -> 20260812) - Intel CPU Microcode was updated to the 20260812 release (bsc#1274785) - Removed MTL/06-aa-04/c0 due to functional issues observed when loading the MCU in some platforms. - Intel CPU Microcode was updated to the 20260811 release (bsc#1274785) - Security updates for INTEL-SA-01379 / CVE-2025-31936 - Security updates for INTEL-SA-01404 / CVE-2025-31938 - Security updates for INTEL-SA-01423 / CVE-2026-20917 - Security updates for INTEL-SA-01428 / CVE-2025-35973 - Security updates for INTEL-SA-01435 / CVE-2026-20716 - Security updates for INTEL-SA-01441 / CVE-2026-20760 - Security updates for INTEL-SA-01442 / CVE-2026-20713 / CVE-2026-20901 - Security updates for INTEL-SA-01443 / CVE-2026-20707 - Update for functional issues.