<?xml version="1.0" encoding="UTF-8"?>
<cvrfdoc xmlns="http://www.icasi.org/CVRF/schema/cvrf/1.1" xmlns:cvrf="http://www.icasi.org/CVRF/schema/cvrf/1.1">
  <DocumentTitle xml:lang="en">Security update for fossil</DocumentTitle>
  <DocumentType>SUSE Patch</DocumentType>
  <DocumentPublisher Type="Vendor">
    <ContactDetails>security@suse.de</ContactDetails>
    <IssuingAuthority>SUSE Security Team</IssuingAuthority>
  </DocumentPublisher>
  <DocumentTracking>
    <Identification>
      <ID>openSUSE-SU-2021:1052-1</ID>
    </Identification>
    <Status>Final</Status>
    <Version>1</Version>
    <RevisionHistory>
      <Revision>
        <Number>1</Number>
        <Date>2021-07-17T18:05:52Z</Date>
        <Description>current</Description>
      </Revision>
    </RevisionHistory>
    <InitialReleaseDate>2021-07-17T18:05:52Z</InitialReleaseDate>
    <CurrentReleaseDate>2021-07-17T18:05:52Z</CurrentReleaseDate>
    <Generator>
      <Engine>cve-database/bin/generate-cvrf.pl</Engine>
      <Date>2017-02-24T01:00:00Z</Date>
    </Generator>
  </DocumentTracking>
  <DocumentNotes>
    <Note Title="Topic" Type="Summary" Ordinal="1" xml:lang="en">Security update for fossil</Note>
    <Note Title="Details" Type="General" Ordinal="2" xml:lang="en">This update for fossil fixes the following issues:

fossil 2.16:

  * Add the fossil patch command
  * Improve the fossil ui command to work on check-out directories
    and remote machines
  * web UI improvements
  * Add fossil bisect run command for improved automation of bisects
  * Improve fossil merge handling of renames
  * wiki now defaults to markdown
  * email alerts can now be set to expire to prevent sending mail
    to abandoned accounts forever

fossil 2.15.2:

  * Fix the client-side TLS so that it verifies that the server
    hostname matches its certificate (boo#1187988)

fossil 2.15.1:

  * fix access to tables starting 'fx_' in ticket report

fossil 2.15:

  * Relax default Content Security policy to allow images to be
    loaded from any URL
  * Updates to skins and their configuration options
  * Built-in skin can now be selected via the skin= request
    parameter and the /skins page.
  * /cookies page can now now  delete individual cookies
  * Various extensions to diff displaz and operations
  * Add the --list option to the tarball, zip, and sqlar commands.
  * New TH1 commands: 'builtin_request_js', 'capexpr', 'foreach',
    'lappend', and 'string match'
  * The leaves command now shows the branch point of each leaf.
  * The fossil add command refuses to add files whose names are
    reserved by Windows (ex: 'aux') unless the --allow-reserved
    option is included.

fossil 2.14

  * add fossil chat
  * enhanced fossil clone
  * performance optimization
  * enhanced documents
  * Pikchr improvements
  * Schema Update Notice #1: This release drops a trigger from 
  the database schema
  * Schema Update Notice #2: This release changes how the descriptions
  of wiki edits are stored in the EVENT table, for improved display
  on timelines

fossil 2.13:

  * wiki improvements: interwiki links, markup features
  * support for rendering pikchr markup scriptions
  * line number modes support interactive selection of range of
    lines to hyperlink to
  * Enhance finfo page to track a file across renames
- minimum/bundled version of sqlite increased to 3.34.0
</Note>
    <Note Title="Terms of Use" Type="Legal Disclaimer" Ordinal="3" xml:lang="en">The CVRF data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).</Note>
    <Note Title="Patchnames" Type="Details" Ordinal="4" xml:lang="en">openSUSE-2021-1052</Note>
  </DocumentNotes>
  <DocumentDistribution xml:lang="en">Copyright SUSE LLC under the Creative Commons License 4.0 with Attribution (CC-BY-4.0)</DocumentDistribution>
  <DocumentReferences>
    <Reference Type="Self">
      <URL>https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/IXKYDSDXE52IUN2KFAJ4I2LXBSMJW72Y/</URL>
      <Description>E-Mail link for openSUSE-SU-2021:1052-1</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/support/security/rating/</URL>
      <Description>SUSE Security Ratings</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1187988</URL>
      <Description>SUSE Bug 1187988</Description>
    </Reference>
  </DocumentReferences>
  <ProductTree xmlns="http://www.icasi.org/CVRF/schema/prod/1.1">
    <Branch Type="Product Family" Name="SUSE Package Hub 15 SP1">
      <Branch Type="Product Name" Name="SUSE Package Hub 15 SP1">
        <FullProductName ProductID="SUSE Package Hub 15 SP1">SUSE Package Hub 15 SP1</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Version" Name="fossil-2.16-bp151.4.9.1">
      <FullProductName ProductID="fossil-2.16-bp151.4.9.1">fossil-2.16-bp151.4.9.1</FullProductName>
    </Branch>
    <Relationship ProductReference="fossil-2.16-bp151.4.9.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Package Hub 15 SP1">
      <FullProductName ProductID="SUSE Package Hub 15 SP1:fossil-2.16-bp151.4.9.1">fossil-2.16-bp151.4.9.1 as a component of SUSE Package Hub 15 SP1</FullProductName>
    </Relationship>
  </ProductTree>
</cvrfdoc>
