Skip to content

Tags: pushbike/flatpak

Tags

1.8.6

Toggle 1.8.6's commit message

Verified

This tag was signed with the committer’s verified signature.
alexlarsson Alexander Larsson
Release 1.8.6

Git-EVTag-v0-SHA512: af3a959997914b91fd94f907c48a9df3c3e791fb12a275787503babd486fc6fb60dee2fac64737c494f96c7fd8086799b2bd9878ab134364b55280bae78837dd

1.12.4

Toggle 1.12.4's commit message
flatpak 1.12.4

This is a regression fix update, reverting non-backwards-compatible
behaviour changes in the solution previously chosen for CVE-2022-21682.

Flatpak 1.12.3 and 1.10.6 changed the behaviour of `--nofilesystem=host`
and `--nofilesystem=home` in a way that was not backwards-compatible in
all cases. For example, some Flatpak users previously used a global
`flatpak override --nofilesystem=home` or
`flatpak override --nofilesystem=host`, but expected that individual apps
would still be able to have finer-grained filesystem access granted by the
app manifest, such as Zoom's `--filesystem=~/Documents/Zoom:create`. With
the changes in 1.12.3, this no longer had the intended result, because
`--nofilesystem=home` was special-cased to disallow inheriting the
finer-grained `--filesystem`.

Flatpak 1.12.4 and 1.10.7 return to the previous behaviour of
`--nofilesystem=host` and `--nofilesystem=home`. Instead, CVE-2022-21682
will be resolved by a new 1.2.2 release of flatpak-builder, which will
use a new option `--nofilesystem=host:reset` introduced in Flatpak 1.12.4
and 1.10.7. In addition to behaving like `--nofilesystem=host`, the new
option prevents filesystem permissions from being inherited from the
app manifest.

Other changes:

 * Clarify documentation of `--nofilesystem`
 * Improve unit test coverage around `--filesystem` and `--nofilesystem`
 * Restore compatibility with older appstream-glib versions, fixing a
   regression in 1.12.3

Git-EVTag-v0-SHA512: 61d12aef36cf0850a69bab9df268de365366f017333511f117c63a86e804945644cef2d84067a4150a53549d8c8b109585c8fef0c0933c456b01c4a7087fd8e9

1.10.7

Toggle 1.10.7's commit message
flatpak 1.10.7

This is a regression fix update, reverting non-backwards-compatible
behaviour changes in the solution previously chosen for CVE-2022-21682.

Flatpak 1.12.3 and 1.10.6 changed the behaviour of `--nofilesystem=host`
and `--nofilesystem=home` in a way that was not backwards-compatible in
all cases. For example, some Flatpak users previously used a global
`flatpak override --nofilesystem=home` or
`flatpak override --nofilesystem=host`, but expected that individual apps
would still be able to have finer-grained filesystem access granted by the
app manifest, such as Zoom's `--filesystem=~/Documents/Zoom:create`. With
the changes in 1.12.3, this no longer had the intended result, because
`--nofilesystem=home` was special-cased to disallow inheriting the
finer-grained `--filesystem`.

Flatpak 1.12.4 and 1.10.7 return to the previous behaviour of
`--nofilesystem=host` and `--nofilesystem=home`. Instead, CVE-2022-21682
will be resolved by a new 1.2.2 release of flatpak-builder, which will
use a new option `--nofilesystem=host:reset` introduced in Flatpak 1.12.4
and 1.10.7. In addition to behaving like `--nofilesystem=host`, the new
option prevents filesystem permissions from being inherited from the
app manifest.

Other changes:

 * Clarify documentation of `--nofilesystem`
 * Improve unit test coverage around `--filesystem` and `--nofilesystem`
 * Restore compatibility with older appstream-glib versions, fixing a
   regression in 1.12.3
 * Update variant-schema-compiler subproject to fix builds with newer
   versions of pyparsing (the content of the generated code is not affected)
 * Make the unit test for CVE-2021-43860 robust against versions of Python's
   http.server module that only read timestamps with a 1 second granularity

Git-EVTag-v0-SHA512: 91a47d62e3ae4b541d835a1fc786034b58a45d7895f82f3d16252e3feb729f67204ea1474a61e2567b47c29a913ce690be3a3e740bd18a1d3bc34aa4ed4c43c7

1.12.3

Toggle 1.12.3's commit message

Verified

This tag was signed with the committer’s verified signature.
alexlarsson Alexander Larsson
Release 1.12.3

Git-EVTag-v0-SHA512: 5498bf5f1457a945e7b52cfd357a6f234cc8dd5a42d6c18d30bf0add676223369dec652dbbc1a98da226a27a5214f9901e4f81fd6cf79a137b93fe0249fb6c9f

1.10.6

Toggle 1.10.6's commit message

Verified

This tag was signed with the committer’s verified signature.
alexlarsson Alexander Larsson
Release 1.10.6

Git-EVTag-v0-SHA512: 19c4049a194685445581c82b39e05acceb5523bffae4767978cf464ae8edd7461abdeacf9c5434d6e9178b850f19c0ae650110918ce1a0becd5cf3f338aac2bb

1.12.2

Toggle 1.12.2's commit message
flatpak 1.12.2

Git-EVTag-v0-SHA512: 5e6e119c2d8f39bdbc55735a5819235de430712a049793b1a64a94bcd2a8a7a7ade5dedaf5098c51b25366cf0d3b3029302cc8f8b42821f76b6db493142ac7ea

1.12.1

Toggle 1.12.1's commit message

Verified

This tag was signed with the committer’s verified signature.
alexlarsson Alexander Larsson
Release 1.12.1

Git-EVTag-v0-SHA512: e38fe92c0228cb5886aae92595cf4711556a4c6914ab159a0eeb7aeebe1818af3cb75013bab0212df080af2523b05c8b1d584f8fc3162157d0f6a7a38f372292

1.12.0

Toggle 1.12.0's commit message

Verified

This tag was signed with the committer’s verified signature.
alexlarsson Alexander Larsson
Release 1.12.0

Git-EVTag-v0-SHA512: fd031a829d2933361dfab94cd43eb7fc43242c53ed577aee689c450ac6d37eca0f3f90c3f045da4466bd6078eeaa7998b37f2bc74e2e31323eea7d29fc31cc1e

1.10.5

Toggle 1.10.5's commit message

Verified

This tag was signed with the committer’s verified signature.
alexlarsson Alexander Larsson
Release 1.10.5

Git-EVTag-v0-SHA512: c04f87185f8e6a81faecc3c7831f9e2e88cf792341c5c0fdc9761656871845f48e7fd60b68fcd9c578620f6f177e873e16669daff4d35fbea23e1dc3a983ee13

1.10.4

Toggle 1.10.4's commit message

Verified

This tag was signed with the committer’s verified signature.
alexlarsson Alexander Larsson
Release 1.10.4

Git-EVTag-v0-SHA512: 107003ee1343afd660b83ded20e939455d17a5f06ecdbb63dc12a219d91b95bd9c954d5b958889ec3cef8c352a537547006b48fbb8217cc020bba9fce93b9fc5