Index | index by Group | index by Distribution | index by Vendor | index by creation date | index by Name | Mirrors | Help | Search |
Name: sequoia-octopus-librnp | Distribution: openSUSE Tumbleweed |
Version: 1.11.1 | Vendor: openSUSE |
Release: 2.1 | Build date: Thu Sep 25 22:01:55 2025 |
Group: Productivity/Networking/Security | Build host: reproducible |
Size: 8988560 | Source RPM: sequoia-octopus-librnp-1.11.1-2.1.src.rpm |
Packager: http://bugs.opensuse.org | |
Url: https://gitlab.com/sequoia-pgp/sequoia-octopus-librnp | |
Summary: librnp drop-in replacement using sequoia-pgp |
Sequoia Octopus' librnp is an alternative OpenPGP implementation for Mozilla Thunderbird. If installed it will replace the upstream Thunderbird OpenPGP backend based on Botan.
LGPL-2.0-or-later
* Thu Sep 25 2025 Adam Mizerski <adam@mizerski.pl> - use 'BuildRequires: rust' to avoid conflict with the recent changes in cargo-packaging * Wed Aug 06 2025 Adam Mizerski <adam@mizerski.pl> - update to 1.11.1 - This release fixes a DoS attack. An attacker can create an OpenPGP message that includes a zip bomb. Instead of aborting after having parsed a certain amount of data, the Octopus would parse the whole message. When processing a message that contains a zip bomb, this would cause Thunderbird to freeze for an unacceptably long time. This issue was reported by codean via our YesWeHack bug bounty program. * Thu May 08 2025 Adam Mizerski <adam@mizerski.pl> - update vendored packages (boo#1242627, CVE-2025-3416) * Mon Mar 17 2025 Adam Mizerski <adam@mizerski.pl> - update to 1.11.0 * Notable changes - Ported to sequoia-openpgp 2. This brings in the machinery to support RFC9580, but without further changes to Thunderbird, it will not be able to make use of newer keys. It might be able to decrypt SEIPDv2 messages, though. * Tue Aug 13 2024 Adam Mizerski <adam@mizerski.pl> - update to 1.10.0 * Notable fixes - We now properly destroy background threads when a library context is freed. Previously, this lead to thread and resource leaks for the ephemeral contexts created by Thunderbird. * Notable changes - If we don't support the RNP API version that Thunderbird requires, we now print a log message to stderr, which should be easier to discover than the message Thunderbird writes to the error console. - We use a more compact time representation in log messages now. * New functionality - rnp_dearmor * Thu Jul 25 2024 Adam Mizerski <adam@mizerski.pl> - update to 1.9.0+git.13.g03113af - make it compatible with current Thunderbird * Sun Jun 23 2024 Adam Mizerski <adam@mizerski.pl> - update to 1.9.0 - no upstream changelog * Tue Apr 16 2024 Adam Mizerski <adam@mizerski.pl> - added _constraints * Wed Mar 20 2024 Adam Mizerski <adam@mizerski.pl> - update to 1.8.1 - Update dependencies. * Mon Feb 26 2024 Adam Mizerski <adam@mizerski.pl> - update to 1.8.0 - Implement rnp_signature_get_features - Update dependencies. * Fri Jan 26 2024 Adam Mizerski <adam@mizerski.pl> - update to 1.7.0 (changelog extracted from git history) - Implement rnp_dump_packets_to_output. - Update h2 to fix RUSTSEC-2024-0003. - Update zerocopy to fix RUSTSEC-2023-0074. - Update shlex to fix RUSTSEC-2024-0006. - Fix password callback's key argument. Previously we passed a pointer to an openpgp::Cert to it, which makes no sense whatsoever, and we got away with that because Thunderbird didn't use it. That changed with https://hg.mozilla.org/comm-central/rev/23ca5f76f6339cc9a7949737204db36d27f0fd33 which uses a callback to discover which key needs to be unlocked to decrypt a message, then asks for the password outside of the callback context, then retries the decryption operation. This new callback asks for the passed key's fingerprint, which fails because we used to pass NULL there a lot. - Bump all dependencies. - cargo_audit is now part of cargo_vendor * Fri Dec 15 2023 Adam Mizerski <adam@mizerski.pl> - update to 1.6.1 - no upstream changelog * Thu Dec 14 2023 Adam Mizerski <adam@mizerski.pl> - update to 1.6.0 - no upstream changelog * Fri Mar 03 2023 Adam Mizerski <adam@mizerski.pl> - update 1.5.0 - Fix support for Thunderbird 102.7 (fixes #83). - Use sequoia-wot to calculate acceptance, based on trust-roots defined in GnuPG. - Filter out revoked and unsupported subkeys. - Misc fixes. * Wed Jan 25 2023 Adam Mizerski <adam@mizerski.pl> - added 117.patch - fixes building with rustc>=1.65 * Mon Jul 04 2022 Adam Mizerski <adam@mizerski.pl> - update to 1.4.1 - no upstream changelog - https://fosstodon.org/@hko/108574455812887315 - This release adds support for Thunderbird 102. * Sat May 07 2022 Adam Mizerski <adam@mizerski.pl> - update to 1.4.0 - no upstream changelog * Sat Apr 23 2022 Adam Mizerski <adam@mizerski.pl> - update to 1.3.0 - no upstream changelog - https://sequoia-pgp.org/blog/2022/04/22/202204-octopus-1.3.0/ - Fixes a bug that could lead to a loss of secret key material. - Make it compatible with Thunderbird 91.8.0. - Follow latest "Packaging Rust Software" guidelines - added _service, cargo_config - use cargo-packaging, instead of rust-packaging * Fri Mar 25 2022 Adam Mizerski <adam@mizerski.pl> - update to 1.2.2 - no upstream changelog - removed patch sequoia-octopus-librnp-v1.2.0-no-git.patch - resolved upstream
/usr/lib/thunderbird /usr/lib/thunderbird/librnp.so
Generated by rpm2html 1.8.1
Fabrice Bellet, Thu Oct 23 22:58:29 2025