)]}'
{
  "log": [
    {
      "commit": "531be778bd4bfc98142f372d1f4136d8a0759d8d",
      "tree": "1633e3d770eca8b13867023ead803d63ccf0c87d",
      "parents": [
        "a0c5a20073a8899a29f6e27ab191a36c56196ebb"
      ],
      "author": {
        "name": "Bernd Kuhls",
        "email": "bernd@kuhls.net",
        "time": "Sun Sep 06 18:31:01 2026 +0200"
      },
      "committer": {
        "name": "Julien Olivain",
        "email": "ju.o@free.fr",
        "time": "Sun Sep 06 22:35:20 2026 +0200"
      },
      "message": "package/unbound: bump version to 1.26.0\n\nhttps://nlnetlabs.nl/projects/unbound/download/#unbound-1-26-0\n\nSigned-off-by: Bernd Kuhls \u003cbernd@kuhls.net\u003e\nSigned-off-by: Julien Olivain \u003cju.o@free.fr\u003e\n"
    },
    {
      "commit": "a0c5a20073a8899a29f6e27ab191a36c56196ebb",
      "tree": "678e56530c0324661016a736fa6bb563683dc7c1",
      "parents": [
        "5a2e1177f9349af33a32b00a90501cb76a17d394"
      ],
      "author": {
        "name": "Bernd Kuhls",
        "email": "bernd@kuhls.net",
        "time": "Fri Sep 04 20:44:57 2026 +0200"
      },
      "committer": {
        "name": "Julien Olivain",
        "email": "ju.o@free.fr",
        "time": "Sun Sep 06 21:44:25 2026 +0200"
      },
      "message": "package/squid: bump version to 7.7\n\nhttps://github.com/squid-cache/squid/blob/SQUID_7_7/ChangeLog\n\nSigned-off-by: Bernd Kuhls \u003cbernd@kuhls.net\u003e\nSigned-off-by: Julien Olivain \u003cju.o@free.fr\u003e\n"
    },
    {
      "commit": "5a2e1177f9349af33a32b00a90501cb76a17d394",
      "tree": "73dd33b929cecb61be488d69d3a59de2531a4bc2",
      "parents": [
        "d1fbea37a6e1f81f7117e4b1a238fdc581132d83"
      ],
      "author": {
        "name": "Bernd Kuhls",
        "email": "bernd@kuhls.net",
        "time": "Fri Sep 04 19:15:54 2026 +0200"
      },
      "committer": {
        "name": "Julien Olivain",
        "email": "ju.o@free.fr",
        "time": "Sun Sep 06 21:42:03 2026 +0200"
      },
      "message": "package/mutt: bump version to 2.4.1\n\nhttp://www.mutt.org/news.html\nhttp://www.mutt.org/relnotes/2.4/\nhttps://gitlab.com/muttmua/mutt/raw/stable/UPDATING\n\nSigned-off-by: Bernd Kuhls \u003cbernd@kuhls.net\u003e\nSigned-off-by: Julien Olivain \u003cju.o@free.fr\u003e\n"
    },
    {
      "commit": "d1fbea37a6e1f81f7117e4b1a238fdc581132d83",
      "tree": "8b64cd1750112fcabd94aaf06cffd33436859a30",
      "parents": [
        "e3c4a32d34bd70fbfba72f384d852d2603233c6c"
      ],
      "author": {
        "name": "Bernd Kuhls",
        "email": "bernd@kuhls.net",
        "time": "Fri Sep 04 18:48:40 2026 +0200"
      },
      "committer": {
        "name": "Julien Olivain",
        "email": "ju.o@free.fr",
        "time": "Sun Sep 06 21:38:17 2026 +0200"
      },
      "message": "package/libcap-ng: bump version to 0.9.5\n\nhttps://github.com/stevegrubb/libcap-ng/blob/v0.9.5/ChangeLog\n\nSigned-off-by: Bernd Kuhls \u003cbernd@kuhls.net\u003e\nSigned-off-by: Julien Olivain \u003cju.o@free.fr\u003e\n"
    },
    {
      "commit": "e3c4a32d34bd70fbfba72f384d852d2603233c6c",
      "tree": "66e267253d314f7873dfb0fbc21b3965b0e2a28d",
      "parents": [
        "612460dffda7566bce48ebcfb257357315ae73e7"
      ],
      "author": {
        "name": "Bernd Kuhls",
        "email": "bernd@kuhls.net",
        "time": "Fri Sep 04 18:33:04 2026 +0200"
      },
      "committer": {
        "name": "Julien Olivain",
        "email": "ju.o@free.fr",
        "time": "Sun Sep 06 21:28:41 2026 +0200"
      },
      "message": "package/hwdata: bump version to 0.411\n\nhttps://github.com/vcrhonek/hwdata/releases/tag/v0.411\nhttps://github.com/vcrhonek/hwdata/releases/tag/v0.410\n\nSigned-off-by: Bernd Kuhls \u003cbernd@kuhls.net\u003e\nSigned-off-by: Julien Olivain \u003cju.o@free.fr\u003e\n"
    },
    {
      "commit": "612460dffda7566bce48ebcfb257357315ae73e7",
      "tree": "cb297b1442b02acdfcf111b88f6448a1f0682ec2",
      "parents": [
        "f77c8cf14e51b9c2cbe472fa8a9a004315fc0a17"
      ],
      "author": {
        "name": "Bernd Kuhls",
        "email": "bernd@kuhls.net",
        "time": "Fri Sep 04 18:25:24 2026 +0200"
      },
      "committer": {
        "name": "Julien Olivain",
        "email": "ju.o@free.fr",
        "time": "Sun Sep 06 21:10:04 2026 +0200"
      },
      "message": "package/cmake: bump version to 4.4.3\n\nhttps://cmake.org/cmake/help/latest/release/4.4.html#id2\n\nSigned-off-by: Bernd Kuhls \u003cbernd@kuhls.net\u003e\nSigned-off-by: Julien Olivain \u003cju.o@free.fr\u003e\n"
    },
    {
      "commit": "f77c8cf14e51b9c2cbe472fa8a9a004315fc0a17",
      "tree": "faa9772b84a5d9a177869a901aced35216c64174",
      "parents": [
        "d9e8462570c5b4698254195083d05dbbb9807692"
      ],
      "author": {
        "name": "Bernd Kuhls",
        "email": "bernd@kuhls.net",
        "time": "Fri Sep 04 18:24:52 2026 +0200"
      },
      "committer": {
        "name": "Julien Olivain",
        "email": "ju.o@free.fr",
        "time": "Sun Sep 06 20:25:59 2026 +0200"
      },
      "message": "package/ccache: bump version to 4.14\n\nhttps://ccache.dev/releasenotes.html#_ccache_4_14\n\nSigned-off-by: Bernd Kuhls \u003cbernd@kuhls.net\u003e\nSigned-off-by: Julien Olivain \u003cju.o@free.fr\u003e\n"
    },
    {
      "commit": "d9e8462570c5b4698254195083d05dbbb9807692",
      "tree": "7afc350a6602b0f3010cd07cd48198bcb888a14f",
      "parents": [
        "490c380155e564fbe9cd346681f078da3f911ce1"
      ],
      "author": {
        "name": "Bernd Kuhls",
        "email": "bernd@kuhls.net",
        "time": "Sun Sep 06 11:09:48 2026 +0200"
      },
      "committer": {
        "name": "Julien Olivain",
        "email": "ju.o@free.fr",
        "time": "Sun Sep 06 18:55:00 2026 +0200"
      },
      "message": "package/openldap: bump version to 2.6.14\n\nhttps://github.com/openldap/openldap/blob/OPENLDAP_REL_ENG_2_6_14/CHANGES\nhttps://www.openldap.org/software/release/changes_lts.html\n\nRebased patch 0001.\n\nSigned-off-by: Bernd Kuhls \u003cbernd@kuhls.net\u003e\nSigned-off-by: Julien Olivain \u003cju.o@free.fr\u003e\n"
    },
    {
      "commit": "490c380155e564fbe9cd346681f078da3f911ce1",
      "tree": "9480e5e7b45facbb34d232778ff2a7ef883aaf78",
      "parents": [
        "d0718179694b407cb93f1603cdf845997dac7345"
      ],
      "author": {
        "name": "Torben Voltmer",
        "email": "mail@t-voltmer.net",
        "time": "Sun Sep 06 13:59:12 2026 +0000"
      },
      "committer": {
        "name": "Julien Olivain",
        "email": "ju.o@free.fr",
        "time": "Sun Sep 06 18:43:07 2026 +0200"
      },
      "message": "package/espflash: bump to version 4.5.0\n\nFor release notes, see:\nhttps://github.com/esp-rs/espflash/releases/tag/v4.1.0\nhttps://github.com/esp-rs/espflash/releases/tag/v4.2.0\nhttps://github.com/esp-rs/espflash/releases/tag/v4.3.0\nhttps://github.com/esp-rs/espflash/releases/tag/v4.4.0\nhttps://github.com/esp-rs/espflash/releases/tag/v4.5.0\n\nUpdate the Config.in help text to match the list of supported\ntarget devices, since espflash now also supports ESP32-C5 and ESP32-C61.\n\nSigned-off-by: Torben Voltmer \u003cmail@t-voltmer.net\u003e\nSigned-off-by: Julien Olivain \u003cju.o@free.fr\u003e\n"
    },
    {
      "commit": "d0718179694b407cb93f1603cdf845997dac7345",
      "tree": "26a51693baf460da05f18c768eb23dbad1c1a3da",
      "parents": [
        "a07a17d00ebf2a3fdf8bc8531c1716f74d18e456"
      ],
      "author": {
        "name": "Julien Olivain",
        "email": "ju.o@free.fr",
        "time": "Sun Sep 06 14:51:12 2026 +0200"
      },
      "committer": {
        "name": "Julien Olivain",
        "email": "ju.o@free.fr",
        "time": "Sun Sep 06 14:51:12 2026 +0200"
      },
      "message": "package/igh-ethercat: remove stale patch 0002\n\nigh-ethercat is failing while attempting to apply patches,\nwith error:\n\n    Applying 0002-Linux-6.19.0-support.patch using patch:\n    patching file devices/generic.c\n    Reversed (or previously applied) patch detected!  Skipping patch.\n    1 out of 1 hunk ignored -- saving rejects to file devices/generic.c.rej\n\nThe package patch 0002 was added in [1] in branch \"master\" while it\nwas in release client cycle. It was cherry-picked in [2] in branch\n\"next\" to apply the bump [3] (which removes the package patches 0001\nand 0002). When the branch \"next\" was merged in \"master\" in commit [4],\nthe patch 0002 was kept.\n\nThis commit removes this stale patch.\n\n[1] https://gitlab.com/buildroot.org/buildroot/-/commit/e4cf512c394f218cc71eb6b496ce4cb004c917bb\n[2] https://gitlab.com/buildroot.org/buildroot/-/commit/8a5fc970b48a432f5df3be1f1e7667095e712b3d\n[3] https://gitlab.com/buildroot.org/buildroot/-/commit/0a91e760f467a90b0f0acf00ec76aac011b241f1\n[4] https://gitlab.com/buildroot.org/buildroot/-/commit/5f2687795595c9af579312c1d504373ece56f43f\n\nFixes:\n- https://autobuild.buildroot.org/results/4f509f1f788c1b8dc5a840ffa2e435c5ed7b6eea/\n\nSigned-off-by: Julien Olivain \u003cju.o@free.fr\u003e\n"
    },
    {
      "commit": "a07a17d00ebf2a3fdf8bc8531c1716f74d18e456",
      "tree": "9f50cfca4f9c28de18873fed9ed7f25f16c31712",
      "parents": [
        "c70effd711ad70bfb0266328d24b9244359f74ff"
      ],
      "author": {
        "name": "Bernd Kuhls",
        "email": "bernd@kuhls.net",
        "time": "Sun Sep 06 12:32:57 2026 +0200"
      },
      "committer": {
        "name": "Julien Olivain",
        "email": "ju.o@free.fr",
        "time": "Sun Sep 06 13:56:45 2026 +0200"
      },
      "message": "package/binutils: remove support for binutils 2.44\n\nNow that binutils 2.47 has been introduced and binutils 2.46.1 made\nthe default version, drop the oldest supported version, binutils 2.44,\nkeeping only the 3 last versions supported: 2.45.1, 2.46.1 and 2.47.\n\nSigned-off-by: Bernd Kuhls \u003cbernd@kuhls.net\u003e\nSigned-off-by: Julien Olivain \u003cju.o@free.fr\u003e\n"
    },
    {
      "commit": "c70effd711ad70bfb0266328d24b9244359f74ff",
      "tree": "a2f354e580ede960fd0f4f3476a961222cc292ee",
      "parents": [
        "a4c3a288e64e5d0fd2578c4a21459842506a4035"
      ],
      "author": {
        "name": "Bernd Kuhls",
        "email": "bernd@kuhls.net",
        "time": "Sun Sep 06 12:32:56 2026 +0200"
      },
      "committer": {
        "name": "Julien Olivain",
        "email": "ju.o@free.fr",
        "time": "Sun Sep 06 13:56:45 2026 +0200"
      },
      "message": "package/binutils: make binutils 2.46.1 be the default\n\nNow that support for binutils 2.47 has been introduced, we follow our\npolicy of making binutils 2.46.1 the default version.\n\nSigned-off-by: Bernd Kuhls \u003cbernd@kuhls.net\u003e\nSigned-off-by: Julien Olivain \u003cju.o@free.fr\u003e\n"
    },
    {
      "commit": "a4c3a288e64e5d0fd2578c4a21459842506a4035",
      "tree": "429203c0304053c8543d41a6ed048c1ee4743790",
      "parents": [
        "f7e943bf42224dafb4d8e28f49de63f31a42ac80"
      ],
      "author": {
        "name": "Bernd Kuhls",
        "email": "bernd@kuhls.net",
        "time": "Sun Sep 06 12:32:55 2026 +0200"
      },
      "committer": {
        "name": "Julien Olivain",
        "email": "ju.o@free.fr",
        "time": "Sun Sep 06 13:56:45 2026 +0200"
      },
      "message": "package/binutils: add support for binutils 2.47\n\nhttps://sourceware.org/pipermail/binutils/2026-July/150449.html\n\nWe bring and rebased patches 0001 and 0002 that we carry for binutils\n2.46.1.\n\nSigned-off-by: Bernd Kuhls \u003cbernd@kuhls.net\u003e\nSigned-off-by: Julien Olivain \u003cju.o@free.fr\u003e\n"
    },
    {
      "commit": "f7e943bf42224dafb4d8e28f49de63f31a42ac80",
      "tree": "30f0b55c409118783f92dcdf7e6c721c59b34153",
      "parents": [
        "7e2c62319303f14a5cd835a2b1f21083dc536878"
      ],
      "author": {
        "name": "Bernd Kuhls",
        "email": "bernd@kuhls.net",
        "time": "Sun Sep 06 12:32:54 2026 +0200"
      },
      "committer": {
        "name": "Julien Olivain",
        "email": "ju.o@free.fr",
        "time": "Sun Sep 06 13:56:45 2026 +0200"
      },
      "message": "package/linux-headers: drop 7.1.x option\n\nThe 7.1.x series is now EOL upstream, so drop the linux-headers\noption and add legacy handling for it.\n\nSigned-off-by: Bernd Kuhls \u003cbernd@kuhls.net\u003e\nSigned-off-by: Julien Olivain \u003cju.o@free.fr\u003e\n"
    },
    {
      "commit": "7e2c62319303f14a5cd835a2b1f21083dc536878",
      "tree": "7acef23f57b32e0513124b761b3bbe825209ecfe",
      "parents": [
        "6528b3e3f86d08b473fc5eaa85575d4aeb3e9bad"
      ],
      "author": {
        "name": "Bernd Kuhls",
        "email": "bernd@kuhls.net",
        "time": "Sun Sep 06 12:32:53 2026 +0200"
      },
      "committer": {
        "name": "Julien Olivain",
        "email": "ju.o@free.fr",
        "time": "Sun Sep 06 13:56:35 2026 +0200"
      },
      "message": "linux: bump latest version to 7.2\n\nFor an overview of changes in 7.2, see:\nhttps://kernelnewbies.org/Linux_7.2\n\nSigned-off-by: Bernd Kuhls \u003cbernd@kuhls.net\u003e\n[Julien: rename \"7.1.13\" symlink to \"7.2.3\"]\nSigned-off-by: Julien Olivain \u003cju.o@free.fr\u003e\n"
    },
    {
      "commit": "6528b3e3f86d08b473fc5eaa85575d4aeb3e9bad",
      "tree": "8be178d9d6a1c0dd5adce8365352522a361f8e03",
      "parents": [
        "a1e25fe7051be4463ce58e492e2e0e183219d449"
      ],
      "author": {
        "name": "Bernd Kuhls",
        "email": "bernd@kuhls.net",
        "time": "Sun Sep 06 12:32:52 2026 +0200"
      },
      "committer": {
        "name": "Julien Olivain",
        "email": "ju.o@free.fr",
        "time": "Sun Sep 06 13:04:41 2026 +0200"
      },
      "message": "{toolchain, linux-headers}: add support for 7.2 headers\n\nSigned-off-by: Bernd Kuhls \u003cbernd@kuhls.net\u003e\nSigned-off-by: Julien Olivain \u003cju.o@free.fr\u003e\n"
    },
    {
      "commit": "a1e25fe7051be4463ce58e492e2e0e183219d449",
      "tree": "bb1dc5ed9a6adb55ec446e4f49a2f4a224b20b09",
      "parents": [
        "0838e968cb9e78d7ca5d1641f39655bc03a2be00"
      ],
      "author": {
        "name": "Bernd Kuhls",
        "email": "bernd@kuhls.net",
        "time": "Sun Sep 06 12:32:51 2026 +0200"
      },
      "committer": {
        "name": "Julien Olivain",
        "email": "ju.o@free.fr",
        "time": "Sun Sep 06 13:04:41 2026 +0200"
      },
      "message": "package/strace: bump version to 7.2\n\nhttps://github.com/strace/strace/releases/tag/v7.2\n\nSigned-off-by: Bernd Kuhls \u003cbernd@kuhls.net\u003e\nSigned-off-by: Julien Olivain \u003cju.o@free.fr\u003e\n"
    },
    {
      "commit": "0838e968cb9e78d7ca5d1641f39655bc03a2be00",
      "tree": "c4450b8e058ee61c4633791a0135b3ae813f2cc6",
      "parents": [
        "e55cb3108531b9a983ecdd607114f644150bf9af"
      ],
      "author": {
        "name": "Bernd Kuhls",
        "email": "bernd@kuhls.net",
        "time": "Sat Sep 05 14:09:22 2026 +0200"
      },
      "committer": {
        "name": "Julien Olivain",
        "email": "ju.o@free.fr",
        "time": "Sun Sep 06 12:18:36 2026 +0200"
      },
      "message": "package/{glibc, localedef}: security bump version to 2.44-40-g30950ce64\n\nFixes CVE-2026-18374:\nhttps://gitlab.com/gnutools/glibc/-/commit/0b4e41fc51e6aba6216a908961b49b0622b47fa0\n\nSigned-off-by: Bernd Kuhls \u003cbernd@kuhls.net\u003e\nSigned-off-by: Julien Olivain \u003cju.o@free.fr\u003e\n"
    },
    {
      "commit": "e55cb3108531b9a983ecdd607114f644150bf9af",
      "tree": "536898d60efa4c3921de1fb3f6c4d6de62ec62b2",
      "parents": [
        "d148168e209fe07660d75f5e56ea00cb3e5f269c"
      ],
      "author": {
        "name": "Bernd Kuhls",
        "email": "bernd@kuhls.net",
        "time": "Fri Sep 04 18:12:28 2026 +0200"
      },
      "committer": {
        "name": "Julien Olivain",
        "email": "ju.o@free.fr",
        "time": "Sun Sep 06 12:15:48 2026 +0200"
      },
      "message": "package/libde265: security bump version to 1.1.2\n\nhttps://github.com/strukturag/libde265/releases/tag/v1.1.2\n\nSecurity fixes:\n(CVE numbers will be added when assigned.)\n\nCVE-2026-XXXXX (GHSA-xp3h-6f5r-8cxp) Heap use-after-free and double free\n in multi-threaded (WPP) decoding. A crafted stream whose slice segments\n repeat or rewind their slice_segment_address within a picture re-ran\n CTB rows that were already marked finished, so the CABAC context handoff\n between rows was no longer ordered and the shared context table was\n released twice. Slice segments that do not follow the previous one in\n tile-scan order are now rejected with the new warning\n DE265_WARNING_SLICE_SEGMENT_ADDRESS_NOT_INCREASING, and the WPP row\n progress is reset for each slice segment. (medium)\n\nCVE-2026-XXXXX (GHSA-mm7m-v26f-wf8x) Heap use-after-free after\n de265_reset(): the pointer to the previous slice header was left\n dangling when the DPB was cleared, and a dependent slice pushed after\n the reset copied from freed memory. (medium)\n\nSigned-off-by: Bernd Kuhls \u003cbernd@kuhls.net\u003e\nSigned-off-by: Julien Olivain \u003cju.o@free.fr\u003e\n"
    },
    {
      "commit": "d148168e209fe07660d75f5e56ea00cb3e5f269c",
      "tree": "c27ffd8a5e789283330e33a1b2cd6667d0bbc16c",
      "parents": [
        "25b8142ef7b9e09ed7d273571ca61aa92888a39c"
      ],
      "author": {
        "name": "Bernd Kuhls",
        "email": "bernd@kuhls.net",
        "time": "Fri Sep 04 18:11:47 2026 +0200"
      },
      "committer": {
        "name": "Julien Olivain",
        "email": "ju.o@free.fr",
        "time": "Sun Sep 06 12:05:25 2026 +0200"
      },
      "message": "package/libheif: security bump version to 1.23.3\n\nhttps://github.com/strukturag/libheif/releases/tag/v1.23.3\n\nFixes the following CVEs:\n\n(CVE numbers will be added when assigned.)\n\nCVE-2026-XXXXX (GHSA-x8r2-mggj-j6wr) Heap buffer overflow (write) in the\n uncompressed (unci) mixed-interleave decoder when the two chroma\n components declare different bit depths. Both the written bytes and the\n overflow length are controlled by the file. (critical)\n\nCVE-2026-XXXXX (GHSA-8fmq-r4pf-7m57) Permanent decoder deadlock through\n a reference cycle between an image and its alpha auxiliary image. The\n alpha edge was not covered by the cycle guard and re-entered a held\n mutex. (high)\n\nCVE-2026-XXXXX (GHSA-w7mc-p8jc-p853) Heap out-of-bounds read in the\n YCbCr 4:2:0 to 16-bit interleaved RGB conversion when the chroma\n planes have a lower bit depth than luma. Heap memory could end up in\n the decoded image. YCbCr conversions with mismatched luma and chroma\n bit depths are now rejected. (high)\n\nCVE-2026-XXXXX (GHSA-4jqm-2x34-6f6r) Heap buffer overflow in the SVT-AV1\n encoder plugin when encoding a high-bit-depth alpha channel, and a\n double free on its send-picture error path. (high)\n\nCVE-2026-84451 (GHSA-hh47-fhqr-cj2r) Incomplete fix for\n GHSA-73p7-m7gg-w2jv: the tile range check of the unci decoder (without\n icef) could still overflow, allowing an out-of-bounds read. (medium)\n\nCVE-2026-XXXXX (GHSA-4h82-g446-83fm) Heap out-of-bounds read when\n converting odd-height 4:2:0 frames of an uncompressed (uncv) image\n sequence to RGB. (medium)\n\nCVE-2026-XXXXX (GHSA-9rj8-5mp5-26c9) Out-of-bounds read in the RGB to\n YCbCr identity-matrix color conversion when the R, G, and B planes\n have different bit depths. (medium)\n\nCVE-2026-84450 (GHSA-gh5q-69gg-c964) A clap property combined with an\n oversized ispe reached an assert() in the Fraction arithmetic and\n aborted the process (incomplete fix for GHSA-jc8f-p23p-5hjg). An error\n is returned instead. (medium)\n\n(GHSA-mw6f-29j3-76f4) Several smaller findings:\n heif_image_handle_get_depth_image_handle() and\n heif_image_handle_get_depth_image_representation_info() dereferenced a\n null pointer on files without a depth image; the TIFF input decoder of\n the example tools had an unbounded EXIF tag allocation and a division\n by zero on zero YCbCr subsampling; assert()s in the PNG input decoder\n are now error returns; integer overflow in the Go binding\u0027s\n ImageAccess.GetPlane(); heif-view now verifies the decoded frame size\n before display. (medium)\n\n(GHSA-8857-r8x5-7499) Undefined behavior (negative shift) in the HDR\n bit-depth up-conversion for target bit depths above 16. Such\n conversions are now rejected. (low)\n\nSigned-off-by: Bernd Kuhls \u003cbernd@kuhls.net\u003e\nSigned-off-by: Julien Olivain \u003cju.o@free.fr\u003e\n"
    },
    {
      "commit": "25b8142ef7b9e09ed7d273571ca61aa92888a39c",
      "tree": "6017a6e0742fb3354fdd9b2233968c302f62d330",
      "parents": [
        "edb18cf3f2df3d55aa216e0b1a6706539354cc76"
      ],
      "author": {
        "name": "Bernd Kuhls",
        "email": "bernd@kuhls.net",
        "time": "Fri Sep 04 17:49:40 2026 +0200"
      },
      "committer": {
        "name": "Julien Olivain",
        "email": "ju.o@free.fr",
        "time": "Sun Sep 06 12:00:27 2026 +0200"
      },
      "message": "package/openvpn: security bump version to 2.7.7\n\nhttps://github.com/OpenVPN/openvpn/blob/v2.7.7/Changes.rst\n\nFixes CVE-2026-84732, the other CVEs are Windows-only.\n\nSigned-off-by: Bernd Kuhls \u003cbernd@kuhls.net\u003e\nSigned-off-by: Julien Olivain \u003cju.o@free.fr\u003e\n"
    },
    {
      "commit": "edb18cf3f2df3d55aa216e0b1a6706539354cc76",
      "tree": "3fc4725a29ee4e151c02105d02d27d5cf0329ce7",
      "parents": [
        "98258e3064a589812eee634dcdd44015f86b295d"
      ],
      "author": {
        "name": "Marcus Hoffmann",
        "email": "buildroot@bubu1.eu",
        "time": "Mon Feb 02 16:02:19 2026 +0100"
      },
      "committer": {
        "name": "Fiona Klute",
        "email": "fiona.klute@gmx.de",
        "time": "Sun Sep 06 11:56:31 2026 +0200"
      },
      "message": "package/python-charset-normalizer: update package url\n\nThe old url redirects here.\n\nSigned-off-by: Marcus Hoffmann \u003cbuildroot@bubu1.eu\u003e\nSigned-off-by: Fiona Klute \u003cfiona.klute@gmx.de\u003e\n"
    },
    {
      "commit": "98258e3064a589812eee634dcdd44015f86b295d",
      "tree": "ce34fa982717bac119a633033dc34375eecfac75",
      "parents": [
        "64ed9e6c43fb531f011caf4b9aacc9e8c1f8dd00"
      ],
      "author": {
        "name": "Bernd Kuhls",
        "email": "bernd@kuhls.net",
        "time": "Fri Sep 04 20:43:41 2026 +0200"
      },
      "committer": {
        "name": "Julien Olivain",
        "email": "ju.o@free.fr",
        "time": "Sun Sep 06 11:30:41 2026 +0200"
      },
      "message": "package/llama-cpp: bump version to b10702\n\nhttps://github.com/ggml-org/llama.cpp/releases\n\nSigned-off-by: Bernd Kuhls \u003cbernd@kuhls.net\u003e\nSigned-off-by: Julien Olivain \u003cju.o@free.fr\u003e\n"
    },
    {
      "commit": "64ed9e6c43fb531f011caf4b9aacc9e8c1f8dd00",
      "tree": "c3c87e579b6631dc2ce66963ec7a4915e83f3948",
      "parents": [
        "d2b7199dea314353b7cdf417ba8625d7c201ece7"
      ],
      "author": {
        "name": "Bernd Kuhls",
        "email": "bernd@kuhls.net",
        "time": "Fri Sep 04 20:50:57 2026 +0200"
      },
      "committer": {
        "name": "Julien Olivain",
        "email": "ju.o@free.fr",
        "time": "Sun Sep 06 11:28:21 2026 +0200"
      },
      "message": "package/libcamera-apps: needs gcc \u003e\u003d 10\n\nBuildroot commit 9a43bf6593aa981040e5ab91e69946af4fe0cee2 bumped the gcc\ndependency from 9 to 10 but forgot to propagate this change to the\nlibcamera-apps package.\n\nSigned-off-by: Bernd Kuhls \u003cbernd@kuhls.net\u003e\nSigned-off-by: Julien Olivain \u003cju.o@free.fr\u003e\n"
    },
    {
      "commit": "d2b7199dea314353b7cdf417ba8625d7c201ece7",
      "tree": "d5f62fcf6e63f6369981460d8f2a2dbc38b8ce83",
      "parents": [
        "4a242e9e7ae40d8f3ecf27b76e0cee69eef78c36"
      ],
      "author": {
        "name": "Bernd Kuhls",
        "email": "bernd@kuhls.net",
        "time": "Sat Sep 05 21:29:04 2026 +0200"
      },
      "committer": {
        "name": "Julien Olivain",
        "email": "ju.o@free.fr",
        "time": "Sun Sep 06 11:23:20 2026 +0200"
      },
      "message": "package/qt5/qt5knx: fix license hash\n\nBuildroot 262a7f6d2f406ed21b2379bb3c4a6c8f6fa0edd7 added the package but\nforgot to provide the hash for LICENSE.GPL3-EXCEPT, instead a hash for\na non-existing file was added to qt5knx.hash.\n\nSigned-off-by: Bernd Kuhls \u003cbernd@kuhls.net\u003e\nSigned-off-by: Julien Olivain \u003cju.o@free.fr\u003e\n"
    },
    {
      "commit": "4a242e9e7ae40d8f3ecf27b76e0cee69eef78c36",
      "tree": "8ce3119e9d726ea77e2d5a8a65a4dbc25a8c0a9d",
      "parents": [
        "c5c0a76751a7e9ba1a8816da68218db9e1379eb9"
      ],
      "author": {
        "name": "Peter Korsgaard",
        "email": "peter@korsgaard.com",
        "time": "Sat Sep 05 22:19:41 2026 +0200"
      },
      "committer": {
        "name": "Julien Olivain",
        "email": "ju.o@free.fr",
        "time": "Sun Sep 06 11:11:32 2026 +0200"
      },
      "message": "package/agec: bump version to 1.0.0\n\nLargely a bugfix release.  Fixes an encryption issue if the cleartext was\nexactly 8KB + N*64KB long.\n\nhttps://git.sr.ht/~min/agec/refs/1.0.0\n\nDrop now upstreamed 0001-io.c-isarmor-do-not-set-eof-for-35-byte-files.patch:\n\nhttps://git.sr.ht/~min/agec/commit/7a529662f9c113ca284c99161b32278f17e278da\n\nUpstream renamed the agec-keygen utility to agecgen, so update the test to\nmatch.\n\nSigned-off-by: Peter Korsgaard \u003cpeter@korsgaard.com\u003e\nSigned-off-by: Julien Olivain \u003cju.o@free.fr\u003e\n"
    },
    {
      "commit": "c5c0a76751a7e9ba1a8816da68218db9e1379eb9",
      "tree": "0359ace5f4e36a4618c52ba5536260f27f888fbf",
      "parents": [
        "9c6eed9ec03431079780ad9dac8dfb53c1ae3691"
      ],
      "author": {
        "name": "Raphaël Gallais-Pou",
        "email": "rgallaispou@gmail.com",
        "time": "Sun Aug 30 18:49:40 2026 +0200"
      },
      "committer": {
        "name": "Julien Olivain",
        "email": "ju.o@free.fr",
        "time": "Sun Sep 06 10:52:15 2026 +0200"
      },
      "message": "package/weston: bump version to 16.0.0\n\nRelease announce:\nhttps://lore.freedesktop.org/wayland-devel/alXq76OX4dVWoP3M@xpredator/T/#u\n\nRemoved already-deprecated config options:\n  * \u0027deprecated-backend-drm-screencast-vaapi\u0027 [1].\n  * \u0027deprecated-shell-fullscreen\u0027 [2].\n  * \u0027deprecated-screenshare\u0027 [3].\n\nThe \u0027pipewire\u0027 and \u0027remoting\u0027 plugins has been deprecated in [4].\nThey have already been removed in the main development branch in\nupstream commit [5] and [6] (not yet in this version 16.0.0).\n\nThis commit removes the \"remoting\" option (rather than changing it to\n\"deprecated-remoting\") because Buildroot was not enabling this option\nand this deprecated option is now disabled by default.\n\nThis commit also removes the \"pipewire\" option (rather than changing\nit to \"deprecated-pipewire\"). The commit log of [4] says the\nreplacement is the \"pipewire-backend\" option, which is already used\nin Buildroot.\n\nTested on STM32MP157C-DK2.\n\n[1] https://gitlab.freedesktop.org/wayland/weston/-/commit/7c3e3d754404453483ffb362be8ab8afb89d3eb2\n[2] https://gitlab.freedesktop.org/wayland/weston/-/commit/29b740ffee98236c5ccb93c09d750b07d37fb8fd\n[3] https://gitlab.freedesktop.org/wayland/weston/-/commit/3bd77f781766abaf8aa9fe55d4f9b98c03e29e42\n[4] https://gitlab.freedesktop.org/wayland/weston/-/commit/ec74bd040389291f0b8d3162506560a8adae31a4\n[5] https://gitlab.freedesktop.org/wayland/weston/-/commit/4606c49d2851a99064cae5e93fe9f464db3a2c58\n[6] https://gitlab.freedesktop.org/wayland/weston/-/commit/d587dfea5bf4816afdb0b7f4c9835956250ab395\n\nSigned-off-by: Raphaël Gallais-Pou \u003crgallaispou@gmail.com\u003e\n[Julien:\n - update link in hash file comment\n - add removed options in Config.in.legacy\n - add back package patch which is not included in release\n - reword commit log (fix and add links to upstream commits)\n]\nSigned-off-by: Julien Olivain \u003cju.o@free.fr\u003e\n"
    },
    {
      "commit": "9c6eed9ec03431079780ad9dac8dfb53c1ae3691",
      "tree": "df37d2ee024fab8ed8b60c986abbbf7c2dcf3ec1",
      "parents": [
        "3469c6793ce6db8f813b3c203d3fc5eeb398e107"
      ],
      "author": {
        "name": "Fengwei Tan",
        "email": "tfx2001@outlook.com",
        "time": "Sat Aug 29 19:12:12 2026 +0800"
      },
      "committer": {
        "name": "Thomas Petazzoni",
        "email": "thomas.petazzoni@bootlin.com",
        "time": "Sat Sep 05 20:50:26 2026 +0200"
      },
      "message": "support/testing, toolchain/toolchain-external/toolchain-external-bootlin: regenerate after MMU dependency update\n\nRegenerate the Bootlin toolchain Kconfig and test configurations using\nsupport/scripts/gen-bootlin-toolchains.\n\nThis adds BR2_USE_MMU to the affected uClibc entries and to the\narchitecture support conditions, and updates the generated tests.\nThe glibc and musl changes only reorder their existing BR2_USE_MMU\ndependencies.\n\nSigned-off-by: Fengwei Tan \u003ctfx2001@outlook.com\u003e\nSigned-off-by: Thomas Petazzoni \u003cthomas.petazzoni@bootlin.com\u003e\n"
    },
    {
      "commit": "3469c6793ce6db8f813b3c203d3fc5eeb398e107",
      "tree": "30b015728fcaf4a2bc1e9761393a4aef80ff3b49",
      "parents": [
        "9556895e784fa87c0cb0b9da2b6f86aa270431a6"
      ],
      "author": {
        "name": "Fengwei Tan",
        "email": "tfx2001@outlook.com",
        "time": "Sat Aug 29 19:12:11 2026 +0800"
      },
      "committer": {
        "name": "Thomas Petazzoni",
        "email": "thomas.petazzoni@bootlin.com",
        "time": "Sat Sep 05 20:50:25 2026 +0200"
      },
      "message": "support/scripts/gen-bootlin-toolchains: add missing BR2_USE_MMU dependencies\n\nThe Bootlin uClibc toolchains for m68k-68xxx, riscv32-ilp32d, and\nxtensa-lx60 require an MMU. However, their generated Kconfig entries\nlack a BR2_USE_MMU dependency, allowing them to be selected for noMMU\nconfigurations. External toolchain validation then fails with:\n\n  MMU support available in C library, please enable BR2_USE_MMU\n\nAdd the missing BR2_USE_MMU dependencies for these architectures to\nprevent them from being selected for noMMU targets.\n\nSigned-off-by: Fengwei Tan \u003ctfx2001@outlook.com\u003e\nSigned-off-by: Thomas Petazzoni \u003cthomas.petazzoni@bootlin.com\u003e\n"
    },
    {
      "commit": "9556895e784fa87c0cb0b9da2b6f86aa270431a6",
      "tree": "718cfc953e1485d95799a52cf26fd8d850f54954",
      "parents": [
        "1f6e5d88361b45fa11e81a712d0fd0b3cfb88040"
      ],
      "author": {
        "name": "Fengwei Tan",
        "email": "tfx2001@outlook.com",
        "time": "Sat Aug 29 19:12:10 2026 +0800"
      },
      "committer": {
        "name": "Thomas Petazzoni",
        "email": "thomas.petazzoni@bootlin.com",
        "time": "Sat Sep 05 20:50:24 2026 +0200"
      },
      "message": "toolchain/toolchain-external/toolchain-external-bootlin: drop duplicate BR2_TOOLCHAIN_HAS_THREADS selections\n\nRegenerate the Bootlin toolchain Kconfig file with\nsupport/scripts/gen-bootlin-toolchains to remove duplicate\nBR2_TOOLCHAIN_HAS_THREADS selections.\n\nCommit 184d47a7adb8 (\"support/scripts/gen-bootlin-toolchains: add new\nscript to support Bootlin toolchains\") initially introduced this issue.\n\nAlthough commit a33e1af4a01c (\"support/scripts/gen-bootlin-toolchains:\navoid selecting _HAS_THREADS multiple times\") fixed the generator script,\nthe Config.in.options file was not regenerated accordingly.\n\nThis is a non-functional cleanup, as repeated Kconfig select statements\nare harmless.\n\nSigned-off-by: Fengwei Tan \u003ctfx2001@outlook.com\u003e\nSigned-off-by: Thomas Petazzoni \u003cthomas.petazzoni@bootlin.com\u003e\n"
    },
    {
      "commit": "1f6e5d88361b45fa11e81a712d0fd0b3cfb88040",
      "tree": "75d11d4a0b5518e2e560e0d17b244d662f77b0e2",
      "parents": [
        "064e09e028cad8db09ffbca72d37b4dc7709205e"
      ],
      "author": {
        "name": "Francois Perrad",
        "email": "francois.perrad.86@gmail.com",
        "time": "Fri Sep 04 20:59:20 2026 +0200"
      },
      "committer": {
        "name": "Julien Olivain",
        "email": "ju.o@free.fr",
        "time": "Sat Sep 05 18:27:45 2026 +0200"
      },
      "message": "package/luasql-sqlite3: bump to version 2.8.0\n\nupdate homepage, Kepler Project is gone\n\ndiff doc/us/license.html: update copyright years and homepage\n\nSigned-off-by: Francois Perrad \u003cfrancois.perrad.86@gmail.com\u003e\nSigned-off-by: Julien Olivain \u003cju.o@free.fr\u003e\n"
    },
    {
      "commit": "064e09e028cad8db09ffbca72d37b4dc7709205e",
      "tree": "740b75a254e3640499c4271ca63fbcaf0efc8e1c",
      "parents": [
        "ed4b68385d22b569779beedbfeb95288d09282eb"
      ],
      "author": {
        "name": "Francois Perrad",
        "email": "francois.perrad.86@gmail.com",
        "time": "Fri Sep 04 20:59:19 2026 +0200"
      },
      "committer": {
        "name": "Julien Olivain",
        "email": "ju.o@free.fr",
        "time": "Sat Sep 05 18:27:45 2026 +0200"
      },
      "message": "package/luajson: bump to version 1.3.5\n\nSigned-off-by: Francois Perrad \u003cfrancois.perrad.86@gmail.com\u003e\nSigned-off-by: Julien Olivain \u003cju.o@free.fr\u003e\n"
    },
    {
      "commit": "ed4b68385d22b569779beedbfeb95288d09282eb",
      "tree": "5198cadf6c980db70da83c14b8132fccbb546ec1",
      "parents": [
        "173cfaf5a324bf7b46531084738e5d0b1e3044cd"
      ],
      "author": {
        "name": "Francois Perrad",
        "email": "francois.perrad.86@gmail.com",
        "time": "Fri Sep 04 20:59:18 2026 +0200"
      },
      "committer": {
        "name": "Julien Olivain",
        "email": "ju.o@free.fr",
        "time": "Sat Sep 05 18:27:45 2026 +0200"
      },
      "message": "package/luafilesystem: bump to version 1.9.0\n\nupdate homepage, Kepler Project is gone\n\ndiff LICENSE:\n    -Copyright © 2003-2014 Kepler Project.\n    +Copyright © 2003-2010 Kepler Project.\n    +Copyright © 2010-2022 The LuaFileSystem authors.\n\nSigned-off-by: Francois Perrad \u003cfrancois.perrad.86@gmail.com\u003e\nSigned-off-by: Julien Olivain \u003cju.o@free.fr\u003e\n"
    },
    {
      "commit": "173cfaf5a324bf7b46531084738e5d0b1e3044cd",
      "tree": "5021b4dbbeba3d16b7b768230dccdd9315af3839",
      "parents": [
        "b0a256dfc59990bec252530d081c11d82879fd9f"
      ],
      "author": {
        "name": "Francois Perrad",
        "email": "francois.perrad.86@gmail.com",
        "time": "Fri Sep 04 20:59:17 2026 +0200"
      },
      "committer": {
        "name": "Julien Olivain",
        "email": "ju.o@free.fr",
        "time": "Sat Sep 05 18:27:45 2026 +0200"
      },
      "message": "package/luadbi-sqlite3: bump to version 0.7.5\n\nSigned-off-by: Francois Perrad \u003cfrancois.perrad.86@gmail.com\u003e\nSigned-off-by: Julien Olivain \u003cju.o@free.fr\u003e\n"
    },
    {
      "commit": "b0a256dfc59990bec252530d081c11d82879fd9f",
      "tree": "1cab16e60e26199af149629e7c7ea285d7c04f12",
      "parents": [
        "196f186837ba5a2a0ac622b1b10875ded18230c7"
      ],
      "author": {
        "name": "Francois Perrad",
        "email": "francois.perrad.86@gmail.com",
        "time": "Fri Sep 04 20:59:16 2026 +0200"
      },
      "committer": {
        "name": "Julien Olivain",
        "email": "ju.o@free.fr",
        "time": "Sat Sep 05 18:27:45 2026 +0200"
      },
      "message": "package/luadbi: bump to version 0.7.5\n\nSigned-off-by: Francois Perrad \u003cfrancois.perrad.86@gmail.com\u003e\nSigned-off-by: Julien Olivain \u003cju.o@free.fr\u003e\n"
    },
    {
      "commit": "196f186837ba5a2a0ac622b1b10875ded18230c7",
      "tree": "765651190e817ee009e2e85b76faa597180fccda",
      "parents": [
        "64c94ae8846a586ac18762084a2a026e7ecd3c5b"
      ],
      "author": {
        "name": "Francois Perrad",
        "email": "francois.perrad.86@gmail.com",
        "time": "Fri Sep 04 20:59:15 2026 +0200"
      },
      "committer": {
        "name": "Julien Olivain",
        "email": "ju.o@free.fr",
        "time": "Sat Sep 05 18:27:45 2026 +0200"
      },
      "message": "package/luabitop: bump to version 1.0.3\n\nSigned-off-by: Francois Perrad \u003cfrancois.perrad.86@gmail.com\u003e\nSigned-off-by: Julien Olivain \u003cju.o@free.fr\u003e\n"
    },
    {
      "commit": "64c94ae8846a586ac18762084a2a026e7ecd3c5b",
      "tree": "8cd1d066155f91974cbb8745854cc67cb6e4689f",
      "parents": [
        "a0db52966bf06f2ce2d0681a5f76eacfe52ba5ac"
      ],
      "author": {
        "name": "Francois Perrad",
        "email": "francois.perrad.86@gmail.com",
        "time": "Fri Sep 04 20:59:14 2026 +0200"
      },
      "committer": {
        "name": "Julien Olivain",
        "email": "ju.o@free.fr",
        "time": "Sat Sep 05 18:27:45 2026 +0200"
      },
      "message": "package/lua-utf8: bump to version 0.2.1\n\nSigned-off-by: Francois Perrad \u003cfrancois.perrad.86@gmail.com\u003e\nSigned-off-by: Julien Olivain \u003cju.o@free.fr\u003e\n"
    },
    {
      "commit": "a0db52966bf06f2ce2d0681a5f76eacfe52ba5ac",
      "tree": "597292c8e955219c3cb98c3ff649b44e21c45134",
      "parents": [
        "c3e961b5af1f81917589e18732e157dfff0ca969"
      ],
      "author": {
        "name": "Francois Perrad",
        "email": "francois.perrad.86@gmail.com",
        "time": "Fri Sep 04 20:59:13 2026 +0200"
      },
      "committer": {
        "name": "Julien Olivain",
        "email": "ju.o@free.fr",
        "time": "Sat Sep 05 18:27:45 2026 +0200"
      },
      "message": "package/lua-std-debug: bump to version 1.1.0\n\ndiff LICENSE.md: update copyright years\n    -Copyright (C) 2002-2018 `std._debug` authors\n    +Copyright (C) 2002-2026 `std._debug` authors\n\nSigned-off-by: Francois Perrad \u003cfrancois.perrad.86@gmail.com\u003e\nSigned-off-by: Julien Olivain \u003cju.o@free.fr\u003e\n"
    },
    {
      "commit": "c3e961b5af1f81917589e18732e157dfff0ca969",
      "tree": "6faf779415cfe7c56f74dc33a61028ca3e6b7809",
      "parents": [
        "bdfdd430ae1957e309602e3360775c486a17e4b3"
      ],
      "author": {
        "name": "Francois Perrad",
        "email": "francois.perrad.86@gmail.com",
        "time": "Fri Sep 04 20:59:12 2026 +0200"
      },
      "committer": {
        "name": "Julien Olivain",
        "email": "ju.o@free.fr",
        "time": "Sat Sep 05 18:27:45 2026 +0200"
      },
      "message": "package/lua-lrexlib-pcre2: bump to version 2.9.4\n\ndiff LICENSE: update copyright years\n\nsee changelog on https://github.com/rrthomas/lrexlib/blob/rel-2-9-4/NEWS\n\nSigned-off-by: Francois Perrad \u003cfrancois.perrad.86@gmail.com\u003e\nSigned-off-by: Julien Olivain \u003cju.o@free.fr\u003e\n"
    },
    {
      "commit": "bdfdd430ae1957e309602e3360775c486a17e4b3",
      "tree": "26595649264806ff15c02bc0205ffa8579846565",
      "parents": [
        "409f7867a7490da38e160391f2800caac805f157"
      ],
      "author": {
        "name": "Francois Perrad",
        "email": "francois.perrad.86@gmail.com",
        "time": "Fri Sep 04 20:59:11 2026 +0200"
      },
      "committer": {
        "name": "Julien Olivain",
        "email": "ju.o@free.fr",
        "time": "Sat Sep 05 18:27:45 2026 +0200"
      },
      "message": "package/lua-datafile: bump to version 0.11\n\nSigned-off-by: Francois Perrad \u003cfrancois.perrad.86@gmail.com\u003e\nSigned-off-by: Julien Olivain \u003cju.o@free.fr\u003e\n"
    },
    {
      "commit": "409f7867a7490da38e160391f2800caac805f157",
      "tree": "2481c20b7f2cc44893fe9e241a036e62eb16647c",
      "parents": [
        "87229b381a6b14171f265811da252f6b883eae8f"
      ],
      "author": {
        "name": "Francois Perrad",
        "email": "francois.perrad.86@gmail.com",
        "time": "Fri Sep 04 20:59:10 2026 +0200"
      },
      "committer": {
        "name": "Julien Olivain",
        "email": "ju.o@free.fr",
        "time": "Sat Sep 05 18:27:45 2026 +0200"
      },
      "message": "package/lua-compat53: bump to version 0.15.1\n\nSigned-off-by: Francois Perrad \u003cfrancois.perrad.86@gmail.com\u003e\nSigned-off-by: Julien Olivain \u003cju.o@free.fr\u003e\n"
    },
    {
      "commit": "87229b381a6b14171f265811da252f6b883eae8f",
      "tree": "bbd6dc31c56e6d0be03a71caa4a0ca31b5aaad05",
      "parents": [
        "6fbe63e14cd58bb5cb9e27c42540dcf820c5a495"
      ],
      "author": {
        "name": "Francois Perrad",
        "email": "francois.perrad.86@gmail.com",
        "time": "Fri Sep 04 20:59:09 2026 +0200"
      },
      "committer": {
        "name": "Julien Olivain",
        "email": "ju.o@free.fr",
        "time": "Sat Sep 05 18:27:45 2026 +0200"
      },
      "message": "package/lsqlite3: bump to version 0.9.7\n\nSigned-off-by: Francois Perrad \u003cfrancois.perrad.86@gmail.com\u003e\nSigned-off-by: Julien Olivain \u003cju.o@free.fr\u003e\n"
    },
    {
      "commit": "6fbe63e14cd58bb5cb9e27c42540dcf820c5a495",
      "tree": "f696525db7121065730bb2eff9445f7b3ce69b7f",
      "parents": [
        "7b611fbd80d8858f056f62a71fdc16da8cd05e69"
      ],
      "author": {
        "name": "Francois Perrad",
        "email": "francois.perrad.86@gmail.com",
        "time": "Fri Sep 04 20:59:09 2026 +0200"
      },
      "committer": {
        "name": "Julien Olivain",
        "email": "ju.o@free.fr",
        "time": "Sat Sep 05 18:26:29 2026 +0200"
      },
      "message": "package/lua: bump to version 5.4.9\n\nFor differences with 5.4.8, see:\nhttps://www.lua.org/work/diffs-lua-5.4.8-lua-5.4.9.html\n\nSigned-off-by: Francois Perrad \u003cfrancois.perrad.86@gmail.com\u003ea\n[Julien: add link to diff with previous version]\nSigned-off-by: Julien Olivain \u003cju.o@free.fr\u003e\n"
    },
    {
      "commit": "7b611fbd80d8858f056f62a71fdc16da8cd05e69",
      "tree": "0c426421f96defdda71adc29d50575dbb602869f",
      "parents": [
        "6910dbda290fbfed0c2ee7e41571b292c19f6228"
      ],
      "author": {
        "name": "Bernd Kuhls",
        "email": "bernd@kuhls.net",
        "time": "Fri Sep 04 20:41:35 2026 +0200"
      },
      "committer": {
        "name": "Julien Olivain",
        "email": "ju.o@free.fr",
        "time": "Sat Sep 05 17:13:25 2026 +0200"
      },
      "message": "package/gnupg2: bump version to 2.5.22\n\nhttps://lists.gnupg.org/pipermail/gnupg-announce/2026q3/000509.html\n\nSigned-off-by: Bernd Kuhls \u003cbernd@kuhls.net\u003e\nSigned-off-by: Julien Olivain \u003cju.o@free.fr\u003e\n"
    },
    {
      "commit": "6910dbda290fbfed0c2ee7e41571b292c19f6228",
      "tree": "b6c413175106cffb647531e521eae025b85dbdfd",
      "parents": [
        "627c482434e12e8ada6fcb45d482ada09af61f73"
      ],
      "author": {
        "name": "Bernd Kuhls",
        "email": "bernd@kuhls.net",
        "time": "Fri Sep 04 20:41:34 2026 +0200"
      },
      "committer": {
        "name": "Julien Olivain",
        "email": "ju.o@free.fr",
        "time": "Sat Sep 05 17:13:25 2026 +0200"
      },
      "message": "package/libksba: bump to version 1.8.1\n\nhttps://github.com/gpg/libksba/blob/libksba-1.8.1/NEWS\nhttps://dev.gnupg.org/T8253\n\nSigned-off-by: Bernd Kuhls \u003cbernd@kuhls.net\u003e\nSigned-off-by: Julien Olivain \u003cju.o@free.fr\u003e\n"
    },
    {
      "commit": "627c482434e12e8ada6fcb45d482ada09af61f73",
      "tree": "a3041add1e9d17023088e5cd851d29c17f65ab7d",
      "parents": [
        "0e631348db15df28d5b576c17097a3ea8a38387c"
      ],
      "author": {
        "name": "Bernd Kuhls",
        "email": "bernd@kuhls.net",
        "time": "Fri Sep 04 20:41:33 2026 +0200"
      },
      "committer": {
        "name": "Julien Olivain",
        "email": "ju.o@free.fr",
        "time": "Sat Sep 05 17:09:02 2026 +0200"
      },
      "message": "package/libgcrypt: bump version to 1.12.3\n\nRelease notes:\nhttps://lists.gnupg.org/pipermail/gnupg-announce/2026q3/000508.html\n\nContains a number of bugfixes, some of which may have (low severity)\nsecurity impact.  As stated by Werner Koch:\n\n All in all we received 26 reports alone from ANSSI but as even the reporter\n mentioned, the real world attack severity is not critical.  Thus we don\u0027t\n consider 1.12.3 a security fix release.  There are some bugs which should\n be fixed to avoid crashes, and thus may lead to DoS.  However, 16384 bit\n RSA keys can also be used for a practical DoS; it all depends on your use\n case.\n\nhttps://www.openwall.com/lists/oss-security/2026/08/31/11\n\nAdded upstream patch to fix a build error introduced by this bump that\nwas detected by the Gitlab pipelines:\n\nsm4-intel-avx512-amd64.S: Assembler messages:\nsm4-intel-avx512-amd64.S:138: Error: operand size mismatch for `vsm4rnds4\u0027\n\nSigned-off-by: Bernd Kuhls \u003cbernd@kuhls.net\u003e\n[Julien: add extra info in commit log from Peter original submission from\n https://lore.kernel.org/buildroot/20260901192724.1021544-1-peter@korsgaard.com/\n]\nSigned-off-by: Julien Olivain \u003cju.o@free.fr\u003e\n"
    },
    {
      "commit": "0e631348db15df28d5b576c17097a3ea8a38387c",
      "tree": "eafc668cef1a933a5c384415e73d1232ae00a69b",
      "parents": [
        "967380b3166d67e749335ce31a1af071390c3a75"
      ],
      "author": {
        "name": "Franciszek Stachura",
        "email": "fbstachura@gmail.com",
        "time": "Mon Aug 31 23:43:52 2026 +0200"
      },
      "committer": {
        "name": "Thomas Petazzoni",
        "email": "thomas.petazzoni@bootlin.com",
        "time": "Sat Sep 05 16:06:18 2026 +0200"
      },
      "message": "support/testing: add nano test\n\nAdd a basic runtime test for nano. The test attempts to write a file\nusing the editor.\n\nSigned-off-by: Franciszek Stachura \u003cfbstachura@gmail.com\u003e\nSigned-off-by: Thomas Petazzoni \u003cthomas.petazzoni@bootlin.com\u003e\n"
    },
    {
      "commit": "967380b3166d67e749335ce31a1af071390c3a75",
      "tree": "96ab47bc04c3f075ed542dea3d4f4d7392a6fd2f",
      "parents": [
        "99529edaef897844c3cb20a107ab0bc26f4ea9d2"
      ],
      "author": {
        "name": "Franciszek Stachura",
        "email": "fbstachura@gmail.com",
        "time": "Mon Aug 31 23:40:40 2026 +0200"
      },
      "committer": {
        "name": "Thomas Petazzoni",
        "email": "thomas.petazzoni@bootlin.com",
        "time": "Sat Sep 05 16:06:11 2026 +0200"
      },
      "message": "package/nano: bump to version 9.2\n\nChangelog:\nhttps://www.nano-editor.org/dist/v9/ChangeLog\nSigned-off-by: Franciszek Stachura \u003cfbstachura@gmail.com\u003e\nSigned-off-by: Thomas Petazzoni \u003cthomas.petazzoni@bootlin.com\u003e\n"
    },
    {
      "commit": "99529edaef897844c3cb20a107ab0bc26f4ea9d2",
      "tree": "9b403dabf266e25d72d52ad7ee3e6c362e72f005",
      "parents": [
        "698535473f7340402d3c36bc1eb66237c63ef083"
      ],
      "author": {
        "name": "Chris Obbard",
        "email": "chris.obbard@oss.qualcomm.com",
        "time": "Mon Aug 31 16:49:58 2026 +0100"
      },
      "committer": {
        "name": "Thomas Petazzoni",
        "email": "thomas.petazzoni@bootlin.com",
        "time": "Sat Sep 05 15:53:04 2026 +0200"
      },
      "message": "package/dtui: require 64-bit atomic support\n\ndtui depends on tui-textarea which unconditionally imports AtomicU64 in\nsrc/widget.rs to pack a viewport rectangle into a single atomic word:\n\n  use std::sync::atomic::{AtomicU64, Ordering};\n  pub struct Viewport(AtomicU64);\n\nAs there is no cfg(target_has_atomic) guard in tui-textarea, its\nbuild fails on any target for which rustc does not provide 64-bit\natomics with:\n\n  Compiling tui-textarea v0.7.0\n  error[E0432]: unresolved import `std::sync::atomic::AtomicU64`\n    --\u003e .../dtui-3.0.0/VENDOR/tui-textarea/src/widget.rs:10:25\n     |\n  10 | use std::sync::atomic::{AtomicU64, Ordering};\n     |                         ^^^^^^^^^ no `AtomicU64` in `sync::atomic`\n     |\n  help: a similar name exists in the module\n     |\n  10 - use std::sync::atomic::{AtomicU64, Ordering};\n  10 + use std::sync::atomic::{AtomicU32, Ordering};\n\nThis has been reported to tui-textarea upstream, but unfortunately the\nproject seems to be unmaintained (issue linked below). A sane workaround\nis to disable the package on targets which lack 64-bit atomic support,\nwhich is exactly what BR2_PACKAGE_HOST_RUSTC_TARGET_HAS_ATOMIC_U64\ndescribes: it is n for armv5te-unknown-linux-{gnu,musl}eabi and\npowerpc-unknown-linux-gnu, the only rust targets Buildroot can generate\nwhich lack 64-bit atomics, and y everywhere else.\n\nThe same problem was hit by package/dust and worked around in commit\n3abc3b97bad9 (\"package/dust: bump to version 1.1.2\") by bumping to a\nversion in which upstream had added the missing guard. That is not an\noption here as tui-textarea 0.7.0 is the latest release.\n\nNote that a runtime test for dtui cannot use the default\ninfra.basetest.BASIC_TOOLCHAIN_CONFIG, since that builds with\nBR2_TOOLCHAIN_EXTERNAL_BOOTLIN_ARMV5_EABI_GLIBC_STABLE, where dtui is now\ndisabled; such a test would need an armv7 or aarch64 toolchain instead.\n\nBuild tested with utils/test-pkg against:\n- BR2_TOOLCHAIN_EXTERNAL_BOOTLIN_ARMV5_EABI_GLIBC_STABLE\n- BR2_TOOLCHAIN_EXTERNAL_BOOTLIN_ARMV5_EABI_MUSL_STABLE\n- BR2_TOOLCHAIN_EXTERNAL_BOOTLIN_POWERPC_E500MC_GLIBC_STABLE\n\nall three fail with the above error before this change and are skipped\nafter it, while armv7 (glibc and musl), aarch64, powerpc64le and x86-64\nstill select and build the package.\n\nLink: https://github.com/rhysd/tui-textarea/issues/66\nFixes: https://autobuild.buildroot.org/results/188f6442371500731453f75983590c922eab6d57\nFixes: https://autobuild.buildroot.org/results/e254db2654f18f1d2110eb8b1a32b43ad0f2a3d6\nSigned-off-by: Christopher Obbard \u003cchris.obbard@oss.qualcomm.com\u003e\nSigned-off-by: Thomas Petazzoni \u003cthomas.petazzoni@bootlin.com\u003e\n"
    },
    {
      "commit": "698535473f7340402d3c36bc1eb66237c63ef083",
      "tree": "cc957a43a1ecf8e93d021363abf1a41923380dc7",
      "parents": [
        "7209f55cd22286eb61c058062aa5f6eebeda8e40"
      ],
      "author": {
        "name": "Chris Obbard",
        "email": "chris.obbard@oss.qualcomm.com",
        "time": "Mon Aug 31 16:49:57 2026 +0100"
      },
      "committer": {
        "name": "Thomas Petazzoni",
        "email": "thomas.petazzoni@bootlin.com",
        "time": "Sat Sep 05 15:52:15 2026 +0200"
      },
      "message": "package/rustc: add BR2_PACKAGE_HOST_RUSTC_TARGET_HAS_ATOMIC_U64\n\nRust does not provide 64-bit atomics on every target Buildroot can\ngenerate. rustc sets max_atomic_width \u003d 32 for three of the 25 targets\nlisted in RUST_TARGETS in utils/update-rust, so\ncore::sync::atomic::AtomicU64 and AtomicI64 simply do not exist there:\n\n  $ rustc --print cfg --target \u003ctarget\u003e | grep target_has_atomic\n  armv5te-unknown-linux-gnueabi     \"16\" \"32\" \"8\" \"ptr\"\n  armv5te-unknown-linux-musleabi    \"16\" \"32\" \"8\" \"ptr\"\n  powerpc-unknown-linux-gnu         \"16\" \"32\" \"8\" \"ptr\"\n\nEvery other supported target, including armv6, armv7, aarch64, all the\nx86 variants, riscv64, s390x, sparc64 and both 64-bit powerpcs, has\nthem, e.g.:\n\n  arm-unknown-linux-gnueabi         \"16\" \"32\" \"64\" \"8\" \"ptr\"\n  armv7-unknown-linux-gnueabihf     \"16\" \"32\" \"64\" \"8\" \"ptr\"\n\nA crate that uses 64-bit atomics without a cfg(target_has_atomic \u003d \"64\")\nguard therefore fails to build on those three targets with:\n\n  error[E0432]: unresolved import `std::sync::atomic::AtomicU64`\n     |\n     |         atomic::{AtomicU64, AtomicU8, AtomicUsize, Ordering},\n     |                  ^^^^^^^^^ no `AtomicU64` in `sync::atomic`\n\nThis has been hit at least twice already: by package/dust, worked around\nin commit 3abc3b97bad9 (\"package/dust: bump to version 1.1.2\") by moving\nto a release in which upstream had added the guard and by package/dtui,\nwhich has no such release available and had to open-code the affected\narchitectures instead.\n\nIt is likely to keep recurring: infra.basetest.BASIC_TOOLCHAIN_CONFIG\nbuilds with BR2_TOOLCHAIN_EXTERNAL_BOOTLIN_ARMV5_EABI_GLIBC_STABLE, so\nevery runtime test that does not override the toolchain compiles for\narmv5te, one of the three affected targets. That is exactly how the two\nfailures above were found.\n\nAdd a hidden symbol so packages can express this constraint once, rather\nthan each open-coding BR2_ARM_CPU_ARMV5 and BR2_powerpc and needing to\nupdate whenever rust gains or changes a target.\n\nNote that armv5te and 32-bit powerpc are only supported by rust for\nglibc and musl, so the uclibc variants of those architectures are\nalready excluded by BR2_PACKAGE_HOST_RUSTC_TARGET_ARCH_SUPPORTS.\n\nSigned-off-by: Christopher Obbard \u003cchris.obbard@oss.qualcomm.com\u003e\nReviewed-by: Romain Naour \u003cromain.naour@smile.fr\u003e\nSigned-off-by: Thomas Petazzoni \u003cthomas.petazzoni@bootlin.com\u003e\n"
    },
    {
      "commit": "7209f55cd22286eb61c058062aa5f6eebeda8e40",
      "tree": "31d6d08e199b311cca27095271e44f2d5e0b4ebe",
      "parents": [
        "a7652a2f4861c154b41928a3239aa27bac2c0383"
      ],
      "author": {
        "name": "Michael Nosthoff",
        "email": "buildroot@heine.tech",
        "time": "Fri Sep 04 13:23:09 2026 +0200"
      },
      "committer": {
        "name": "Thomas Petazzoni",
        "email": "thomas.petazzoni@bootlin.com",
        "time": "Sat Sep 05 15:49:59 2026 +0200"
      },
      "message": "package/gtest: bump to version 1.18.0\n\nchangelog:\nhttps://github.com/google/googletest/releases/tag/v1.18.0\n\nSigned-off-by: Michael Nosthoff \u003cbuildroot@heine.tech\u003e\nSigned-off-by: Thomas Petazzoni \u003cthomas.petazzoni@bootlin.com\u003e\n"
    },
    {
      "commit": "a7652a2f4861c154b41928a3239aa27bac2c0383",
      "tree": "3104d00e07d88c96aabf25684ca0ab108336c881",
      "parents": [
        "ab9097227c6665686b5b65526cb4e3ea084566a7"
      ],
      "author": {
        "name": "Michael Nosthoff",
        "email": "buildroot@heine.tech",
        "time": "Fri Sep 04 08:52:55 2026 +0200"
      },
      "committer": {
        "name": "Thomas Petazzoni",
        "email": "thomas.petazzoni@bootlin.com",
        "time": "Sat Sep 05 15:49:00 2026 +0200"
      },
      "message": "package/catch2: bump to version 3.16.0\n\nchangelog:\nhttps://github.com/catchorg/Catch2/releases/tag/v3.16.0\n\nSigned-off-by: Michael Nosthoff \u003cbuildroot@heine.tech\u003e\nSigned-off-by: Thomas Petazzoni \u003cthomas.petazzoni@bootlin.com\u003e\n"
    },
    {
      "commit": "ab9097227c6665686b5b65526cb4e3ea084566a7",
      "tree": "d4f71a7a054b00fc88de39d6dbcd0078ff6ec1c9",
      "parents": [
        "270ef20df15489ba9e5a1657b3ef24b14b1adb58"
      ],
      "author": {
        "name": "Bernd Kuhls",
        "email": "bernd@kuhls.net",
        "time": "Sat Sep 05 09:53:17 2026 +0200"
      },
      "committer": {
        "name": "Fiona Klute",
        "email": "fiona.klute@gmx.de",
        "time": "Sat Sep 05 11:47:22 2026 +0200"
      },
      "message": "package/rrdtool: bump version to 1.11.0\n\nhttps://github.com/oetiker/rrdtool-1.x/blob/v1.11.0/CHANGES\n\nSigned-off-by: Bernd Kuhls \u003cbernd@kuhls.net\u003e\nSigned-off-by: Fiona Klute \u003cfiona.klute@gmx.de\u003e\n"
    },
    {
      "commit": "270ef20df15489ba9e5a1657b3ef24b14b1adb58",
      "tree": "91e533ac0f6a4a557853c8e0e7bdf943611a449d",
      "parents": [
        "47c45f7f62b60ac24b65c06022f66e0ee8be4b24"
      ],
      "author": {
        "name": "Bernd Kuhls",
        "email": "bernd@kuhls.net",
        "time": "Sat Sep 05 08:21:20 2026 +0200"
      },
      "committer": {
        "name": "Fiona Klute",
        "email": "fiona.klute@gmx.de",
        "time": "Sat Sep 05 11:47:22 2026 +0200"
      },
      "message": "package/libxml2: security bump version to 2.15.4\n\nhttps://download.gnome.org/sources/libxml2/2.15/libxml2-2.15.4.news\n\nFixes the following security issues:\n\n- xmlregexp: Prevent out-of-bounds read in NXT macro\n- fix: add missing overflow checks in dict.c, uri.c, and valid.c\n- xmlregexp: Calc string length after null checking\n- xpointer: Check overflow in xmlXPtrEvalXPtrPart\n- xmlIO: Check for int overflow before calling writecallback\n- fix(xinclude): propagate parseFlags in xmlXIncludeProcess and\n  xmlXIncludeProcessTree\n\nSigned-off-by: Bernd Kuhls \u003cbernd@kuhls.net\u003e\nSigned-off-by: Fiona Klute \u003cfiona.klute@gmx.de\u003e\n"
    },
    {
      "commit": "47c45f7f62b60ac24b65c06022f66e0ee8be4b24",
      "tree": "3941bff1779a546e8c94f356432d1e7987afd6c5",
      "parents": [
        "df61b7e9bb460ed0fa017394af4eec7da4f82a0d"
      ],
      "author": {
        "name": "Bernd Kuhls",
        "email": "bernd@kuhls.net",
        "time": "Fri Sep 04 18:32:44 2026 +0200"
      },
      "committer": {
        "name": "Fiona Klute",
        "email": "fiona.klute@gmx.de",
        "time": "Fri Sep 04 22:43:52 2026 +0200"
      },
      "message": "package/wireless-regdb: bump version to 2026.09.03\n\nhttps://lists.infradead.org/pipermail/wireless-regdb/2026-September/001953.html\n\nSigned-off-by: Bernd Kuhls \u003cbernd@kuhls.net\u003e\nSigned-off-by: Fiona Klute \u003cfiona.klute@gmx.de\u003e\n"
    },
    {
      "commit": "df61b7e9bb460ed0fa017394af4eec7da4f82a0d",
      "tree": "9836b12b005903c96bb78807a06fb91c371e7573",
      "parents": [
        "5f2687795595c9af579312c1d504373ece56f43f"
      ],
      "author": {
        "name": "Martin Bachmann",
        "email": "martin.bachmann@designwerk.com",
        "time": "Fri Mar 06 14:03:22 2026 +0000"
      },
      "committer": {
        "name": "Fiona Klute",
        "email": "fiona.klute@gmx.de",
        "time": "Fri Sep 04 22:37:32 2026 +0200"
      },
      "message": "package/dejavu: add missing license information\n\nDEJAVU_LICENSE is primarily BitstreamVera. The license file also\nspecifies that DejaVu-specific changes and certain math extensions are\nin the Public Domain. This matches the licensing logic used by\nOpenEmbedded/Yocto.\n\nSigned-off-by: Martin Bachmann \u003cmartin.bachmann@designwerk.com\u003e\n[Fiona: wrap lines in commit message]\nSigned-off-by: Fiona Klute \u003cfiona.klute@gmx.de\u003e\n"
    },
    {
      "commit": "5f2687795595c9af579312c1d504373ece56f43f",
      "tree": "a3f8e61987a2382f2f851fec163b49a434ae99e7",
      "parents": [
        "db652bbabaa710f2f917b204065d33858a57023c",
        "f92220f16b3b0c24cadae6f92a662d2ac22a879d"
      ],
      "author": {
        "name": "Peter Korsgaard",
        "email": "peter@korsgaard.com",
        "time": "Fri Sep 04 18:18:19 2026 +0200"
      },
      "committer": {
        "name": "Peter Korsgaard",
        "email": "peter@korsgaard.com",
        "time": "Fri Sep 04 18:18:19 2026 +0200"
      },
      "message": "Merge branch \u0027next\u0027\n\nSigned-off-by: Peter Korsgaard \u003cpeter@korsgaard.com\u003e\n"
    },
    {
      "commit": "db652bbabaa710f2f917b204065d33858a57023c",
      "tree": "efa5d5f87666664f48e3e0ca23895fec6b4f1fc3",
      "parents": [
        "91a2916a97a2aa29f98dcdbb4bec19382636dee7"
      ],
      "author": {
        "name": "Peter Korsgaard",
        "email": "peter@korsgaard.com",
        "time": "Fri Sep 04 18:17:01 2026 +0200"
      },
      "committer": {
        "name": "Peter Korsgaard",
        "email": "peter@korsgaard.com",
        "time": "Fri Sep 04 18:17:01 2026 +0200"
      },
      "message": "Kickoff 2026.11 cycle\n\nSigned-off-by: Peter Korsgaard \u003cpeter@korsgaard.com\u003e\n"
    },
    {
      "commit": "91a2916a97a2aa29f98dcdbb4bec19382636dee7",
      "tree": "46498a81247c5febc9a7075cea838f7f83e301b5",
      "parents": [
        "d5180309b1b66ef3b8eaccca70ad69be8e0729a1"
      ],
      "author": {
        "name": "Peter Korsgaard",
        "email": "peter@korsgaard.com",
        "time": "Fri Sep 04 18:16:22 2026 +0200"
      },
      "committer": {
        "name": "Peter Korsgaard",
        "email": "peter@korsgaard.com",
        "time": "Fri Sep 04 18:16:22 2026 +0200"
      },
      "message": "docs/website/news.html: add 2026.08 announcement link\n\nSigned-off-by: Peter Korsgaard \u003cpeter@korsgaard.com\u003e\n"
    },
    {
      "commit": "d5180309b1b66ef3b8eaccca70ad69be8e0729a1",
      "tree": "ff1c924def6555ef6eaadda9b090186065960177",
      "parents": [
        "f3a1c36e84d1564805dfc02f85d6ba03a962f2dc"
      ],
      "author": {
        "name": "Peter Korsgaard",
        "email": "peter@korsgaard.com",
        "time": "Fri Sep 04 17:28:27 2026 +0200"
      },
      "committer": {
        "name": "Peter Korsgaard",
        "email": "peter@korsgaard.com",
        "time": "Fri Sep 04 17:31:57 2026 +0200"
      },
      "message": "Update for 2026.08\n\nSigned-off-by: Peter Korsgaard \u003cpeter@korsgaard.com\u003e\n"
    },
    {
      "commit": "f3a1c36e84d1564805dfc02f85d6ba03a962f2dc",
      "tree": "c1a41df2612d8bf6c919b8f3549114f976a3778a",
      "parents": [
        "05ee0ab1e0a52cde42ce8c3aa77c980339b906b4"
      ],
      "author": {
        "name": "Peter Korsgaard",
        "email": "peter@korsgaard.com",
        "time": "Fri Sep 04 17:29:55 2026 +0200"
      },
      "committer": {
        "name": "Peter Korsgaard",
        "email": "peter@korsgaard.com",
        "time": "Fri Sep 04 17:30:58 2026 +0200"
      },
      "message": "docs/website/news.html: add 2026.08-rc3 announcement\n\nWas missed when the download page was updated for 2026.08-rc3 in commit\ne6b06b8d9c (\"Update for 2026.08-rc3\").\n\nSigned-off-by: Peter Korsgaard \u003cpeter@korsgaard.com\u003e\n"
    },
    {
      "commit": "05ee0ab1e0a52cde42ce8c3aa77c980339b906b4",
      "tree": "59b28e17126a33e4e2573d9893a377092ddc681a",
      "parents": [
        "dfc909b1cddf7e69fe3d1ad96fdac08f595dccf2"
      ],
      "author": {
        "name": "Thomas Perale",
        "email": "thomas.perale@mind.be",
        "time": "Fri Sep 04 15:41:40 2026 +0200"
      },
      "committer": {
        "name": "Peter Korsgaard",
        "email": "peter@korsgaard.com",
        "time": "Fri Sep 04 16:58:41 2026 +0200"
      },
      "message": "docs/website: add Othermo as a silver sponsor\n\nOthermo offers manufacturer-independent operational monitoring for\nenergy centers and boiler rooms. They connect a wide range of peripheral\nsuch as meters, pumps or pressure maintenance [1][2].\n\nThank you for sponsoring LTS maintenance !\n\n[1] https://othermo.de/\n[2] https://www.linkedin.com/company/othermo-gmbh/\n\nSigned-off-by: Thomas Perale \u003cthomas.perale@mind.be\u003e\nSigned-off-by: Peter Korsgaard \u003cpeter@korsgaard.com\u003e\n"
    },
    {
      "commit": "dfc909b1cddf7e69fe3d1ad96fdac08f595dccf2",
      "tree": "fd1ee3880b7d2911575371e60ebea2f365fe31bb",
      "parents": [
        "ad9557dba535b2b2ad39733c9c3d31851d34a9aa"
      ],
      "author": {
        "name": "Thomas Perale",
        "email": "thomas.perale@mind.be",
        "time": "Fri Sep 04 09:00:45 2026 +0200"
      },
      "committer": {
        "name": "Peter Korsgaard",
        "email": "peter@korsgaard.com",
        "time": "Fri Sep 04 13:53:31 2026 +0200"
      },
      "message": "package/erlang: security bump to v26.2.5.21\n\nSee the changelogs:\n\n- https://www.erlang.org/patches/OTP-26.2.5.16\n- https://www.erlang.org/patches/OTP-26.2.5.17\n- https://www.erlang.org/patches/OTP-26.2.5.18\n- https://www.erlang.org/patches/OTP-26.2.5.19\n- https://www.erlang.org/patches/OTP-26.2.5.20\n- https://www.erlang.org/patches/OTP-26.2.5.21\n\nThis fixes the following vulnerabilities:\n\n- CVE-2026-21620:\n    Relative Path Traversal, Improper Isolation or Compartmentalization\n    vulnerability in erlang otp erlang/otp (tftp_file modules), erlang otp\n    inets (tftp_file modules), erlang otp tftp (tftp_file modules) allows\n    Relative Path Traversal. This vulnerability is associated with program\n    files lib/tftp/src/tftp_file.erl, src/tftp_file.erl.\n\nFor more information, see:\n - https://www.cve.org/CVERecord?id\u003dCVE-2026-21620\n\n- CVE-2026-23941:\n    Inconsistent Interpretation of HTTP Requests (\u0027HTTP Request\n    Smuggling\u0027) vulnerability in Erlang OTP (inets httpd module) allows\n    HTTP Request Smuggling.  This vulnerability is associated with program\n    files lib/inets/src/http_server/httpd_request.erl and program routines\n    httpd_request:parse_headers/7.  The server does not reject or\n    normalize duplicate Content-Length headers. The earliest Content-\n    Length in the request is used for body parsing while common reverse\n    proxies (nginx, Apache httpd, Envoy) honor the last Content-Length\n    value. This violates RFC 9112 Section 6.3 and allows front-end/back-\n    end desynchronization, leaving attacker-controlled bytes queued as the\n    start of the next request.\n\nFor more information, see:\n - https://www.cve.org/CVERecord?id\u003dCVE-2026-23941\n\n- CVE-2026-23942:\n    Improper Limitation of a Pathname to a Restricted Directory (\u0027Path\n    Traversal\u0027) vulnerability in Erlang OTP (ssh_sftpd module) allows Path\n    Traversal.  This vulnerability is associated with program files\n    lib/ssh/src/ssh_sftpd.erl and program routines\n    ssh_sftpd:is_within_root/2.  The SFTP server uses string prefix\n    matching via lists:prefix/2 rather than proper path component\n    validation when checking if a path is within the configured root\n    directory. This allows authenticated users to access sibling\n    directories that share a common name prefix with the configured root\n    directory. For example, if root is set to /home/user1, paths like\n    /home/user10 or /home/user1_backup would incorrectly be considered\n    within the root.\n\nFor more information, see:\n - https://www.cve.org/CVERecord?id\u003dCVE-2026-23942\n\n- CVE-2026-23943:\n    Improper Handling of Highly Compressed Data (Compression Bomb)\n    vulnerability in Erlang OTP ssh (ssh_transport modules) allows Denial\n    of Service via Resource Depletion.  The SSH transport layer advertises\n    legacy zlib compression by default and inflates attacker-controlled\n    payloads pre-authentication without any size limit, enabling reliable\n    memory exhaustion DoS.  Two compression algorithms are affected:  *\n    zlib: Activates immediately after key exchange, enabling\n    unauthenticated attacks * zlib@openssh.com: Activates post-\n    authentication, enabling authenticated attacks  Each SSH packet can\n    decompress ~255 MB from 256 KB of wire data (1029:1 amplification\n    ratio). Multiple packets can rapidly exhaust available memory, causing\n    OOM kills in memory-constrained environments.  This vulnerability is\n    associated with program files lib/ssh/src/ssh_transport.erl and\n    program routines ssh_transport:decompress/2,\n    ssh_transport:handle_packet_part/4.\n\nFor more information, see:\n - https://www.cve.org/CVERecord?id\u003dCVE-2026-23943\n\n- CVE-2026-28810:\n    Generation of Predictable Numbers or Identifiers vulnerability in\n    Erlang/OTP kernel (inet_res, inet_db modules) allows DNS Cache\n    Poisoning.  The built-in DNS resolver (inet_res) uses a sequential,\n    process-global 16-bit transaction ID for UDP queries and does not\n    implement source port randomization. Response validation relies almost\n    entirely on this ID, making DNS cache poisoning practical for an\n    attacker who can observe one query or predict the next ID. This\n    conflicts with RFC 5452 recommendations for mitigating forged DNS\n    answers.  inet_res is intended for use in trusted network environments\n    and with trusted recursive resolvers. Earlier documentation did not\n    clearly state this deployment assumption, which could lead users to\n    deploy the resolver in environments where spoofed DNS responses are\n    possible.  This vulnerability is associated with program files\n    lib/kernel/src/inet_db.erl and lib/kernel/src/inet_res.erl.\n\nFor more information, see:\n - https://www.cve.org/CVERecord?id\u003dCVE-2026-28810\n\n- CVE-2026-32147:\n    Improper Limitation of a Pathname to a Restricted Directory (\u0027Path\n    Traversal\u0027) vulnerability in Erlang OTP ssh (ssh_sftpd module) allows\n    an authenticated SFTP user to modify file attributes outside the\n    configured chroot directory.  The SFTP daemon (ssh_sftpd) stores the\n    raw, user-supplied path in file handles instead of the chroot-resolved\n    path. When SSH_FXP_FSETSTAT is issued on such a handle, file\n    attributes (permissions, ownership, timestamps) are modified on the\n    real filesystem path, bypassing the root directory boundary entirely.\n    Any authenticated SFTP user on a server configured with the root\n    option can modify file attributes of files outside the intended chroot\n    boundary. The prerequisite is that a target file must exist on the\n    real filesystem at the same relative path. Note that this\n    vulnerability only allows modification of file attributes; file\n    contents cannot be read or altered through this attack vector.  If the\n    SSH daemon runs as root, this enables direct privilege escalation: an\n    attacker can set the setuid bit on any binary, change ownership of\n    sensitive files, or make system configuration world-writable.  This\n    vulnerability is associated with program files\n    lib/ssh/src/ssh_sftpd.erl and program routines ssh_sftpd:do_open/4 and\n    ssh_sftpd:handle_op/4.\n\nFor more information, see:\n  - https://www.cve.org/CVERecord?id\u003dCVE-2026-32147\n\n- CVE-2026-42789:\n    Improper Following of a Certificate\u0027s Chain of Trust vulnerability in\n    Erlang OTP public_key (pubkey_cert module) allows a non-CA certificate\n    to be accepted as an intermediate issuer, enabling certificate chain\n    forgery.  In lib/public_key/src/pubkey_cert.erl,\n    pubkey_cert:validate_extensions/7 contains two flaws that together\n    allow a certificate with basicConstraints cA:false and no keyUsage\n    extension to be used as an intermediate issuer in a chain passed to\n    public_key:pkix_path_validation/3: the cA:false clause recurses into\n    the remaining extensions without rejecting the certificate when it is\n    in issuer position, and the keyUsage check only fires when the\n    extension is present, so a certificate lacking keyUsage entirely\n    bypasses the keyCertSign enforcement.  Any party holding an end-entity\n    certificate with basicConstraints cA:false and no keyUsage extension,\n    issued by any CA in the victim\u0027s trust store, can use that\n    certificate\u0027s private key to sign forged leaf certificates for\n    arbitrary identities. public_key:pkix_path_validation/3 accepts the\n    resulting chain, and by extension every TLS or mTLS endpoint built on\n    the OTP ssl application that relies on the default verifier is\n    affected, including server identity verification on the client side\n    and client certificate verification on mTLS servers.\n\nFor more information, see:\n - https://www.cve.org/CVERecord?id\u003dCVE-2026-42789\n\n- CVE-2026-42790:\n    Improper Certificate Validation vulnerability in Erlang OTP public_key\n    (pubkey_cert and public_key modules) allows a DNS nameConstraints\n    bypass via subject CommonName fallback in TLS hostname verification.\n    Two flaws combine to allow a subordinate CA whose DNS nameConstraints\n    are restricted (e.g. permitted;DNS:allowed.example.com) to issue a\n    leaf certificate that an OTP TLS client accepts as a valid identity\n    for an out-of-scope hostname (e.g. victim.example.com):  First,\n    pubkey_cert:validate_names/6 in lib/public_key/src/pubkey_cert.erl\n    only checks SAN DNS entries against nameConstraints. Per RFC 5280, a\n    permitted DNS subtree only restricts certificates that contain a DNS-\n    typed name. A leaf with no subjectAltName therefore trivially\n    satisfies any permitted;DNS:... constraint regardless of its subject\n    commonName.  Second, public_key:pkix_verify_hostname/3 in\n    lib/public_key/src/public_key.erl falls back to the subject commonName\n    when no subjectAltName is present, extracting id-at-commonName\n    attributes as presented IDs and matching them against the reference\n    hostname. The strict pkix_verify_hostname_match_fun(https) matcher\n    does not suppress this fallback.  The result is that path validation\n    accepts a CN-only leaf under a DNS-constrained intermediate (no SAN\n    means the nameConstraints are not triggered), and hostname\n    verification then accepts it via the CN fallback. The bypass is\n    reachable from stock ssl:connect with verify_peer, a trusted CA, SNI,\n    and the canonical strict https hostname matcher.\n\nFor more information, see:\n - https://www.cve.org/CVERecord?id\u003dCVE-2026-42790\n\nSigned-off-by: Thomas Perale \u003cthomas.perale@mind.be\u003e\nSigned-off-by: Peter Korsgaard \u003cpeter@korsgaard.com\u003e\n"
    },
    {
      "commit": "ad9557dba535b2b2ad39733c9c3d31851d34a9aa",
      "tree": "73d7bf55773d63c5af897c4f1074a46e4c621c37",
      "parents": [
        "5f8d0b78ec32bd35b8a38812c71f33529a2723cb"
      ],
      "author": {
        "name": "Bernd Kuhls",
        "email": "bernd@kuhls.net",
        "time": "Thu Sep 03 08:39:13 2026 +0200"
      },
      "committer": {
        "name": "Peter Korsgaard",
        "email": "peter@korsgaard.com",
        "time": "Fri Sep 04 13:46:58 2026 +0200"
      },
      "message": "package/libcurl: security bump to version 8.22.0\n\nhttps://curl.se/ch/8.22.0.html\nhttps://daniel.haxx.se/blog/2026/09/02/curl-8-22-0/\n\nFixes the following CVEs:\nCVE-2026-13608: OpenLDAP SASL authentication bypass\nCVE-2026-18924: HTTP/2 server push UAF\nCVE-2026-19931: Negotiate ambient user conn reuse\nCVE-2026-80229: OpenSSL provider use-after-free\nCVE-2026-80230: OpenSSL pinning bypass\nCVE-2026-80231: native CA store conn reuse\nCVE-2026-80255: secure cookie attribute bypass with tab\nCVE-2026-82208: wolfSSL CA-cache hit overrides callback\nCVE-2026-82209: domain-scoped PSL domain cookie\n\nSigned-off-by: Bernd Kuhls \u003cbernd@kuhls.net\u003e\nSigned-off-by: Peter Korsgaard \u003cpeter@korsgaard.com\u003e\n"
    },
    {
      "commit": "5f8d0b78ec32bd35b8a38812c71f33529a2723cb",
      "tree": "cf4b3712cbe502413af5724e98e363277a5e1049",
      "parents": [
        "c05de97a2bfe51d5d85e3071df3be7eec61a8375"
      ],
      "author": {
        "name": "Bernd Kuhls",
        "email": "bernd@kuhls.net",
        "time": "Thu Sep 03 08:39:12 2026 +0200"
      },
      "committer": {
        "name": "Peter Korsgaard",
        "email": "peter@korsgaard.com",
        "time": "Thu Sep 03 21:08:18 2026 +0200"
      },
      "message": "package/libopenssl: disable atomic operations for m68k Coldfire\n\nThis patch fixes a build error with OpenSSL-enabled libcurl which was\ndetected by the Gitlab pipelines:\n\nchecking for openssl options with pkg-config... found\nconfigure: pkg-config: SSL_LIBS: \"-lssl -lcrypto -pthread\"\nconfigure: pkg-config: SSL_LDFLAGS: \"-L/builds/bkuhls/buildroot/br-test-pkg/bootlin-m68k-5208-uclibc/host/bin/../m68k-buildroot-uclinux-uclibc/sysroot/usr/lib\"\nconfigure: pkg-config: SSL_CPPFLAGS: \"\"\nchecking for HMAC_Update in -lcrypto... no\nchecking for HMAC_Init_ex in -lcrypto... no\nchecking OpenSSL linking with -ldl... no\nchecking OpenSSL linking with -ldl and -lpthread... no\nchecking for SSL_set_quic_use_legacy_codepoint... no\nchecking for SSL_set_quic_tls_cbs... no\nconfigure: OpenSSL version does not speak any known QUIC API\nconfigure: OPT_OPENSSL: /builds/bkuhls/buildroot/br-test-pkg/bootlin-m68k-5208-uclibc/host/m68k-buildroot-uclinux-uclibc/sysroot/usr\nconfigure: OPENSSL_ENABLED:\nconfigure: error: --with-openssl was given but OpenSSL could not be detected\nmake[1]: *** [package/pkg-generic.mk:263: /builds/bkuhls/buildroot/br-test-pkg/bootlin-m68k-5208-uclibc/build/libcurl-8.21.0/.stamp_configured] Error 1\n\nAlthough OpenSSL was found using pkg-config the build tests fail.\n\nA local build shows the concrete error in config.log, for example:\n\nconfigure:27577: checking for HMAC_Update in -lcrypto\nconfigure:27599: /home/bernd/buildroot/output/host/bin/m68k-linux-gcc\n -o conftest -D_LARGEFILE_SOURCE -D_LARGEFILE64_SOURCE\n -D_FILE_OFFSET_BITS\u003d64 -O2 -g0 -fno-dwarf2-cfi-asm -Wl,-elf2flt\u003d-r\n -static -Werror-implicit-function-declaration -Wno-system-headers\n -D_LARGEFILE_SOURCE -D_LARGEFILE64_SOURCE -D_FILE_OFFSET_BITS\u003d64\n -D_GNU_SOURCE     -Wl,-elf2flt\u003d-r -static\n -L/home/bernd/buildroot/output/host/bin/../m68k-buildroot-uclinux-uclibc/sysroot/usr/lib\n -L/home/bernd/buildroot/output/host/bin/../m68k-buildroot-uclinux-uclibc/sysroot/usr/lib\n conftest.c -lcrypto  -lssl -lcrypto -lz -pthread -lz  \u003e\u00265\n/home/bernd/buildroot/output/host/opt/ext-toolchain/m68k-buildroot-uclinux-uclibc/bin/ld.real:\n /home/bernd/buildroot/output/host/bin/../m68k-buildroot-uclinux-uclibc/sysroot/usr/lib/libcrypto.a(libcrypto-lib-threads_pthread.o):\n in function `ossl_rcu_read_lock\u0027:\nthreads_pthread.c:(.text+0xa4): undefined reference to `__atomic_fetch_add_8\u0027\n\nThis error occurs many times for various atomic operations:\n\n$ grep \"undefined reference to \\`__atomic\" output/build/libcurl-8.20.0/config.log | sort -u | grep -v real\nthreads_pthread.c:(.text+0x28a): undefined reference to `__atomic_fetch_sub_8\u0027\nthreads_pthread.c:(.text+0x3b4): undefined reference to `__atomic_fetch_add_8\u0027\nthreads_pthread.c:(.text+0x9c8): undefined reference to `__atomic_is_lock_free\u0027\nthreads_pthread.c:(.text+0xa4): undefined reference to `__atomic_fetch_add_8\u0027\nthreads_pthread.c:(.text+0xa9c): undefined reference to `__atomic_is_lock_free\u0027\nthreads_pthread.c:(.text+0xb66): undefined reference to `__atomic_is_lock_free\u0027\nthreads_pthread.c:(.text+0xc30): undefined reference to `__atomic_is_lock_free\u0027\nthreads_pthread.c:(.text+0xcdc): undefined reference to `__atomic_is_lock_free\u0027\n\nThe build error can be reproduced with the current buildroot tree using\nthis defconfig:\n\nBR2_m68k\u003dy\nBR2_m68k_cf5208\u003dy\nBR2_TOOLCHAIN_EXTERNAL\u003dy\nBR2_TOOLCHAIN_EXTERNAL_BOOTLIN_M68K_COLDFIRE_UCLIBC_STABLE\u003dy\nBR2_PACKAGE_OPENSSL\u003dy\nBR2_PACKAGE_LIBCURL\u003dy\n\nAlthough the toolchain lacks atomics support\n\n$ grep ATOMIC .config\n$\n\nit emits atomic-related defines, for example:\n\n$ echo | output/host/bin/m68k-linux-gcc -dM -E - | grep __ATOMIC_ACQ_REL\n#define __ATOMIC_ACQ_REL 4\n$\n\nThis specific define __ATOMIC_ACQ_REL is used in OpenSSL to enable\natomic support at various places:\nhttps://github.com/openssl/openssl/blob/openssl-3.6.3/crypto/threads_pthread.c\n\ncausing the build errors we see with the mentioned defconfig.\n\nTo fix the problem we use an OpenSSL-provided define to forcefully\ndisable the usage of atomic intrinsics.\n\nThe misdetection of atomic intrinsics for m68k coldfire is not a new\nproblem:\nhttps://lists.buildroot.org/pipermail/buildroot/2017-May/180841.html\nhttps://lists.buildroot.org/pipermail/buildroot/2026-May/803110.html\n\nSigned-off-by: Bernd Kuhls \u003cbernd@kuhls.net\u003e\nSigned-off-by: Peter Korsgaard \u003cpeter@korsgaard.com\u003e\n"
    },
    {
      "commit": "c05de97a2bfe51d5d85e3071df3be7eec61a8375",
      "tree": "3cf2534c1c750f7d1400358235201a8513a03996",
      "parents": [
        "8f38b17f76cc5963e69371c51d4915cb6ee221a6"
      ],
      "author": {
        "name": "Bernd Kuhls",
        "email": "bernd@kuhls.net",
        "time": "Wed Sep 02 22:16:56 2026 +0200"
      },
      "committer": {
        "name": "Julien Olivain",
        "email": "ju.o@free.fr",
        "time": "Wed Sep 02 22:27:10 2026 +0200"
      },
      "message": "{linux, linux-headers}: bump 6.12.x, 6.6.x, 6.1.x, 5.15.x, 5.10.x, 7.1.x, 6.18.x series\n\nUpdate the latest kernel releases to:\n - 6.12.107 -\u003e 6.12.108\n - 6.6.155 -\u003e 6.6.156\n - 6.1.186 -\u003e 6.1.187\n - 5.15.219 -\u003e 5.15.220\n - 5.10.268 -\u003e 5.10.269\n - 7.1.12 -\u003e 7.1.13\n - 6.18.48 -\u003e 6.18.49\n\nSigned-off-by: Bernd Kuhls \u003cbernd@kuhls.net\u003e\nSigned-off-by: Julien Olivain \u003cju.o@free.fr\u003e\n"
    },
    {
      "commit": "8f38b17f76cc5963e69371c51d4915cb6ee221a6",
      "tree": "7de7b703bee86dede0c824310eb1d64b1b2197ed",
      "parents": [
        "672b5f9213841bd79f1596e755bbffa7e4f39d2a"
      ],
      "author": {
        "name": "Andreas Ziegler",
        "email": "br025@umbiko.net",
        "time": "Sun Aug 30 09:51:06 2026 +0200"
      },
      "committer": {
        "name": "Julien Olivain",
        "email": "ju.o@free.fr",
        "time": "Wed Sep 02 21:28:15 2026 +0200"
      },
      "message": "package/mpd: update to version 0.24.15\n\nVersion 0.24.15 change log:\n\n* protocol\n\tfix crash on \"sticker delete\" and \"sticker find\"\n* database\n\tupnp: fix crash bug\n* input\n\talsa, curl, nfs: fix stalled transfers\n* playlist\n\tasx, pls, rss, xspf: limit to 16 MB\n\tcue: fix problem playing CUE tracks in music directory root\n* player\n\tfix noise with replay gain and cross-fade\n\nSigned-off-by: Andreas Ziegler \u003cbr025@umbiko.net\u003e\nSigned-off-by: Julien Olivain \u003cju.o@free.fr\u003e\n"
    },
    {
      "commit": "672b5f9213841bd79f1596e755bbffa7e4f39d2a",
      "tree": "c83b609a8ee3a1cf63e77fd1a29bd9a2865c8c37",
      "parents": [
        "94013c3a95a849b6a8d8db5321f9bfea4c389b10"
      ],
      "author": {
        "name": "Alexis Lothoré",
        "email": "alexis.lothore@bootlin.com",
        "time": "Wed Sep 02 10:11:49 2026 +0200"
      },
      "committer": {
        "name": "Julien Olivain",
        "email": "ju.o@free.fr",
        "time": "Wed Sep 02 21:25:29 2026 +0200"
      },
      "message": "package/openscap: drop duplicate patch\n\nCommit bd5b267b1de0 (\"package/openscap: fix build failure with dbus and\nmusl\") brought an upstream patch to fix a build failure on the openscap\npackage, detected by the autobuilder on buildroot 2026.02.x, which had\nopenscap 1.3.12 at that time. bd5b267b1de0 has recently been merged on\nmaster; openscap has already been bumped to 1.4.4 on this branch, and so\nit already brings the needed fix for musl+dbus build configurations,\nhence making the patch step fail. This upstream patch is then not needed\nanymore on any maintained branch.\n\nFixes: https://autobuild.buildroot.org/results/d11d0b82dcdb4bf10f6c37db8bdbc42a78bdf28b/\nFixes: https://autobuild.buildroot.org/results/4397a4ef94ccf482f1ab9d24b6334adb0222a580/\nSigned-off-by: Alexis Lothoré \u003calexis.lothore@bootlin.com\u003e\nSigned-off-by: Julien Olivain \u003cju.o@free.fr\u003e\n"
    },
    {
      "commit": "94013c3a95a849b6a8d8db5321f9bfea4c389b10",
      "tree": "45a73608437d08c5122b2bfdb77979b80846ed32",
      "parents": [
        "79fd6241e4347f67d659cc02669448397b458d52"
      ],
      "author": {
        "name": "Peter Korsgaard",
        "email": "peter@korsgaard.com",
        "time": "Tue Sep 01 21:41:55 2026 +0200"
      },
      "committer": {
        "name": "Julien Olivain",
        "email": "ju.o@free.fr",
        "time": "Wed Sep 02 21:04:20 2026 +0200"
      },
      "message": "package/exiv2: security bump to version 0.28.9\n\nFixes the following vulnerabilities:\n\nCVE-2026-68546: Heap out-of-bounds write in RemoteIo when reading from a\nmalicious remote server (WebReady/Curl builds)\nhttps://github.com/Exiv2/exiv2/security/advisories/GHSA-3695-mjv8-3r52\n\nCVE-2026-68547: Heap out-of-bounds read in RemoteIo when reading\nblock-aligned remote CRW files\nhttps://github.com/Exiv2/exiv2/security/advisories/GHSA-jcgh-p9v3-pw6j\n\nCVE-2026-49275: Out of bounds read in CrwMap::decodeBasic\nhttps://github.com/Exiv2/exiv2/security/advisories/GHSA-hxph-pv7w-8649\n\nOut-of-bounds write in RemoteIo::mmap\nhttps://github.com/Exiv2/exiv2/security/advisories/GHSA-vg6c-9f6h-4x5q\n\nOut of bounds write in http.cpp\nhttps://github.com/Exiv2/exiv2/security/advisories/GHSA-9v3x-mhg4-wwv2\n\nInfinite loop in QuickTimeVideo::userDataDecoder\nhttps://github.com/Exiv2/exiv2/security/advisories/GHSA-fgw8-p7pr-37cp\n\nFor more details, see the announcement:\nhttps://www.openwall.com/lists/oss-security/2026/08/30/1\n\nNotice: the RemoteIo-related vulnerabilities are not applicable for\nBuildroot as exiv2 is not built with libcurl support.\n\nSigned-off-by: Peter Korsgaard \u003cpeter@korsgaard.com\u003e\nSigned-off-by: Julien Olivain \u003cju.o@free.fr\u003e\n"
    },
    {
      "commit": "79fd6241e4347f67d659cc02669448397b458d52",
      "tree": "caaa7200b4b794ace71f79bd1210956b42b26f17",
      "parents": [
        "789485b3e7a70e18c799ea330b3c184ce9ea245e"
      ],
      "author": {
        "name": "Romain Naour",
        "email": "romain.naour@smile.fr",
        "time": "Thu Aug 27 23:21:25 2026 +0200"
      },
      "committer": {
        "name": "Julien Olivain",
        "email": "ju.o@free.fr",
        "time": "Tue Sep 01 23:58:23 2026 +0200"
      },
      "message": "board/qemu: add xtensa kernel patch\n\n-fno-stack-protector must be passed to avoid linking errors related to\nundefined references to \u0027__stack_chk_guard\u0027 and \u0027__stack_chk_fail\u0027 if\ntoolchain enforces -fstack-protector.\n\nFixes:\nhttps://gitlab.com/buildroot.org/toolchains-builder/-/jobs/15876432953\n\nSigned-off-by: Romain Naour \u003cromain.naour@smile.fr\u003e\nSigned-off-by: Julien Olivain \u003cju.o@free.fr\u003e\n"
    },
    {
      "commit": "789485b3e7a70e18c799ea330b3c184ce9ea245e",
      "tree": "4b4ab3c6074d3fe49e810b129bda03a7972f2b78",
      "parents": [
        "08cc0938b53cd7e8c6a746bf6592747bad1cfa5f"
      ],
      "author": {
        "name": "Romain Naour",
        "email": "romain.naour@smile.fr",
        "time": "Thu Aug 27 23:21:24 2026 +0200"
      },
      "committer": {
        "name": "Julien Olivain",
        "email": "ju.o@free.fr",
        "time": "Tue Sep 01 23:56:47 2026 +0200"
      },
      "message": "package/gcc: enable decimal float on s390\n\nFloating-point type _Float16 added in gcc-16 on s390 now requires\ndecimal floating-point support enabled in the toolchain [1][2].\n\nWithout decimal floating-point, gcc 16.2.0 fails to build with:\n\n../../../libgcc/config/s390/_dpd_sd_to_hf.c:27:25: error: decimal floating-point not supported for this target\n   27 | HFtype __dpd_truncsdhf (_Decimal32);\n      |                         ^~~~~~~~~~\n../../../libgcc/config/s390/_dpd_sd_to_hf.c:31:16: error: decimal floating-point not supported for this target\n   31 | force_convert (_Decimal32 x)\n      |                ^~~~~~~~~~\n../../../libgcc/config/s390/_dpd_hf_to_td.c:34:1: error: decimal floating-point not supported for this target\n   34 | _Decimal128\n      | ^~~~~~~~~~~\n../../../libgcc/config/s390/_dpd_sd_to_hf.c:35:18: error: decimal floating-point not supported for this target\n   35 | __dpd_truncsdhf (_Decimal32 x)\n\nEnable decimal floating-point support as suggested by Alexander\nEgorenkov.\n\nFixes:\nhttps://lore.kernel.org/buildroot/ansJ5dXXblvYeMLB@windsurf/\n\n[1] https://gcc.gnu.org/gcc-16/changes.html#s390\n[2] https://gcc.gnu.org/git/?p\u003dgcc.git;a\u003dcommit;h\u003d5d6d56d837c3dbeabd382c1fb4f7d21d9891f4b9\n\nCc: Alexander Egorenkov \u003cegorenar@linux.ibm.com\u003e\nSigned-off-by: Romain Naour \u003cromain.naour@smile.fr\u003e\nSigned-off-by: Julien Olivain \u003cju.o@free.fr\u003e\n"
    },
    {
      "commit": "08cc0938b53cd7e8c6a746bf6592747bad1cfa5f",
      "tree": "8239927a65200a5f8a27b4e6014a07a534c1fbb9",
      "parents": [
        "32b4f3f942a26476da9533cb11afdeb5a27861ba"
      ],
      "author": {
        "name": "Sébastien Szymanski",
        "email": "sebastien.szymanski@armadeus.com",
        "time": "Tue Sep 01 17:44:32 2026 +0200"
      },
      "committer": {
        "name": "Peter Korsgaard",
        "email": "peter@korsgaard.com",
        "time": "Tue Sep 01 23:41:26 2026 +0200"
      },
      "message": "package/newt: update _SITE\n\nOld URL returns 404, update _SITE to https://releases.pagure.org/newt\n\nSigned-off-by: Sébastien Szymanski \u003csebastien.szymanski@armadeus.com\u003e\nSigned-off-by: Peter Korsgaard \u003cpeter@korsgaard.com\u003e\n"
    },
    {
      "commit": "32b4f3f942a26476da9533cb11afdeb5a27861ba",
      "tree": "4ffd43b1a5981768cb54c9a7324b466f5d4c4dd5",
      "parents": [
        "45636d67c93e3722543e181900bcb74a52b01bbb"
      ],
      "author": {
        "name": "Romain Naour",
        "email": "romain.naour@smile.fr",
        "time": "Thu Aug 27 23:21:23 2026 +0200"
      },
      "committer": {
        "name": "Julien Olivain",
        "email": "ju.o@free.fr",
        "time": "Tue Sep 01 23:00:29 2026 +0200"
      },
      "message": "linux: disable SSP support when needed\n\nx86 and x86_64 kernels \u003e\u003d 6.15 now requires ssp toolchain support\nwhen CONFIG_STACKPROTECTOR is enabled [1].\n\nFor toolchains without SSP support, make sure to disable\nCONFIG_STACKPROTECTOR to avoid link issues when building kernel\nmodules.\n\n  MODPOST Module.symvers\n  ERROR: modpost: \"__stack_chk_guard\" [drivers/\u003cmodule\u003e.ko] undefined!\n\nWhile the SSP support is mandatory for glibc and musl based toolchains\n[2], it\u0027s still optional for uClibc-ng based toolchains and not enabled\nby default when building a new toolchain.\n\nThe Toolchain builder project enabled recently the SSP support for all\nuClibc toolchains [3] to avoid such issue.\n\nBut x86 (32bits) musl based toolchains lack of SSP support due to a\nlong term gcc issue [4]. For a decade Alpine Linux, OpenWRT and Yocto\npovide additional gcc and musl patches to workaround the gcc issue [5]\n\nWe may consider in the long term removing the support for toolchains\nwithout SSP and doing so removing x86 (32bits) musl toolchain.\n\nFixes:\nhttps://gitlab.com/buildroot.org/toolchains-builder/-/jobs/15832356731 (x86-64--uclibc--bleeding-edge_test)\nhttps://gitlab.com/buildroot.org/toolchains-builder/-/jobs/15832356104 (x86-64--uclibc--stable_test)\n\nhttps://gitlab.com/buildroot.org/toolchains-builder/-/jobs/15832355429 (x86-64-core-i7--uclibc--bleeding-edge_test)\nhttps://gitlab.com/buildroot.org/toolchains-builder/-/jobs/15832354341 (x86-64-core-i7--uclibc--stable_test)\n\nhttps://gitlab.com/buildroot.org/toolchains-builder/-/jobs/15832326525 (x86-64-v2--uclibc--bleeding-edge_test)\nhttps://gitlab.com/buildroot.org/toolchains-builder/-/jobs/15832316220 (x86-64-v2--uclibc--stable_test)\n\nhttps://gitlab.com/buildroot.org/toolchains-builder/-/jobs/15819139512 (x86-i686--uclibc--stable_test)\nhttps://gitlab.com/buildroot.org/toolchains-builder/-/jobs/15819139511 (x86-i686--uclibc--bleeding-edge_test)\n\nhttps://gitlab.com/buildroot.org/toolchains-builder/-/jobs/15819139510 (x86-i686--musl--stable_test)\nhttps://gitlab.com/buildroot.org/toolchains-builder/-/jobs/15819139509 (x86-i686--musl--bleeding-edge_test)\n\nhttps://gitlab.com/buildroot.org/toolchains-builder/-/jobs/15819139506 (x86-core2--uclibc--stable_test)\nhttps://gitlab.com/buildroot.org/toolchains-builder/-/jobs/15819139505 (x86-core2--uclibc--bleeding-edge_test)\n\nhttps://gitlab.com/buildroot.org/toolchains-builder/-/jobs/15819139504 (x86-core2--musl--stable_test)\nhttps://gitlab.com/buildroot.org/toolchains-builder/-/jobs/15819139503 (x86-core2--musl--bleeding-edge_test)\n\n[1] https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/commit/?id\u003d0ee2689b9374d6fd5f43b703713a53227\n[2] e811f5154944147e4fceb8d199321aba91070587\n[3] https://gitlab.com/buildroot.org/toolchains-builder/-/commit/90413f665735e1786cca2403cd1ff997920c99ae\n[4] https://www.openwall.com/lists/musl/2016/12/04/2\n[5] https://git.alpinelinux.org/aports/tree/main/musl/APKBUILD#n65\n    https://git.alpinelinux.org/aports/tree/main/gcc/0018-Alpine-musl-package-provides-libssp_nonshared.a.-We-.patch\n    https://github.com/openwrt/openwrt/blob/v25.12.5/toolchain/gcc/patches-15.x/230-musl_libssp.patch\n    https://github.com/openwrt/openwrt/blob/v25.12.5/toolchain/musl/patches/200-add_libssp_nonshared.patch\n    https://github.com/openembedded/openembedded-core/commit/77fb841f2e747dc7fb5e9234d870a7a32a74d09b\n\nCc: Thomas Petazzoni \u003cthomas.petazzoni@bootlin.com\u003e\nSigned-off-by: Romain Naour \u003cromain.naour@smile.fr\u003e\nSigned-off-by: Julien Olivain \u003cju.o@free.fr\u003e\n"
    },
    {
      "commit": "45636d67c93e3722543e181900bcb74a52b01bbb",
      "tree": "48ffda71a5ac68f087ac262fc4d164e49e607567",
      "parents": [
        "e56c6b32fdae124cf898ef823177ad7892b30538"
      ],
      "author": {
        "name": "Romain Naour",
        "email": "romain.naour@smile.fr",
        "time": "Mon Aug 31 22:57:03 2026 +0200"
      },
      "committer": {
        "name": "Julien Olivain",
        "email": "ju.o@free.fr",
        "time": "Tue Sep 01 21:31:01 2026 +0200"
      },
      "message": "support/testing: TestMdnsd: improve test reliability\n\nThe mdnsd runtime test can randomly fail on slow runners.\n\nIt\u0027s hard to reproduce locally (only one failure after a few attempts)\nbut we can reproduce it easily by removing the while loop entirely.\n\nIt turns out that mdnsd is started by S50mdnsd before the\nemulator.login() change the system date:\n\n  [BRTEST# date -s @1788032864\n  Sat Aug 29 19:47:44 UTC 2026\n\nSince the minimal rootfs.cpio generated\tfor TestMdnsd doesn\u0027t have any\nntp client installed, it start with \"January 1, 1970\".\n\nThe date change may cause some issue to the mdnsd daemon which blocks\nany response from mquery command.\n\nWhen the problem occurs, \"mquery -T _http._tcp\" reply is empty:\n\n  # mquery -T _http._tcp\n  Querying _http._tcp.local. for PTR (12) ... press Ctrl-C to stop\n\nTo workaround the issue, restart mdnsd manually.\n\nFixes:\nhttps://gitlab.com/buildroot.org/buildroot/-/jobs/16185948555\n\nSigned-off-by: Romain Naour \u003cromain.naour@smile.fr\u003e\nSigned-off-by: Julien Olivain \u003cju.o@free.fr\u003e\n"
    },
    {
      "commit": "e56c6b32fdae124cf898ef823177ad7892b30538",
      "tree": "fffaf0a64f99a544d46493e35634cd2c0bfbdfe6",
      "parents": [
        "45acb281caa9fa30799426ba7ef4694c0b61fa85"
      ],
      "author": {
        "name": "Romain Naour",
        "email": "romain.naour@smile.fr",
        "time": "Mon Aug 31 22:57:02 2026 +0200"
      },
      "committer": {
        "name": "Julien Olivain",
        "email": "ju.o@free.fr",
        "time": "Tue Sep 01 21:31:01 2026 +0200"
      },
      "message": "Revert \"support/testing: TestMdnsd: improve test reliability\"\n\nThe issue was reproduced in 2026.08-rc3 Gitlab-CI pipeline [1] despite\nthe fix applied.\n\n[1] https://gitlab.com/buildroot.org/buildroot/-/jobs/16185948555\n\nThis reverts commit b4b1de1f7f1865af25f5dc47beac06a37b929c4a.\n\nSigned-off-by: Romain Naour \u003cromain.naour@smile.fr\u003e\nSigned-off-by: Julien Olivain \u003cju.o@free.fr\u003e\n"
    },
    {
      "commit": "45acb281caa9fa30799426ba7ef4694c0b61fa85",
      "tree": "d9515de8b3684e4bda52830bc72d25342d4bd064",
      "parents": [
        "a31afeb8a4c5f964e657f8b5753868eef0303081"
      ],
      "author": {
        "name": "Fiona Klute (othermo GmbH)",
        "email": "fiona.klute@gmx.de",
        "time": "Mon Aug 31 19:53:58 2026 +0200"
      },
      "committer": {
        "name": "Julien Olivain",
        "email": "ju.o@free.fr",
        "time": "Tue Sep 01 21:14:52 2026 +0200"
      },
      "message": "package/dracut: pass HOST_CONFIGURE_OPTS to make\n\nDracut-internal executables were linked against system libraries,\ninstead of Buildroot host packages. For example:\n\n$ ldd host/lib/dracut/dracut-install\n\tlinux-vdso.so.1 (0x00007f578cf06000)\n\tlibc.so.6 \u003d\u003e /usr/lib/x86_64-linux-gnu/libc.so.6 (0x00007f578cccd000)\n\tlibkmod.so.2 \u003d\u003e /usr/lib/x86_64-linux-gnu/libkmod.so.2 (0x00007f578ccb1000)\n\t/lib64/ld-linux-x86-64.so.2 (0x00007f578cf08000)\n\tlibcrypto.so.3 \u003d\u003e /usr/lib/x86_64-linux-gnu/libcrypto.so.3 (0x00007f578c600000)\n\tlibz.so.1 \u003d\u003e /usr/lib/x86_64-linux-gnu/libz.so.1 (0x00007f578cc92000)\n\tlibzstd.so.1 \u003d\u003e /usr/lib/x86_64-linux-gnu/libzstd.so.1 (0x00007f578c536000)\n\nThe reason is that Dracut is not a \"real\" autoconf package, and the\nhand-written ./configure script does not preserve LDFLAGS for\nmake. Pass the environment variables directly to fix this.\n\nSigned-off-by: Fiona Klute (othermo GmbH) \u003cfiona.klute@gmx.de\u003e\n[Julien: add comment in dracut.mk]\nSigned-off-by: Julien Olivain \u003cju.o@free.fr\u003e\n"
    },
    {
      "commit": "a31afeb8a4c5f964e657f8b5753868eef0303081",
      "tree": "8dc759e24ad480c1e4686b719903639a6e2b83b9",
      "parents": [
        "55a7ece9e53f2de0cd96294efeb38045bbd41bef"
      ],
      "author": {
        "name": "Bernd Kuhls",
        "email": "bernd@kuhls.net",
        "time": "Tue Sep 01 18:23:37 2026 +0200"
      },
      "committer": {
        "name": "Peter Korsgaard",
        "email": "peter@korsgaard.com",
        "time": "Tue Sep 01 21:07:36 2026 +0200"
      },
      "message": "package/ncmpc: fix build with fmt \u003e\u003d 12.2.0\n\nBuildroot commit cc5c36afffd71e6e01a9371f1a7316fc10a8e3f9 bumped fmt to\nversion 12.2.0 causing build errors with ncmpc which are fixed by adding\nan upstream patch.\n\nFixes:\nhttps://autobuild.buildroot.net/results/b97/b97146ba1b4996b644c564898f5633dd8c0d4b83/\n\nSigned-off-by: Bernd Kuhls \u003cbernd@kuhls.net\u003e\nSigned-off-by: Peter Korsgaard \u003cpeter@korsgaard.com\u003e\n"
    },
    {
      "commit": "f92220f16b3b0c24cadae6f92a662d2ac22a879d",
      "tree": "841581fe66c035a21f53967a5dc63908175568db",
      "parents": [
        "6c3c5f8728ba9782fe11867723e0ec25b89c72f6"
      ],
      "author": {
        "name": "Neal Frager",
        "email": "neal.frager@amd.com",
        "time": "Tue Sep 01 09:44:43 2026 +0100"
      },
      "committer": {
        "name": "Peter Korsgaard",
        "email": "peter@korsgaard.com",
        "time": "Tue Sep 01 20:11:39 2026 +0200"
      },
      "message": "board/xilinx: remove xilinx_2026.1/linux.hash\n\nNow that all Xilinx boards have been bumped to Linux 6.18.40, remove the hash\nfor the xlnx_rebase_v6.18_LTS_2026.1 release tag.\n\nSigned-off-by: Neal Frager \u003cneal.frager@amd.com\u003e\nSigned-off-by: Peter Korsgaard \u003cpeter@korsgaard.com\u003e\n"
    },
    {
      "commit": "6c3c5f8728ba9782fe11867723e0ec25b89c72f6",
      "tree": "bcd8a4f440d5022402bb7d5e74db7a17a3934828",
      "parents": [
        "0dae674d98c951699bb12d9c2686fbdc2f4d036f"
      ],
      "author": {
        "name": "Neal Frager",
        "email": "neal.frager@amd.com",
        "time": "Tue Sep 01 09:44:42 2026 +0100"
      },
      "committer": {
        "name": "Peter Korsgaard",
        "email": "peter@korsgaard.com",
        "time": "Tue Sep 01 20:11:27 2026 +0200"
      },
      "message": "configs/versal2_*: bump to Linux 6.18.40\n\nBump the versal2 defconfig to Linux 6.18.40.\n\nRun tested on a versal2 vek385 evaluation board.\n\nSigned-off-by: Neal Frager \u003cneal.frager@amd.com\u003e\nSigned-off-by: Peter Korsgaard \u003cpeter@korsgaard.com\u003e\n"
    },
    {
      "commit": "0dae674d98c951699bb12d9c2686fbdc2f4d036f",
      "tree": "facf38798834f0306b0e56484c96eec81ec45a4b",
      "parents": [
        "b1009287df7fda4e90ce3e95bbae1f08288a78dc"
      ],
      "author": {
        "name": "Neal Frager",
        "email": "neal.frager@amd.com",
        "time": "Tue Sep 01 09:44:41 2026 +0100"
      },
      "committer": {
        "name": "Peter Korsgaard",
        "email": "peter@korsgaard.com",
        "time": "Tue Sep 01 20:10:43 2026 +0200"
      },
      "message": "configs/versal_*: bump to Linux 6.18.40\n\nBump the versal defconfigs to Linux 6.18.40.\n\nRun tested on a versal vek280 evaluation board.\n\nSigned-off-by: Neal Frager \u003cneal.frager@amd.com\u003e\nSigned-off-by: Peter Korsgaard \u003cpeter@korsgaard.com\u003e\n"
    },
    {
      "commit": "b1009287df7fda4e90ce3e95bbae1f08288a78dc",
      "tree": "2551f3c629adb1c003d4f97701ab5727459a12cc",
      "parents": [
        "cfd58dedd126de6d3e7f0588e2f5f2d7e163d336"
      ],
      "author": {
        "name": "Neal Frager",
        "email": "neal.frager@amd.com",
        "time": "Tue Sep 01 09:44:40 2026 +0100"
      },
      "committer": {
        "name": "Peter Korsgaard",
        "email": "peter@korsgaard.com",
        "time": "Tue Sep 01 20:10:12 2026 +0200"
      },
      "message": "configs/zynqmp_*: bump to Linux 6.18.40\n\nBump the zynqmp defconfigs to Linux 6.18.40.\n\nRun tested on a zynqmp zcu102 evaluation board.\nRun tested on a kria kv260 evaluation board.\n\nSigned-off-by: Neal Frager \u003cneal.frager@amd.com\u003e\nSigned-off-by: Peter Korsgaard \u003cpeter@korsgaard.com\u003e\n"
    },
    {
      "commit": "cfd58dedd126de6d3e7f0588e2f5f2d7e163d336",
      "tree": "9e7e5d524ed17756e2655fe864edfa2b691908ed",
      "parents": [
        "1a87a2669d9dac045f1c088bf6acaf4e46e53b38"
      ],
      "author": {
        "name": "Neal Frager",
        "email": "neal.frager@amd.com",
        "time": "Tue Sep 01 09:44:39 2026 +0100"
      },
      "committer": {
        "name": "Peter Korsgaard",
        "email": "peter@korsgaard.com",
        "time": "Tue Sep 01 20:09:49 2026 +0200"
      },
      "message": "configs/zynq_*: bump to Linux 6.18.40\n\nBump the zynq defconfigs to Linux 6.18.40.\n\nRun-tested on a ZC702 Evaluation Board.\n\nSigned-off-by: Neal Frager \u003cneal.frager@amd.com\u003e\nSigned-off-by: Peter Korsgaard \u003cpeter@korsgaard.com\u003e\n"
    },
    {
      "commit": "1a87a2669d9dac045f1c088bf6acaf4e46e53b38",
      "tree": "c6221663c3e029175bdfd10b1c9d6587aa271855",
      "parents": [
        "798741f4dc8da3baed0c7947d459d9d4223d90d4"
      ],
      "author": {
        "name": "Neal Frager",
        "email": "neal.frager@amd.com",
        "time": "Tue Sep 01 09:44:38 2026 +0100"
      },
      "committer": {
        "name": "Peter Korsgaard",
        "email": "peter@korsgaard.com",
        "time": "Tue Sep 01 20:09:29 2026 +0200"
      },
      "message": "board/xilinx: add Linux 6.18.40 hash\n\nAdd the hash for the Xilinx Linux 6.18.40 release tag.\n\nSigned-off-by: Neal Frager \u003cneal.frager@amd.com\u003e\nSigned-off-by: Peter Korsgaard \u003cpeter@korsgaard.com\u003e\n"
    },
    {
      "commit": "55a7ece9e53f2de0cd96294efeb38045bbd41bef",
      "tree": "6d9898b9d03608b6788008bd31cbe438c6327ef3",
      "parents": [
        "db3d0d44acae1bda1fb5d06cbdd01f7fe3621857"
      ],
      "author": {
        "name": "Thomas Petazzoni",
        "email": "thomas.petazzoni@bootlin.com",
        "time": "Sat Aug 29 00:11:44 2026 +0200"
      },
      "committer": {
        "name": "Peter Korsgaard",
        "email": "peter@korsgaard.com",
        "time": "Tue Sep 01 16:10:56 2026 +0200"
      },
      "message": "package/dpdk: make the libvirt dependency explicit\n\nexamples/vm_power_manager/meson.build in DPDK detects the presence of\nlibvirt:\n\nopt_dep \u003d cc.find_library(\u0027virt\u0027, required : false)\n\nand then builds some examples or not depending on the availability of\nlibvirt. Let\u0027s make this optional dependency explicit in dpdk.mk, even\nif there\u0027s no explicit enable/disable option for it.\n\nSigned-off-by: Thomas Petazzoni \u003cthomas.petazzoni@bootlin.com\u003e\nSigned-off-by: Peter Korsgaard \u003cpeter@korsgaard.com\u003e\n"
    },
    {
      "commit": "db3d0d44acae1bda1fb5d06cbdd01f7fe3621857",
      "tree": "35159e0f94a258d25b50bdcbe641b642098c94f7",
      "parents": [
        "0742e67d2f94118d4227d29e409dc50de0acfb07"
      ],
      "author": {
        "name": "Thomas Petazzoni",
        "email": "thomas.petazzoni@bootlin.com",
        "time": "Sat Aug 29 00:11:43 2026 +0200"
      },
      "committer": {
        "name": "Peter Korsgaard",
        "email": "peter@korsgaard.com",
        "time": "Tue Sep 01 16:10:34 2026 +0200"
      },
      "message": "package/dpdk: fix example build issue when libvirt is present\n\nWhen libvirt is present before DPDK is built, some additional examples\nare compiled. One of them fails to build due to a missing \u003cstdlib.h\u003e\ninclude. Let\u0027s import a patch from OpenSuse, that we have submitted\nupstream, to fix this issue.\n\nWe couldn\u0027t find any autobuilder failure for this issue, but the\nfollowing defconfig allows to reproduce the failure:\n\nBR2_aarch64\u003dy\nBR2_TOOLCHAIN_EXTERNAL\u003dy\nBR2_TOOLCHAIN_EXTERNAL_BOOTLIN\u003dy\nBR2_TOOLCHAIN_EXTERNAL_BOOTLIN_AARCH64_GLIBC_STABLE\u003dy\nBR2_ROOTFS_DEVICE_CREATION_DYNAMIC_EUDEV\u003dy\nBR2_PACKAGE_DPDK\u003dy\nBR2_PACKAGE_DPDK_EXAMPLES\u003dy\nBR2_PACKAGE_LIBVIRT\u003dy\n\nThe problem exists since DPDK v19.11, so it has been in Buildroot\nsince DPDK was introduced in commit\nd17d1b6bde95d46376c4fe93e8ca1a1f9da6c179.\n\nSigned-off-by: Thomas Petazzoni \u003cthomas.petazzoni@bootlin.com\u003e\nSigned-off-by: Peter Korsgaard \u003cpeter@korsgaard.com\u003e\n"
    },
    {
      "commit": "0742e67d2f94118d4227d29e409dc50de0acfb07",
      "tree": "bcf4e5946ad8ac55403bbb7c5993dcde0ac5c378",
      "parents": [
        "8dea6e7c089cb5d4fa7bd788fc6e07c9f19f70a8"
      ],
      "author": {
        "name": "Dario Binacchi",
        "email": "dario.binacchi@amarulasolutions.com",
        "time": "Sun Aug 30 17:48:11 2026 +0200"
      },
      "committer": {
        "name": "Peter Korsgaard",
        "email": "peter@korsgaard.com",
        "time": "Tue Sep 01 16:09:26 2026 +0200"
      },
      "message": "package/drogon: Fix incomplete \u0027struct tm\u0027 type on uClibc\n\nAdd a patch including \u003ctime.h\u003e in Date.h to fix the following build\nfailure:\n\n  Date.cc:98:28: error: return type \u0027struct trantor::tm\u0027 is incomplete\n     98 | struct tm Date::tmStruct() const\n        |                            ^~~~~\n\nFixes:\n- https://autobuild.buildroot.org/results/e48e0fc1b95a8ad5de964b1e6d12bc45ac39f0b4\n\nSigned-off-by: Dario Binacchi \u003cdario.binacchi@amarulasolutions.com\u003e\nSigned-off-by: Peter Korsgaard \u003cpeter@korsgaard.com\u003e\n"
    },
    {
      "commit": "8dea6e7c089cb5d4fa7bd788fc6e07c9f19f70a8",
      "tree": "a7d1b9f3e5121b0f654a7e6127dc660ceb311f66",
      "parents": [
        "88a4958afaacf74bc513dfaef21c611ccd861f5e"
      ],
      "author": {
        "name": "Julien Olivain",
        "email": "ju.o@free.fr",
        "time": "Mon Aug 31 21:49:10 2026 +0200"
      },
      "committer": {
        "name": "Peter Korsgaard",
        "email": "peter@korsgaard.com",
        "time": "Mon Aug 31 22:39:22 2026 +0200"
      },
      "message": "package/perl: apply perl-cross patch only on target perl\n\nBuildroot commit [1] (package/perl: fix build issue with musl)\nintroduced a patch that is meant to be applied on top of perl-cross,\nwhich is extracted on top of perl only in the target variant.\n\nSince the patch was introduced as a normal package patch, the Buildroot\ninfra is trying to always apply it, even for the host package variant.\nSince perl-cross is not extracted for the host variant, some patched\nfiles are missing. In that case, the host-perl is failing with error:\n\n    \u003e\u003e\u003e host-perl 5.42.3 Patching\n    Applying 0001-configure-keep-_GNU_SOURCE-in-build-flags.patch using patch:\n    can\u0027t find file to patch at input line 46\n\nThis commit fixes the issue by moving the package patch in a dedicated\n\"perl-cross\" subdirectory, to make sure it will no longer be applied by\nthe infra. We apply the patch only for the target package variant using\na _POST_PATCH_HOOKS hook.\n\nFixes:\n- [1]\n- https://gitlab.com/buildroot.org/buildroot/-/jobs/16185948610 (TestPerlXMLLibXML)\n- ...and few other tests requiring host-perl\n\n[1] https://gitlab.com/buildroot.org/buildroot/-/commit/d950fff290b1318fd72c7f09fedbd1b87b96155f\n\nSigned-off-by: Julien Olivain \u003cju.o@free.fr\u003e\nSigned-off-by: Peter Korsgaard \u003cpeter@korsgaard.com\u003e\n"
    },
    {
      "commit": "88a4958afaacf74bc513dfaef21c611ccd861f5e",
      "tree": "257614b268cd31c17f661b4cfee26864491a1989",
      "parents": [
        "3577d1442efc8b6cdc396008bf867845319d508a"
      ],
      "author": {
        "name": "Thomas Petazzoni",
        "email": "thomas.petazzoni@bootlin.com",
        "time": "Fri Aug 28 21:40:56 2026 +0200"
      },
      "committer": {
        "name": "Peter Korsgaard",
        "email": "peter@korsgaard.com",
        "time": "Mon Aug 31 22:35:57 2026 +0200"
      },
      "message": "package/libnfs: fix gnutls support\n\nIn Buildroot commit a035a0f99fa3bbeca776d741bbdeb6c04b3b35c8, libnfs\nwas bumped from 5.0.3 to 6.0.2, and 6.0.2 brought optional gnutls\nsupport.\n\nUnfortunately, the gnutls support was a bit buggy, as the libnfs\nlibrary ends up using gnutls symbols without being linked to\nlibgnutls, causing build failures down the road when other packages\ntry to link against libnfs.\n\nWe backport 3 commits from upstream 6.0.2..7.0.0 to address this\nissue.\n\nFixes:\n\n  https://autobuild.buildroot.net/results/b070248b2bceaceaaed8e826b1247ccfba1ba9fb\n  https://autobuild.buildroot.net/results/e1461b76121addd8f04f08819b2e3e453a12c679\n  https://autobuild.buildroot.net/results/87c79193d2ea86f47e36232fe514837ad99c5f30\n\nSigned-off-by: Thomas Petazzoni \u003cthomas.petazzoni@bootlin.com\u003e\nTested-by: Andreas Ziegler \u003cbr025@umbiko.net\u003e\nSigned-off-by: Peter Korsgaard \u003cpeter@korsgaard.com\u003e\n"
    },
    {
      "commit": "798741f4dc8da3baed0c7947d459d9d4223d90d4",
      "tree": "f28d28e38f57901d70ffb299e3f06a915a00b461",
      "parents": [
        "ed881dfca758240ee304e5a042ffc3f7c47f31d2"
      ],
      "author": {
        "name": "Christian Stewart",
        "email": "christian@aperture.us",
        "time": "Sun Aug 30 20:10:29 2026 -0400"
      },
      "committer": {
        "name": "Julien Olivain",
        "email": "ju.o@free.fr",
        "time": "Mon Aug 31 22:00:08 2026 +0200"
      },
      "message": "package/go: new major version 1.27\n\nBump to go1.27.0. The go-bootstrap-stage5 package (go1.25.x) still\nsatisfies the bootstrap requirement, so no bootstrap stage changes are\nneeded.\n\nRemove the workaround for https://github.com/golang/go/issues/77436,\nwhich the go.mk comment scheduled for removal at this bump: restore the\nplain CGO_CFLAGS and CGO_CXXFLAGS settings in HOST_GO_TARGET_ENV.\n\nhttps://go.dev/doc/go1.27#bootstrap\n\nSigned-off-by: Christian Stewart \u003cchristian@aperture.us\u003e\nSigned-off-by: Julien Olivain \u003cju.o@free.fr\u003e\n"
    },
    {
      "commit": "3577d1442efc8b6cdc396008bf867845319d508a",
      "tree": "e4f0ebbb2172971bd713f35c877e3bb4e48b89ce",
      "parents": [
        "913512e3028159aefb4b26062ee11b960e6e24a2"
      ],
      "author": {
        "name": "Bernd Kuhls",
        "email": "bernd@kuhls.net",
        "time": "Mon Aug 31 00:16:06 2026 +0200"
      },
      "committer": {
        "name": "Peter Korsgaard",
        "email": "peter@korsgaard.com",
        "time": "Mon Aug 31 21:30:33 2026 +0200"
      },
      "message": "package/proftpd: security bump version to 1.3.9d\n\nhttps://github.com/proftpd/proftpd/blob/v1.3.9d/NEWS\n\nVersion 1.3.9b fixes CVE-2026-44331.\n\nSwitched to sha256 tarball hash provided by upstream.\n\nSigned-off-by: Bernd Kuhls \u003cbernd@kuhls.net\u003e\nSigned-off-by: Peter Korsgaard \u003cpeter@korsgaard.com\u003e\n"
    },
    {
      "commit": "913512e3028159aefb4b26062ee11b960e6e24a2",
      "tree": "e9e0661fec4ef0280a8c1a20a1de546251ac400c",
      "parents": [
        "4c504ef75df4caf58acd20c02c9b2993708b1390"
      ],
      "author": {
        "name": "Jimmy Durand Wesolowski",
        "email": "jimmy.wesolowski@mobileye.com",
        "time": "Mon Aug 31 19:09:41 2026 +0300"
      },
      "committer": {
        "name": "Peter Korsgaard",
        "email": "peter@korsgaard.com",
        "time": "Mon Aug 31 21:10:23 2026 +0200"
      },
      "message": "package/openssh: ensure libxcrypt is enabled to provide a crypt() implementation\n\nWhen OpenSSL is enabled, if DES support is enabled, OpenSSH uses\nDES_crypt. However, without OpenSSL or its DES support, there is no\navailable crypt() implementation for OpenSSH libopenbsd-compat xcrypt()\nfunction, resulting in the following error:\n\n.../host/bin/i686-buildroot-linux-gnu-gcc -o sshd-auth sshd-auth.o\n  auth2-methods.o auth-rhosts.o auth-passwd.o sshpty.o sshlogin.o\n  servconf.o serverloop.o auth.o auth2.o auth-options.o session.o\n  auth2-chall.o groupaccess.o auth-bsdauth.o auth2-hostbased.o\n  auth2-kbdint.o auth2-none.o auth2-passwd.o auth2-pubkey.o\n  auth2-pubkeyfile.o auth2-gss.o gss-serv.o gss-serv-krb5.o\n  monitor_wrap.o auth-krb5.o audit.o audit-bsm.o audit-linux.o\n  platform.o loginrec.o auth-pam.o auth-shadow.o auth-sia.o\n  sandbox-null.o sandbox-rlimit.o sandbox-darwin.o\n  sandbox-seccomp-filter.o sandbox-capsicum.o sandbox-solaris.o\n  sftp-server.o sftp-common.o uidswap.o ssh-pkcs11-client.o\n  ssh-sk-client.o -L. -Lopenbsd-compat/ -D_LARGEFILE_SOURCE\n  -D_LARGEFILE64_SOURCE -D_FILE_OFFSET_BITS\u003d64 -O2 -g0\n  -D_FORTIFY_SOURCE\u003d1 -Wl,-z,relro -Wl,-z,now -Wl,-z,noexecstack\n  -fstack-protector-strong -pie -lssh -lopenbsd-compat\n  -L.../host/bin/../i686-buildroot-linux-gnu/sysroot/usr/lib\n  -lssl -lcrypto -lcrypto -lz\n.../host/lib/gcc/i686-buildroot-linux-gnu/15.3.0/../../../../\n  i686-buildroot-linux-gnu/bin/ld:\n  openbsd-compat//libopenbsd-compat.a(xcrypt.o): in function `xcrypt\u0027:\nxcrypt.c:(.text+0x51): undefined reference to `crypt\u0027\n.../host/lib/gcc/i686-buildroot-linux-gnu/15.3.0/../../../../\n  i686-buildroot-linux-gnu/bin/ld:\nopenbsd-compat//libopenbsd-compat.a(xcrypt.o): in function `xcrypt\u0027:\nxcrypt.c:(.text+0x51): undefined reference to `crypt\u0027 collect2: error:\nld returned 1 exit status make[2]: *** [Makefile:233: sshd-auth] Error\n1 make[2]: *** Waiting for unfinished jobs....  collect2: error: ld\nreturned 1 exit status make[2]: *** [Makefile:230: sshd-session] Error\n1 make[1]: *** [package/pkg-generic.mk:273:\n.../build/openssh-10.4p1/.stamp_built]\nError 2 make: *** [Makefile:83: _all] Error 2\n\nThis commit enables BR2_PACKAGE_LIBXCRYPT with OpenSSH as long as\nglibc is used. Since \"sshd-auth\" is compiled regardless of\nBR2_PACKAGE_OPENSSH_SERVER, we need to enable it with BR2_PACKAGE_OPENSSH.\n\nSigned-off-by: Jimmy Durand Wesolowski \u003cjimmy.wesolowski@mobileye.com\u003e\nSigned-off-by: Peter Korsgaard \u003cpeter@korsgaard.com\u003e\n"
    },
    {
      "commit": "4c504ef75df4caf58acd20c02c9b2993708b1390",
      "tree": "8cc63170afb7b04254ff8f90e055906375884577",
      "parents": [
        "cb18f3a74a49a62119857ce1ab712ff4528a1d3d"
      ],
      "author": {
        "name": "Bernd Kuhls",
        "email": "bernd@kuhls.net",
        "time": "Mon Aug 31 20:30:47 2026 +0200"
      },
      "committer": {
        "name": "Peter Korsgaard",
        "email": "peter@korsgaard.com",
        "time": "Mon Aug 31 21:08:46 2026 +0200"
      },
      "message": "package/expat: security bump version to 2.8.4\n\nhttps://github.com/libexpat/libexpat/blob/R_2_8_4/expat/Changes\nhttps://blog.hartwork.org/posts/expat-2-8-4-released/\n\nFixes CVE-2026-66046, CVE-2026-76641, CVE-2026-76956 \u0026 CVE-2026-76957.\n\nSigned-off-by: Bernd Kuhls \u003cbernd@kuhls.net\u003e\nSigned-off-by: Peter Korsgaard \u003cpeter@korsgaard.com\u003e\n"
    },
    {
      "commit": "cb18f3a74a49a62119857ce1ab712ff4528a1d3d",
      "tree": "070c2168d98b0f674807004be021a542ec9db679",
      "parents": [
        "2eefcb245fa5da3c9f469bc7478a524b7bc1e6db"
      ],
      "author": {
        "name": "Titouan Christophe via buildroot",
        "email": "buildroot@buildroot.org",
        "time": "Mon Aug 31 16:05:30 2026 +0200"
      },
      "committer": {
        "name": "Fiona Klute",
        "email": "fiona.klute@gmx.de",
        "time": "Mon Aug 31 16:31:35 2026 +0200"
      },
      "message": "package/vim: fix hash for README.txt\n\nBuildroot commit 297f6f1921960c1735bca34b5a80138e2a8261f4 updated vim.\nHowever README.txt (used as part of the license hash check) has been updated\nupstream in [1], without any corresponding hash change in Buildroot, leading\nto build failure.\n\nFixes: https://gitlab.com/buildroot.org/buildroot/-/work_items/189\n\nNB: This also affects 2025.02.x \u0026 2026.05.x, so this patch\n    should be applied there too.\n\n[1] https://github.com/vim/vim/commit/e7e21018fc0b60c153c8e668f696d95e574cc5a4\n\nSigned-off-by: Titouan Christophe \u003ctitouan.christophe@mind.be\u003e\nSigned-off-by: Fiona Klute \u003cfiona.klute@gmx.de\u003e\n"
    },
    {
      "commit": "2eefcb245fa5da3c9f469bc7478a524b7bc1e6db",
      "tree": "3f9a03377fceb9ad60baefea576db8148e866195",
      "parents": [
        "2d7d9d8200232bce215d87cadda443ba74308f01"
      ],
      "author": {
        "name": "Thomas Petazzoni",
        "email": "thomas.petazzoni@bootlin.com",
        "time": "Fri Aug 28 19:20:00 2026 +0200"
      },
      "committer": {
        "name": "Peter Korsgaard",
        "email": "peter@korsgaard.com",
        "time": "Mon Aug 31 07:59:29 2026 +0200"
      },
      "message": "docs/website: patchwork is now at patchwork.buildroot.org\n\npatchwork.buildroot.org used to be a redirect to patchwork.ozlabs.org,\nbut we are now running our own instance, so let\u0027s adjust the links in\nthe website accordingly.\n\nSigned-off-by: Thomas Petazzoni \u003cthomas.petazzoni@bootlin.com\u003e\nSigned-off-by: Peter Korsgaard \u003cpeter@korsgaard.com\u003e\n"
    },
    {
      "commit": "2d7d9d8200232bce215d87cadda443ba74308f01",
      "tree": "b6842545d4c6fefb94c98f25e0e941caf96c1d0f",
      "parents": [
        "911dc3a5d28ca33a1e44358a5c4760a6eba1f9ae"
      ],
      "author": {
        "name": "Thomas Petazzoni",
        "email": "thomas.petazzoni@bootlin.com",
        "time": "Fri Aug 28 19:19:59 2026 +0200"
      },
      "committer": {
        "name": "Peter Korsgaard",
        "email": "peter@korsgaard.com",
        "time": "Mon Aug 31 07:58:52 2026 +0200"
      },
      "message": "docs/manual: patchwork is now at patchwork.buildroot.org\n\npatchwork.buildroot.org used to be a redirect to patchwork.ozlabs.org,\nbut we are now running our own instance, so let\u0027s adjust the links in\nthe manual accordingly.\n\nSigned-off-by: Thomas Petazzoni \u003cthomas.petazzoni@bootlin.com\u003e\nSigned-off-by: Peter Korsgaard \u003cpeter@korsgaard.com\u003e\n"
    },
    {
      "commit": "911dc3a5d28ca33a1e44358a5c4760a6eba1f9ae",
      "tree": "2c23c3b566ecd138c9568d8b3aa5ac106b8ea74e",
      "parents": [
        "6bd5918183ee656448252e0a3eec978c184ee36b"
      ],
      "author": {
        "name": "Bernd Kuhls",
        "email": "bernd@kuhls.net",
        "time": "Sun Aug 30 21:41:53 2026 +0200"
      },
      "committer": {
        "name": "Julien Olivain",
        "email": "ju.o@free.fr",
        "time": "Sun Aug 30 22:38:46 2026 +0200"
      },
      "message": "package/libldns: security bump version to 1.9.2\n\nhttps://community.nlnetlabs.nl/t/ldns-1-9-1-released/3403\nhttps://community.nlnetlabs.nl/t/ldns-1-9-2-released/3404\n\"Please do not install ldns version 1.9.1 as it has a wrong .so version.\n Install ldns version 1.9.2 instead.\"\n\nFixes CVE-2026-10846.\n\nSigned-off-by: Bernd Kuhls \u003cbernd@kuhls.net\u003e\nSigned-off-by: Julien Olivain \u003cju.o@free.fr\u003e\n"
    },
    {
      "commit": "6bd5918183ee656448252e0a3eec978c184ee36b",
      "tree": "71bf8d1cf84fdac649e4c181450ea443f254369b",
      "parents": [
        "be382f6061216ca82a735d0992894c4e6fe5173a"
      ],
      "author": {
        "name": "Bernd Kuhls",
        "email": "bernd@kuhls.net",
        "time": "Sat Aug 29 20:57:53 2026 +0200"
      },
      "committer": {
        "name": "Julien Olivain",
        "email": "ju.o@free.fr",
        "time": "Sun Aug 30 18:53:13 2026 +0200"
      },
      "message": "package/freeswitch: security bump version to 1.11.3\n\nhttps://github.com/signalwire/freeswitch/releases/tag/v1.11.3\n\"This is an important release containing critical security fixes and\n stability improvements. [...] We strongly encourage all users to\n upgrade to v1.11.3 as soon as possible.\"\n\nSigned-off-by: Bernd Kuhls \u003cbernd@kuhls.net\u003e\nSigned-off-by: Julien Olivain \u003cju.o@free.fr\u003e\n"
    },
    {
      "commit": "be382f6061216ca82a735d0992894c4e6fe5173a",
      "tree": "35cf9d3b9953b6edaeba770b96b3f4cdcacc20c0",
      "parents": [
        "e1ec936cf732e50bddb588985a8d6738b43da3ac"
      ],
      "author": {
        "name": "Bernd Kuhls",
        "email": "bernd@kuhls.net",
        "time": "Sat Aug 29 21:07:55 2026 +0200"
      },
      "committer": {
        "name": "Julien Olivain",
        "email": "ju.o@free.fr",
        "time": "Sun Aug 30 18:24:23 2026 +0200"
      },
      "message": "package/{glibc, localedef}: security bump version to 2.44-36-g2d5421ffc\n\nFixes the following CVEs:\n\nCVE-2026-19499:\nhttps://gitlab.com/gnutools/glibc/-/commit/63b53df549451a5d69fcba6d7612ea99f517e8e3\n\nCVE-2026-77117:\nhttps://gitlab.com/gnutools/glibc/-/commit/6f9b2bfa500bf5d1cff5d990adfff4b71298dadd\n\nCVE-2026-80489:\nhttps://gitlab.com/gnutools/glibc/-/commit/cb61572ea3f773e1e1978f6c412cc36a30acdb0c\n\nAdded GLIBC_IGNORE_CVES for CVE-2026-19542 which was forgotten in\nbuildroot commit 58f31377389dd2f5090e4dd69deb4d5f994f88c0.\n\nSigned-off-by: Bernd Kuhls \u003cbernd@kuhls.net\u003e\nSigned-off-by: Julien Olivain \u003cju.o@free.fr\u003e\n"
    },
    {
      "commit": "ed881dfca758240ee304e5a042ffc3f7c47f31d2",
      "tree": "2823d5562c5e069fccb5e4a0f0e8162f30e18497",
      "parents": [
        "1982fdeaa4aa3d5656717bacffc4b1e78bfd6b26"
      ],
      "author": {
        "name": "Mattia Narducci",
        "email": "mattianarducci1@gmail.com",
        "time": "Sun Aug 16 21:56:09 2026 +0200"
      },
      "committer": {
        "name": "Thomas Petazzoni",
        "email": "thomas.petazzoni@bootlin.com",
        "time": "Sun Aug 30 00:15:38 2026 +0200"
      },
      "message": "package/ser2net: bump version to 4.6.8\n\nChangelog: https://sourceforge.net/p/ser2net/news\n\nUpdated licenses hashes due to upstream commit:\nhttps://github.com/cminyard/ser2net/commit/2bc83f09548dec25b0bec48e11a3ee1942fb3c3e\n\nDrop patch 0001 that was a backport of a upstream security fix.\n\nAdd a upstream patch to fix build against uClibc.\n\nSigned-off-by: Mattia Narducci \u003cmattianarducci1@gmail.com\u003e\nSigned-off-by: Thomas Petazzoni \u003cthomas.petazzoni@bootlin.com\u003e\n"
    },
    {
      "commit": "1982fdeaa4aa3d5656717bacffc4b1e78bfd6b26",
      "tree": "74431a26513ee1aa653a63260e6863abd4c22f17",
      "parents": [
        "e9c340a3947b7ae2c415bdbee6f76b568a257424"
      ],
      "author": {
        "name": "Mattia Narducci",
        "email": "mattianarducci1@gmail.com",
        "time": "Sun Aug 16 21:56:08 2026 +0200"
      },
      "committer": {
        "name": "Thomas Petazzoni",
        "email": "thomas.petazzoni@bootlin.com",
        "time": "Sat Aug 29 23:57:00 2026 +0200"
      },
      "message": "package/gensio: add portaudio optional dependency\n\nPortaudio is an optional dependency which is enabled by default since\nversion 2.7.3 when alsa-lib is not available:\nhttps://github.com/cminyard/gensio/commit/71eef5e3cef2232eed85c5cb604bdf5fe3ebf580\n\nSigned-off-by: Mattia Narducci \u003cmattianarducci1@gmail.com\u003e\nSigned-off-by: Thomas Petazzoni \u003cthomas.petazzoni@bootlin.com\u003e\n"
    }
  ],
  "next": "e9c340a3947b7ae2c415bdbee6f76b568a257424"
}
