Skip to content

Weekly portage-stable package updates 2026-03-02#3761

Draft
github-actions[bot] wants to merge 290 commits intomainfrom
buildbot/weekly-portage-stable-package-updates-2026-03-02
Draft

Weekly portage-stable package updates 2026-03-02#3761
github-actions[bot] wants to merge 290 commits intomainfrom
buildbot/weekly-portage-stable-package-updates-2026-03-02

Conversation

@github-actions
Copy link

@github-actions github-actions bot commented Mar 2, 2026

CI: http://localhost:8080/job/container/job/sdk/2533/cldsv

Closes flatcar/Flatcar#1912
Closes flatcar/Flatcar#1915
Closes flatcar/Flatcar#1945
Closes flatcar/Flatcar#1950
Closes flatcar/Flatcar#1965
Closes flatcar/Flatcar#1970
Closes flatcar/Flatcar#1990
Closes flatcar/Flatcar#1993
Closes flatcar/Flatcar#1994
Closes flatcar/Flatcar#1995
Closes flatcar/Flatcar#2010
Closes flatcar/Flatcar#2011
Closes flatcar/Flatcar#2012
Closes flatcar/Flatcar#2013
Closes flatcar/Flatcar#2015
Closes flatcar/Flatcar#2016

Partially deals with flatcar/Flatcar#1964

glibc update, minor systemd update, bunch of security updates (as can be seen above), containerd and podman bumps, portage and catalyst updates (so fingers crossed).

--

  • app-admin/eselect: [DEV]

  • app-arch/xz-utils: [PROD] [DEV]

  • app-arch/zstd: [PROD] [DEV]

    • still at 1.5.7-r1
    • added signature verification
    • added IUSE flag 'verify-sig'
    • build dependencies:
      • added a dependency '>=app-portage/gemato-20' for USE 'verify-sig?'
      • added a dependency 'sec-keys/openpgp-keys-zstd' for USE 'verify-sig?'
      • added a dependency 'app-alternatives/gpg' for USE 'verify-sig?' -> '||'
      • added a dependency 'app-crypt/gnupg[-alternatives(-)]' for USE 'verify-sig?' -> '||'
  • app-containers/aardvark-dns: [SYSEXT-PODMAN]

  • app-containers/containerd: [SYSEXT-CONTAINERD]

  • app-containers/containers-common: [SYSEXT-PODMAN]

  • app-containers/containers-image: [SYSEXT-PODMAN]

  • app-containers/containers-storage: [SYSEXT-PODMAN]

  • app-containers/cri-tools: [PROD] [DEV]

    • still at 1.33.0
    • generate shell completion also when cross compiling
  • app-containers/docker: [SYSEXT-DOCKER]

    • still at 28.2.2
    • added a fix for cross-compilation, so our modifications are not necessary anymore
  • app-containers/docker-cli: [SYSEXT-DOCKER]

    • still at 28.4.0
    • removed IUSE flag 'hardened'
      • dropped as it's broken and unnecessary
      • dropped USE=hardened from overlay profiles too
  • app-containers/incus: [SYSEXT-INCUS]

  • app-containers/lxc: [SYSEXT-INCUS]

    • still at 6.0.5
    • pulled in a patch for some syscall detection
  • app-containers/netavark: [SYSEXT-PODMAN]

  • app-containers/podman: [SYSEXT-PODMAN]

  • app-containers/runc: [SYSEXT-CONTAINERD]

    • still at 1.4.0-r1
    • removed IUSE flag 'hardened'
      • broken and unnecessary
    • added some kernel config checks
  • app-crypt/argon2: [PROD] [DEV]

    • still at 20190702-r1
    • fixed prefix install in obscure case
  • app-crypt/gnupg: [PROD] [DEV]

  • app-crypt/p11-kit: [PROD] [DEV]

    • from 0.25.5 to 0.26.2
    • fixes CVE-2026-2100
    • package became unstable on 'amd64' and 'arm64'
      • added accept keywords to overlay profiles
    • added support for signature verification
    • added IUSE flag 'verify-sig'
    • build dependencies:
      • added a dependency '>=app-portage/gemato-20' for USE 'verify-sig?'
      • added a dependency 'sec-keys/openpgp-keys-p11-kit' for USE 'verify-sig?'
      • added a dependency 'app-alternatives/gpg' for USE 'verify-sig?' -> '||'
      • added a dependency 'app-crypt/gnupg[-alternatives(-)]' for USE 'verify-sig?' -> '||'
    • dependencies:
      • changes for sys-apps/systemd with USE conditionals 'systemd?':
        • dropped slot constraint
    • runtime dependencies:
      • changes for sys-apps/systemd with USE conditionals 'systemd?':
        • dropped slot constraint
    • release notes: http://github.com/p11-glue/p11-kit/releases/tag/0.26.{2..0} http://github.com/p11-glue/p11-kit/releases/tag/0.25.{10..6}
  • app-doc/eclass-manpages:

    • from 20251126 to 20260124
    • release notes: none
  • app-editors/nano:

    • still at 8.7
    • added support for signature verification
    • added IUSE flag 'verify-sig'
    • build dependencies:
      • added a dependency '>=app-portage/gemato-20' for USE 'verify-sig?'
      • added a dependency 'sec-keys/openpgp-keys-bennoschulenberg' for USE 'verify-sig?'
      • added a dependency 'app-alternatives/gpg' for USE 'verify-sig?' -> '||'
      • added a dependency 'app-crypt/gnupg[-alternatives(-)]' for USE 'verify-sig?' -> '||'
  • app-emulation/qemu:

    • from 10.0.5 to 10.2.0-r1
    • added IUSE flag 'valgrind'
      • support for debugging with valgrind
    • added IUSE flag 'passt'
      • for passt networking backend
    • build dependencies:
      • added a dependency '>=dev-util/gdbus-codegen-2.80.5-r1'
    • dependencies:
      • changes for dev-libs/nettle with USE conditionals 'gnutls?':
        • added version constraint >=3.7.3
      • changes for net-libs/gnutls with USE conditionals 'gnutls?':
        • changed version constraint from >=3.0 to >=3.7.5
      • added a dependency 'net-misc/passt' for USE 'passt?'
      • added a dependency 'dev-debug/valgrind' for USE 'valgrind?'
    • runtime dependencies:
      • changes for dev-libs/nettle with USE conditionals 'gnutls?':
        • added version constraint >=3.7.3
      • changes for net-libs/gnutls with USE conditionals 'gnutls?':
        • changed version constraint from >=3.0 to >=3.7.5
      • added a dependency 'net-misc/passt' for USE 'passt?'
    • release notes: https://wiki.qemu.org/ChangeLog/10.2 https://wiki.qemu.org/ChangeLog/10.1
  • app-misc/pax-utils: [PROD] [DEV]

  • app-portage/gentoolkit: [DEV]

  • coreos-devel/sdk-depends:

    • from 0.0.1-r56 to 0.0.1-r57
    • dependencies:
      • added a dependency 'sys-apps/man-pages'
      • added a dependency 'virtual/man'
    • runtime dependencies:
      • added a dependency 'sys-apps/man-pages'
      • added a dependency 'virtual/man'
  • dev-build/meson:

  • dev-cpp/azure-core:

  • dev-cpp/azure-identity:

  • dev-db/sqlite: [PROD] [DEV]

  • dev-debug/gdb: [DEV]

  • dev-debug/strace: [PROD] [DEV]

  • dev-embedded/u-boot-tools:

    • from 2025.01 to 2025.01-r2
    • dropped bundling of dtc in favor of a dependency on sys-apps/dtc
    • dependencies:
      • added a dependency '>=sys-apps/dtc-1.4.6'
    • runtime dependencies:
      • added a dependency '>=sys-apps/dtc-1.4.6'
  • dev-lang/go:

    • from 1.25.5 to 1.25.5-r1
    • avoid stripping toolchain binaries for the data race detector to work
  • dev-lang/rust:

    • from 1.91.0 to 1.92.0_p1-r1
    • build dependencies:
      • added a dependency 'llvm-core/clang' for USE 'rust_sysroots_wasm?'
      • added a dependency 'dev-lang/rust:1.92.0' for USE '||'
      • added a dependency 'dev-lang/rust-bin:1.92.0' for USE '||'
    • release notes: https://blog.rust-lang.org/2025/12/11/Rust-1.92.0/
  • dev-libs/elfutils: [PROD] [DEV]

    • still at 0.194
    • package became stable on 'amd64'
      • droped accept keywords from overlay profiles
    • IUSE flag 'libarchive' became enabled by default
      • we disable it in profiles
    • IUSE flag 'debuginfod' became enabled by default
      • we disable it in profiles
  • dev-libs/expat: [PROD] [DEV]

  • dev-libs/glib: [PROD] [DEV]

    • from 2.84.4 to 2.84.4-r2
    • fixes CVE-2025-13601, CVE-2025-14087
    • fixed USE=systemtap when cross-compiling
    • package became unstable on 'amd64' and 'arm64'
      • added accept keywords to overlay profiles
    • dependencies:
      • dropped a dependency '>=dev-libs/gobject-introspection-common-1.82.0' for USE 'introspection?'
      • added a dependency '>=dev-debug/systemtap-1.3' for USE 'systemtap?'
    • runtime dependencies:
      • dropped a dependency '>=dev-libs/gobject-introspection-common-1.82.0' for USE 'introspection?'
  • dev-libs/glib: [PROD] [DEV]

    • still at 2.84.4
    • dependencies:
      • dropped a dependency '>=dev-libs/gobject-introspection-common-1.82.0' for USE 'introspection?'
      • added a dependency '>=dev-debug/systemtap-1.3' for USE 'systemtap?'
    • runtime dependencies:
      • dropped a dependency '>=dev-libs/gobject-introspection-common-1.82.0' for USE 'introspection?'
  • dev-libs/gmp: [PROD] [DEV]

    • still at 6.3.0-r1
    • added support for signature verification
    • added IUSE flag 'verify-sig'
    • build dependencies:
      • added a dependency '>=app-portage/gemato-20' for USE 'verify-sig?'
      • added a dependency 'sec-keys/openpgp-keys-gmp' for USE 'verify-sig?'
      • added a dependency 'app-alternatives/gpg' for USE 'verify-sig?' -> '||'
      • added a dependency 'app-crypt/gnupg[-alternatives(-)]' for USE 'verify-sig?' -> '||'
  • dev-libs/libbsd: [PROD] [DEV]

    • still at 0.11.8
    • fix stripping lto bytecode
  • dev-libs/libgcrypt: [PROD] [DEV]

    • from 1.11.2 to 1.11.2-r1
    • drop flags stripping, seems to be unnecessary
  • dev-libs/libgpg-error: [PROD] [DEV]

  • dev-libs/libnl: [PROD] [DEV]

    • still at 3.11.0
    • package became stable on 'amd64'
      • dropped accept keywords from overlay profiles
    • added support for signature verification
    • added IUSE flag 'verify-sig'
    • build dependencies:
      • added a dependency '>=app-portage/gemato-20' for USE 'verify-sig?'
      • added a dependency 'sec-keys/openpgp-keys-thomashaller' for USE 'verify-sig?'
      • added a dependency 'app-alternatives/gpg' for USE 'verify-sig?' -> '||'
      • added a dependency 'app-crypt/gnupg[-alternatives(-)]' for USE 'verify-sig?' -> '||'
  • dev-libs/libpipeline: [DEV]

    • still at 1.5.8
    • added support for signature verification
    • added IUSE flag 'verify-sig'
    • build dependencies:
      • added a dependency '>=app-portage/gemato-20' for USE 'verify-sig?'
      • added a dependency 'sec-keys/openpgp-keys-cjwatson' for USE 'verify-sig?'
      • added a dependency 'app-alternatives/gpg' for USE 'verify-sig?' -> '||'
      • added a dependency 'app-crypt/gnupg[-alternatives(-)]' for USE 'verify-sig?' -> '||'
  • dev-libs/libsodium: [PROD] [DEV]

  • dev-libs/libtasn1: [PROD] [DEV]

  • dev-libs/libusb: [PROD] [DEV]

    • still at 1.0.29
    • added support for signature verification
    • added IUSE flag 'verify-sig'
    • build dependencies:
      • added a dependency '>=app-portage/gemato-20' for USE 'verify-sig?'
      • added a dependency 'sec-keys/openpgp-keys-libusb' for USE 'verify-sig?'
      • added a dependency 'app-alternatives/gpg' for USE 'verify-sig?' -> '||'
      • added a dependency 'app-crypt/gnupg[-alternatives(-)]' for USE 'verify-sig?' -> '||'
  • dev-libs/libxml2: [PROD] [DEV]

  • dev-libs/libxslt: [VMWARE]

  • dev-libs/mpc: [DEV]

    • still at 1.3.1
    • added support for signature verification
    • added IUSE flag 'verify-sig'
    • build dependencies:
      • added a dependency '>=app-portage/gemato-20' for USE 'verify-sig?'
      • added a dependency 'sec-keys/openpgp-keys-mpc' for USE 'verify-sig?'
      • added a dependency 'app-alternatives/gpg' for USE 'verify-sig?' -> '||'
      • added a dependency 'app-crypt/gnupg[-alternatives(-)]' for USE 'verify-sig?' -> '||'
  • dev-libs/xxhash: [PROD] [DEV]

    • from 0.8.3-r1 to 0.8.3-r2
    • added static-libs support
    • added use of dot-a eclass
    • added IUSE flag 'static-libs'
  • dev-python/cryptography:

  • dev-python/docutils:

  • dev-python/jaraco-context: [SYSEXT-PYTHON]

  • dev-python/jaraco-functools: [SYSEXT-PYTHON]

  • dev-python/packaging: [SYSEXT-PYTHON]

  • dev-python/pathspec:

  • dev-python/poetry-core:

    • from 2.2.1 to 2.3.0
    • added IUSE flag 'verify-provenance'
    • build dependencies:
      • changes for dev-python/lark:
        • changed version constraint from >=1.2.2 to >=1.3.1
      • added a dependency 'dev-python/pypi-attestations' for USE 'verify-provenance?'
    • runtime dependencies:
      • changes for dev-python/lark:
        • changed version constraint from >=1.2.2 to >=1.3.1
    • release notes: http://github.com/python-poetry/poetry-core/releases/tag/2.3.0
  • dev-python/snakeoil:

    • from 0.10.11 to 0.11.0
    • runtime dependencies:
      • dropped a dependency 'dev-python/lazy-object-proxy[python_targets_pypy3_11(-)?,python_targets_python3_11(-)?,python_targets_python3_12(-)?,python_targets_python3_13(-)?,python_targets_python3_14(-)?]'
    • release notes: http://github.com/pkgcore/snakeoil/releases/tag/v0.11.0
  • dev-python/trove-classifiers: [SYSEXT-PYTHON]

  • dev-python/wheel: [SYSEXT-PYTHON]

  • dev-util/catalyst:

    • from 4.0.0 to 4.1.1
    • added IUSE flag 'qcow2'
      • possibly for creating qcow2 images, disabled
    • runtime dependencies:
      • added a dependency 'app-emulation/qemu' for USE 'qcow2?' -> 'amd64?'
      • added a dependency 'sys-block/parted' for USE 'qcow2?' -> 'amd64?'
      • added a dependency 'sys-boot/grub[grub_platforms_efi-32,grub_platforms_efi-64]' for USE 'qcow2?' -> 'amd64?'
      • added a dependency 'sys-fs/dosfstools' for USE 'qcow2?' -> 'amd64?'
      • added a dependency 'sys-fs/xfsprogs' for USE 'qcow2?' -> 'amd64?'
    • release notes: https://gitweb.gentoo.org/proj/catalyst.git/log/?h=4.1.1
  • dev-util/maturin:

    • from 1.10.2 to 1.11.5
    • build dependencies:
      • changes for dev-lang/rust with USE conditionals '||':
        • changed version constraint from >=1.83.0 to >=1.85.0
      • changes for dev-lang/rust-bin with USE conditionals '||':
        • changed version constraint from >=1.83.0 to >=1.85.0
    • release notes: http://github.com/PyO3/maturin/releases/tag/v1.11.5
  • dev-util/pkgcheck:

    • from 0.10.37-r1 to 0.10.39
    • build dependencies:
      • changes for dev-libs/tree-sitter-bash:
        • changed version constraint from >=0.21.0 to >=0.25.1
      • dropped a dependency 'dev-python/lazy-object-proxy[python_targets_python3_11(-)?,python_targets_python3_12(-)?,python_targets_python3_13(-)?,python_targets_python3_14(-)?]'
      • changes for dev-python/snakeoil:
        • changed version constraint from >=0.10.11 to >=0.11.0
      • dropped a dependency '<dev-python/snakeoil-0.11.0[python_targets_python3_11(-)?,python_targets_python3_12(-)?,python_targets_python3_13(-)?,python_targets_python3_14(-)?]'
      • changes for dev-python/tree-sitter:
        • changed version constraint from >=0.25.0 to >=0.25.2
      • changes for sys-apps/pkgcore:
        • changed version constraint from ~0.12.30 to >=0.12.31
    • runtime dependencies:
      • changes for dev-libs/tree-sitter-bash:
        • changed version constraint from >=0.21.0 to >=0.25.1
      • dropped a dependency 'dev-python/lazy-object-proxy[python_targets_python3_11(-)?,python_targets_python3_12(-)?,python_targets_python3_13(-)?,python_targets_python3_14(-)?]'
      • changes for dev-python/snakeoil:
        • changed version constraint from >=0.10.11 to >=0.11.0
      • dropped a dependency '<dev-python/snakeoil-0.11.0[python_targets_python3_11(-)?,python_targets_python3_12(-)?,python_targets_python3_13(-)?,python_targets_python3_14(-)?]'
      • changes for dev-python/tree-sitter:
        • changed version constraint from >=0.25.0 to >=0.25.2
      • changes for sys-apps/pkgcore:
        • changed version constraint from ~0.12.30 to >=0.12.31
    • release notes: http://github.com/pkgcore/pkgcheck/releases/tag/v0.10.39 http://github.com/pkgcore/pkgcheck/releases/tag/v0.10.38
  • eclass/acct-group.eclass:

    • added support for EAPI 9
  • eclass/acct-user.eclass:

    • added support for EAPI 9
  • eclass/app-alternatives.eclass:

    • added support for EAPI 9
  • eclass/autotools.eclass:

    • added support for EAPI 9
  • eclass/crossdev.eclass:

    • added support for EAPI 9
  • eclass/desktop.eclass:

    • added support for EAPI 9
  • eclass/dist-kernel-utils.eclass:

    • added a function for getting a modules compressor
  • eclass/elisp-common.eclass:

    • bumped emacs version
  • eclass/flag-o-matic.eclass:

    • added -freport-bug to allowed flags
  • eclass/gnuconfig.eclass:

    • added support for EAPI 9
  • eclass/java-pkg-opt-2.eclass:

    • added support for EAPI 9
  • eclass/java-utils-2.eclass:

    • added support for EAPI 9
  • eclass/libtool.eclass:

    • added support for EAPI 9
  • eclass/llvm-r1.eclass:

    • marked as deprecated
  • eclass/llvm-utils.eclass:

    • added support for EAPI 9
  • eclass/llvm.eclass:

    • updated docs to point to a newer version of llvm eclass
  • eclass/meson.eclass:

    • add two helpers to configure meson
  • eclass/multibuild.eclass:

    • added support for EAPI 9
  • eclass/multilib-build.eclass:

    • added support for EAPI 9
  • eclass/out-of-source-utils.eclass:

    • added support for EAPI 9
  • eclass/out-of-source.eclass:

    • added support for EAPI 9
  • eclass/plocale.eclass:

    • added support for EAPI 9
  • eclass/portability.eclass:

    • added support for EAPI 9
  • eclass/preserve-libs.eclass:

    • added support for EAPI 9
  • eclass/qmake-utils.eclass:

    • dropped support for EAPI 7
    • added a function for getting qt libexec
  • eclass/rust.eclass:

    • added support for llvm 22
    • a bunch of new rust versions
  • eclass/sgml-catalog-r1.eclass:

    • added support for EAPI 9
  • eclass/strip-linguas.eclass:

    • added support for EAPI 9
  • eclass/sysroot.eclass:

    • a bunch of stuff, ask Chewi for details ;)
    • added support for running with wine
    • added a check for the need for qemu from binary pkgs
    • added sanity checks for sysroot wrapper
    • fixed dynamic linker check
  • eclass/toolchain-autoconf.eclass:

    • fixed env filename logic for prerelease versions
  • eclass/toolchain-funcs.eclass:

    • added support for EAPI 9
    • adapted tc-is-lto to non-ELF
  • eclass/toolchain.eclass:

    • added a workaround for broken --disable-* flags
    • reenabled build IDs
      • if stuff breaks, this is what we will need to disable
    • some nvptx fortran stuff, whatever
  • eclass/unpacker.eclass:

    • added support for more makeself versions
  • eclass/user-info.eclass:

    • added support for EAPI 9
  • eclass/vcs-snapshot.eclass:

    • added support for EAPI 9
  • eclass/verify-sig.eclass:

    • added support for EAPI 9
    • tolerate whitespace in openssl digest output
  • media-libs/libpng:

  • net-analyzer/netperf: [DEV]

    • from 2.7.0_p20210121 to 2.7.0_p20210121-r1
    • pulled in a patch for fixing build with gcc 15
      • dropped ours from user-patches
    • added accept keywords to overlay profiles
  • net-analyzer/tcpdump: [PROD] [DEV]

    • from 4.99.5 to 4.99.6
    • build dependencies:
      • changes for sec-keys/openpgp-keys-tcpdump with USE conditionals 'verify-sig?':
        • changed version constraint from >=20240901 to >=20260104
    • dependencies:
      • changes for net-libs/libpcap:
        • changed version constraint from >=1.10.1 to >=1.10.5
    • runtime dependencies:
      • changes for net-libs/libpcap:
        • changed version constraint from >=1.10.1 to >=1.10.5
    • release notes: https://raw.githubusercontent.com/the-tcpdump-group/tcpdump/refs/tags/tcpdump-4.99.6/CHANGES
  • net-dialup/lrzsz: [DEV]

    • still at 0.12.20-r10
    • fixed build with c23 on newer glibc
  • net-dns/c-ares: [PROD] [DEV]

  • net-firewall/ebtables: [PROD] [DEV]

    • still at 2.0.11-r3
    • added support for signature verification
    • added IUSE flag 'verify-sig'
    • build dependencies:
      • added a dependency '>=app-portage/gemato-20' for USE 'verify-sig?'
      • added a dependency 'sec-keys/openpgp-keys-netfilter' for USE 'verify-sig?'
      • added a dependency 'app-alternatives/gpg' for USE 'verify-sig?' -> '||'
      • added a dependency 'app-crypt/gnupg[-alternatives(-)]' for USE 'verify-sig?' -> '||'
    • runtime dependencies:
      • added a dependency 'sec-keys/openpgp-keys-netfilter' for USE 'verify-sig?'
  • net-firewall/nftables: [PROD] [DEV]

    • from 1.1.5 to 1.1.6
    • dependencies:
      • changes for net-libs/libnftnl:
        • changed version constraint from >=1.3.0 to >=1.3.1
    • runtime dependencies:
      • changes for net-libs/libnftnl:
        • changed version constraint from >=1.3.0 to >=1.3.1
    • release notes: https://lwn.net/Articles/1049470/
  • net-libs/gnutls: [PROD] [DEV]

  • net-libs/libpcap: [PROD] [DEV]

  • net-libs/nghttp2: [PROD] [DEV]

  • net-misc/curl: [PROD] [DEV]

  • net-misc/iperf: [DEV]

  • net-misc/iputils: [PROD] [DEV]

    • from 20250605-r1 to 20250605-r3
    • added support for signature verification
    • added IUSE flag 'suid'
      • make ping, arping and clockdiff binaries suid, disabled
    • added IUSE flag 'verify-sig'
    • IUSE flag 'caps' became enabled by default
      • needed for filecaps
    • build dependencies:
      • added a dependency '>=app-portage/gemato-20' for USE 'verify-sig?'
      • added a dependency 'sec-keys/openpgp-keys-pevik' for USE 'verify-sig?'
      • added a dependency 'app-alternatives/gpg' for USE 'verify-sig?' -> '||'
      • added a dependency 'app-crypt/gnupg[-alternatives(-)]' for USE 'verify-sig?' -> '||'
  • net-misc/passt: [SYSEXT-PODMAN]

  • net-misc/rsync: [PROD] [DEV]

  • net-misc/socat: [PROD] [DEV]

  • net-vpn/wireguard-tools: [PROD] [DEV]

  • profiles:

    • masked sys-libs/glibc < 2.41-r10
  • sec-keys/openpgp-keys-gentoo-release: [DEV]

    • from 20250806 to 20260125
    • release notes: none
  • sys-apps/acl: [PROD] [DEV]

    • from 2.3.2-r2 to 2.3.2-r3
    • added a patch fixing memory wasting issue
  • sys-apps/busybox:

    • from 1.36.1-r3 to 1.36.1-r4
    • build dependencies:
      • added a dependency '>=sys-apps/coreutils-9.2' for USE 'make-symlinks?'
  • sys-apps/gentoo-functions: [PROD] [DEV]

  • sys-apps/groff: [DEV]

    • still at 1.23.0-r1
    • build dependencies:
      • added a dependency 'sys-devel/m4'
  • sys-apps/iproute2: [PROD] [DEV]

  • sys-apps/iucode_tool:

    • from 2.3.1-r1 to 2.3.1-r2
    • EAPI changed from '7' to '8'
    • pulls in a patch for running it on non-x86 arches
    • package became unstable on 'amd64' and 'arm64'
      • added accept keywords to overlay profiles
  • sys-apps/kbd: [PROD] [DEV]

    • still at 2.9.0-r1
    • licenses:
      • dropped license 'GPL-2'
      • added license 'GPL-2+'
  • sys-apps/keyutils: [PROD] [DEV]

    • still at 1.6.3-r1
    • dropped an obsolete patch
  • sys-apps/less: [PROD] [DEV]

    • still at 685
    • added support for signature verification
    • added IUSE flag 'verify-sig'
    • build dependencies:
      • added a dependency '>=app-portage/gemato-20' for USE 'verify-sig?'
      • added a dependency 'sec-keys/openpgp-keys-less' for USE 'verify-sig?'
      • added a dependency 'app-alternatives/gpg' for USE 'verify-sig?' -> '||'
      • added a dependency 'app-crypt/gnupg[-alternatives(-)]' for USE 'verify-sig?' -> '||'
  • sys-apps/locale-gen:

  • sys-apps/man-db: [DEV]

    • from 2.13.1 to 2.13.1-r1
    • added support for signature verification
    • added IUSE flag 'verify-sig'
    • build dependencies:
      • added a dependency '>=app-portage/gemato-20' for USE 'verify-sig?'
      • added a dependency 'sec-keys/openpgp-keys-cjwatson' for USE 'verify-sig?'
      • added a dependency 'app-alternatives/gpg' for USE 'verify-sig?' -> '||'
      • added a dependency 'app-crypt/gnupg[-alternatives(-)]' for USE 'verify-sig?' -> '||'
  • sys-apps/man-pages: [DEV]

    • still at 6.10
    • build dependencies:
      • dropped a dependency 'app-alternatives/bc'
  • sys-apps/pciutils: [PROD] [DEV]

    • still at 3.14.0
    • added support for signature verification
    • added IUSE flag 'verify-sig'
    • build dependencies:
      • added a dependency '>=app-portage/gemato-20' for USE 'verify-sig?'
      • added a dependency 'sec-keys/openpgp-keys-martinmares' for USE 'verify-sig?'
      • added a dependency 'app-alternatives/gpg' for USE 'verify-sig?' -> '||'
      • added a dependency 'app-crypt/gnupg[-alternatives(-)]' for USE 'verify-sig?' -> '||'
  • sys-apps/pcsc-lite:

  • sys-apps/pkgcore:

    • from 0.12.30-r1 to 0.12.32
    • build dependencies:
      • added a dependency '>=app-shells/bash-5.3[readline]'
      • added a dependency 'dev-python/lxml[python_targets_python3_11(-)?,python_targets_python3_12(-)?,python_targets_python3_13(-)?,python_targets_python3_14(-)?]'
      • changes for dev-python/snakeoil:
        • changed version constraint from >=0.10.11 to >=0.11.0
      • dropped a dependency '<dev-python/snakeoil-0.11.0[python_targets_python3_11(-)?,python_targets_python3_12(-)?,python_targets_python3_13(-)?,python_targets_python3_14(-)?]'
    • runtime dependencies:
      • changes for app-shells/bash:
        • changed version constraint from >=5.2 to >=5.3
      • changes for dev-python/snakeoil:
        • changed version constraint from >=0.10.11 to >=0.11.0
      • dropped a dependency '<dev-python/snakeoil-0.11.0[python_targets_python3_11(-)?,python_targets_python3_12(-)?,python_targets_python3_13(-)?,python_targets_python3_14(-)?]'
    • release notes: http://github.com/pkgcore/pkgcore/releases/tag/v0.12.32 http://github.com/pkgcore/pkgcore/releases/tag/v0.12.31
  • sys-apps/portage: [DEV]

  • sys-apps/pv:

  • sys-apps/smartmontools: [DEV]

    • still at 7.5-r1
    • added support for signature verification
    • added IUSE flag 'verify-sig'
    • build dependencies:
      • added a dependency '>=app-portage/gemato-20' for USE 'verify-sig?'
      • added a dependency 'sec-keys/openpgp-keys-smartmontools' for USE 'verify-sig?'
      • added a dependency 'app-alternatives/gpg' for USE 'verify-sig?' -> '||'
      • added a dependency 'app-crypt/gnupg[-alternatives(-)]' for USE 'verify-sig?' -> '||'
  • sys-apps/systemd: [PROD] [DEV]

  • sys-apps/texinfo:

    • still at 7.2-r4
    • added support for signature verification
    • added IUSE flag 'verify-sig'
    • build dependencies:
      • added a dependency '>=app-portage/gemato-20' for USE 'verify-sig?'
      • added a dependency 'sec-keys/openpgp-keys-texinfo' for USE 'verify-sig?'
      • added a dependency 'app-alternatives/gpg' for USE 'verify-sig?' -> '||'
      • added a dependency 'app-crypt/gnupg[-alternatives(-)]' for USE 'verify-sig?' -> '||'
  • sys-apps/util-linux: [PROD] [DEV]

  • sys-auth/pambase: [PROD] [DEV]

    • from 20251104 to 20251104-r1
    • IUSE flag 'yescrypt' became enabled by default
    • IUSE flag 'sha512' became disabled by default
    • this means that different hashing algo will be used for new passwords, old passwords will stay at sha512 and will work just fine
  • sys-auth/polkit: [PROD] [DEV]

    • still at 126-r2
    • build dependencies:
      • dropped a dependency 'dev-libs/gobject-introspection-common'
  • sys-auth/sssd: [PROD] [DEV]

    • from 2.9.7 to 2.9.8
    • package became unstable on 'amd64'
      • updated accept keywords in overlay profiles
    • fixes CVE-2025-11561
    • added support for signature verification
    • added IUSE flag 'verify-sig'
    • build dependencies:
      • added a dependency '>=app-portage/gemato-20' for USE 'verify-sig?'
      • added a dependency 'sec-keys/openpgp-keys-sssd' for USE 'verify-sig?'
      • added a dependency 'app-alternatives/gpg' for USE 'verify-sig?' -> '||'
      • added a dependency 'app-crypt/gnupg[-alternatives(-)]' for USE 'verify-sig?' -> '||'
    • release notes: https://sssd.io/release-notes/sssd-2.9.8.html
  • sys-block/thin-provisioning-tools: [PROD] [DEV]

    • still at 1.3.1
    • build dependencies:
      • changes for dev-lang/rust with USE conditionals 'llvm_slot_21?' -> '||':
        • changed slot constraint from 9999 to 1.94.0
      • changes for dev-lang/rust-bin with USE conditionals 'llvm_slot_21?' -> '||':
        • changed slot constraint from 9999 to 1.94.0
  • sys-boot/gnu-efi:

  • sys-boot/grub:

    • from 2.12-r11 to 2.12-r12
    • reworked sbat generation
  • sys-devel/binutils: [DEV]

    • still at 2.45.1
    • IUSE flag 'debuginfod' became enabled by default
      • disabled in Flatcar
  • sys-devel/gcc: [PROD] [DEV]

    • from 15.2.1_p20251122 to 15.2.1_p20260214
    • dropped an upstreamed patch from patch bundle
  • sys-firmware/intel-microcode: [PROD] [DEV]

  • sys-fs/cryptsetup: [PROD] [DEV]

  • sys-fs/e2fsprogs: [PROD] [DEV]

    • still at 1.47.3-r1
    • added support for signature verification
    • added IUSE flag 'verify-sig'
    • build dependencies:
      • added a dependency '>=app-portage/gemato-20' for USE 'verify-sig?'
      • added a dependency 'sec-keys/openpgp-keys-tytso' for USE 'verify-sig?'
      • added a dependency 'app-alternatives/gpg' for USE 'verify-sig?' -> '||'
      • added a dependency 'app-crypt/gnupg[-alternatives(-)]' for USE 'verify-sig?' -> '||'
  • sys-fs/erofs-utils:

    • still at 1.8.10-r1
    • package became stable on 'amd64' and 'arm64'
      • dropped accept keywords from overlay profiles
  • sys-fs/fuse: [SYSEXT-INCUS] [SYSEXT-PODMAN] [VMWARE]

    • from 3.17.4 to 3.18.1
    • added IUSE flag 'io-uring'
      • for fuse-over-io-uring communication
    • added IUSE flag 'systemtap'
      • for user statically-defined tracing
    • dependencies:
      • added a dependency 'sys-libs/liburing:=[abi_x86_32(-)?,abi_x86_64(-)?,abi_x86_x32(-)?,abi_mips_n32(-)?,abi_mips_n64(-)?,abi_mips_o32(-)?,abi_s390_32(-)?,abi_s390_64(-)?]' for USE 'io-uring?'
      • added a dependency 'sys-process/numactl' for USE 'io-uring?'
    • runtime dependencies:
      • added a dependency 'sys-libs/liburing:=[abi_x86_32(-)?,abi_x86_64(-)?,abi_x86_x32(-)?,abi_mips_n32(-)?,abi_mips_n64(-)?,abi_mips_o32(-)?,abi_s390_32(-)?,abi_s390_64(-)?]' for USE 'io-uring?'
      • added a dependency 'sys-process/numactl' for USE 'io-uring?'
    • release notes: http://github.com/libfuse/libfuse/releases/tag/fuse-3.18.1 http://github.com/libfuse/libfuse/releases/tag/fuse-3.18.0
  • sys-fs/fuse-overlayfs: [SYSEXT-PODMAN]

  • sys-fs/quota: [PROD] [DEV]

  • sys-fs/xfsprogs: [PROD] [DEV]

  • sys-fs/zfs: [SYSEXT-ZFS]

    • still at 2.3.4
    • package became stable on 'arm64'
      • dropped accept keywords from overlay profiles
  • sys-fs/zfs-kmod: [SYSEXT-ZFS]

    • still at 2.3.4
    • package became stable on 'arm64'
      • dropped accept keywords from overlay profiles
  • sys-kernel/dracut: [PROD] [DEV]

    • from 109 to 109-r1
    • added IUSE flag 'systemd'
      • enabled on Flatcar, enables ELF .note.dlopen sections parsing
    • dependencies:
      • added a dependency '>=sys-apps/systemd-257:=' for USE 'systemd?'
    • runtime dependencies:
      • added a dependency '>=sys-apps/kmod-23'
      • added a dependency '>=sys-apps/systemd-257:=' for USE 'systemd?'
  • sys-kernel/linux-headers: [PROD] [DEV]

  • sys-libs/glibc: [PROD] [DEV]

    • from 2.41-r6 to 2.42-r5
    • added support for signature verification
    • fixes CVE-2026-0861, CVE-2026-0915, CVE-2025-15281
    • added IUSE flag 'verify-sig'
    • added IUSE flag 'sframe'
      • support for a new stack trace format, currently disabled
    • build dependencies:
      • added a dependency '>=sys-devel/binutils-2.45' for USE 'sframe?'
      • added a dependency '>=app-portage/gemato-20' for USE 'verify-sig?'
      • added a dependency 'sec-keys/openpgp-keys-glibc' for USE 'verify-sig?'
      • added a dependency 'app-alternatives/gpg' for USE 'verify-sig?' -> '||'
      • added a dependency 'app-crypt/gnupg[-alternatives(-)]' for USE 'verify-sig?' -> '||'
    • release notes: https://lists.gnu.org/archive/html/info-gnu/2025-07/msg00011.html
  • sys-libs/libseccomp: [PROD] [DEV]

    • still at 2.6.0-r3
    • added support for signature verification
    • added IUSE flag 'verify-sig'
    • build dependencies:
      • added a dependency '>=app-portage/gemato-20' for USE 'verify-sig?'
      • added a dependency 'sec-keys/openpgp-keys-libseccomp' for USE 'verify-sig?'
      • added a dependency 'app-alternatives/gpg' for USE 'verify-sig?' -> '||'
      • added a dependency 'app-crypt/gnupg[-alternatives(-)]' for USE 'verify-sig?' -> '||'
  • sys-libs/libselinux: [PROD] [DEV]

    • still at 3.8.1-r3
    • build dependencies:
      • added a dependency '>=dev-python/gpep517-16[python_targets_python3_11(-)?,python_targets_python3_12(-)?,python_targets_python3_13(-)?,python_targets_python3_14(-)?]' for USE 'python?'
      • added a dependency '>=dev-python/setuptools-78.1.0[python_targets_python3_11(-)?,python_targets_python3_12(-)?,python_targets_python3_13(-)?,python_targets_python3_14(-)?]' for USE 'python?'
      • added a dependency 'dev-lang/python:3.12' for USE 'python?' -> 'python_targets_python3_12?'
  • sys-libs/pam: [PROD] [DEV]

    • from 1.7.1-r2 to 1.7.1-r3
    • build dependencies:
      • changes for sec-keys/openpgp-keys-pam with USE conditionals 'verify-sig?':
        • added version constraint ~20230330
  • sys-libs/timezone-data: [PROD] [DEV]

  • sys-process/psmisc:

    • still at 23.7
    • added support for signature verification
    • added IUSE flag 'verify-sig'
    • build dependencies:
      • added a dependency '>=app-portage/gemato-20' for USE 'verify-sig?'
      • added a dependency 'sec-keys/openpgp-keys-craigsmall' for USE 'verify-sig?'
      • added a dependency 'app-alternatives/gpg' for USE 'verify-sig?' -> '||'
      • added a dependency 'app-crypt/gnupg[-alternatives(-)]' for USE 'verify-sig?' -> '||'
  • x11-drivers/nvidia-drivers: [SYSEXT-NVIDIA-DRIVERS-535] [SYSEXT-NVIDIA-DRIVERS-535-OPEN]

  • x11-drivers/nvidia-drivers: [SYSEXT-NVIDIA-DRIVERS-570] [SYSEXT-NVIDIA-DRIVERS-570-OPEN]

--

  • changelog
  • image diff

@github-actions github-actions bot added the main label Mar 2, 2026
Flatcar Buildbot added 29 commits March 4, 2026 18:58
It's from Gentoo commit 15b81bcecfb1984c912efd340e662f1e21ca7ad0.

Signed-off-by: Flatcar Buildbot <buildbot@flatcar-linux.org>
It's from Gentoo commit d7b4253867daa019117df7970b7cc24b88a71fd9.

Signed-off-by: Flatcar Buildbot <buildbot@flatcar-linux.org>
It's from Gentoo commit 900c0ee7e1d9216e47aab2ce63f20136500abec8.

Signed-off-by: Flatcar Buildbot <buildbot@flatcar-linux.org>
It's from Gentoo commit 1206ca1cdfd6f2471b013856e40bc109bef8a386.

Signed-off-by: Flatcar Buildbot <buildbot@flatcar-linux.org>
It's from Gentoo commit b786e027006bd213f69b1424879d0862074211d7.

Signed-off-by: Flatcar Buildbot <buildbot@flatcar-linux.org>
It's from Gentoo commit d13b85c350532840a2d84fc45ade8da2f3c865fa.

Signed-off-by: Flatcar Buildbot <buildbot@flatcar-linux.org>
It's from Gentoo commit 41fe5afc9953ae9d497dd936f40f9a9ab6c26f07.

Signed-off-by: Flatcar Buildbot <buildbot@flatcar-linux.org>
It's from Gentoo commit a25550068e83334990cbde591af4e17f0d9ffc48.

Signed-off-by: Flatcar Buildbot <buildbot@flatcar-linux.org>
It's from Gentoo commit c77b9c1188474c82c8ec6aeed59d8a3008fd2d6b.

Signed-off-by: Flatcar Buildbot <buildbot@flatcar-linux.org>
It's from Gentoo commit db7e79e5ac0391047752f5015c94d6d15fb3a22d.

Signed-off-by: Flatcar Buildbot <buildbot@flatcar-linux.org>
It's from Gentoo commit f363f98d6a19453a397af537f7102d59e431a1ad.

Signed-off-by: Flatcar Buildbot <buildbot@flatcar-linux.org>
It's from Gentoo commit f363f98d6a19453a397af537f7102d59e431a1ad.

Signed-off-by: Flatcar Buildbot <buildbot@flatcar-linux.org>
It's from Gentoo commit f363f98d6a19453a397af537f7102d59e431a1ad.

Signed-off-by: Flatcar Buildbot <buildbot@flatcar-linux.org>
It's from Gentoo commit dff3a48e955aee6f9b95677c72b2164bdef962b4.

Signed-off-by: Flatcar Buildbot <buildbot@flatcar-linux.org>
It's from Gentoo commit 514db4d6ac702c0bde9f75467615380150fdf3aa.

Signed-off-by: Flatcar Buildbot <buildbot@flatcar-linux.org>
It's from Gentoo commit a170c21d9f7d5e58af62d25c57b91d4527b7aba0.

Signed-off-by: Flatcar Buildbot <buildbot@flatcar-linux.org>
It's from Gentoo commit 9d183f2001f6e768cdfb2d6c191f160f55f00564.

Signed-off-by: Flatcar Buildbot <buildbot@flatcar-linux.org>
It's from Gentoo commit 2d3e6eaa08af5dc94b70e5ce5755a823cd3d6ae3.

Signed-off-by: Flatcar Buildbot <buildbot@flatcar-linux.org>
It's from Gentoo commit b35f47e12294d793dbd2edca4698fc482f99dd3b.

Signed-off-by: Flatcar Buildbot <buildbot@flatcar-linux.org>
It's from Gentoo commit 31d2a94eac6e785ae20e003c849ed66f2f3a90bc.

Signed-off-by: Flatcar Buildbot <buildbot@flatcar-linux.org>
It's from Gentoo commit 528bc788ed5367e2e3b970c34fef7153204a9ce4.

Signed-off-by: Flatcar Buildbot <buildbot@flatcar-linux.org>
It's from Gentoo commit 923c030c8f3a8e3a2b7d6be5126c0de64bba07eb.

Signed-off-by: Flatcar Buildbot <buildbot@flatcar-linux.org>
It's from Gentoo commit 168bf7364b8246cbb8b44eb30f5cc9ef2fa983c5.

Signed-off-by: Flatcar Buildbot <buildbot@flatcar-linux.org>
It's from Gentoo commit 0bf386e412822b87e81fbc4c31b11e4ef0ce30de.

Signed-off-by: Flatcar Buildbot <buildbot@flatcar-linux.org>
It's from Gentoo commit bb1d0f576638f4fb1dca5ab0cc955418834fcd9d.

Signed-off-by: Flatcar Buildbot <buildbot@flatcar-linux.org>
It's from Gentoo commit d74ddb081de4df9b7aef5ac8f41e76a9f72b3288.

Signed-off-by: Flatcar Buildbot <buildbot@flatcar-linux.org>
It's from Gentoo commit 4e81343c0da6feeba38b90b0cf5d0ac3c8e2b939.

Signed-off-by: Flatcar Buildbot <buildbot@flatcar-linux.org>
It's from Gentoo commit c39263fa38487403d472066559fbdb3453f483a9.

Signed-off-by: Flatcar Buildbot <buildbot@flatcar-linux.org>
It's from Gentoo commit d38aadd70b6a973eefa1d93140607eb7429ecd52.

Signed-off-by: Flatcar Buildbot <buildbot@flatcar-linux.org>
krnowak added 25 commits March 4, 2026 18:58
Signed-off-by: Krzesimir Nowak <knowak@microsoft.com>
…ers/docker

Signed-off-by: Krzesimir Nowak <knowak@microsoft.com>
Was dropped from the ebuild as it was broken and unnecessary.

Signed-off-by: Krzesimir Nowak <knowak@microsoft.com>
…iners/incus

Signed-off-by: Krzesimir Nowak <knowak@microsoft.com>
Signed-off-by: Krzesimir Nowak <knowak@microsoft.com>
Signed-off-by: Krzesimir Nowak <knowak@microsoft.com>
Signed-off-by: Krzesimir Nowak <knowak@microsoft.com>
Signed-off-by: Krzesimir Nowak <knowak@microsoft.com>
Signed-off-by: Krzesimir Nowak <knowak@microsoft.com>
…netperf

Signed-off-by: Krzesimir Nowak <knowak@microsoft.com>
Signed-off-by: Krzesimir Nowak <knowak@microsoft.com>
Signed-off-by: Krzesimir Nowak <knowak@microsoft.com>
Signed-off-by: Krzesimir Nowak <knowak@microsoft.com>
Signed-off-by: Krzesimir Nowak <knowak@microsoft.com>
Signed-off-by: Krzesimir Nowak <knowak@microsoft.com>
Signed-off-by: Krzesimir Nowak <knowak@microsoft.com>
Signed-off-by: Krzesimir Nowak <knowak@microsoft.com>
Signed-off-by: Krzesimir Nowak <knowak@microsoft.com>
Signed-off-by: Krzesimir Nowak <knowak@microsoft.com>
Signed-off-by: Krzesimir Nowak <knowak@microsoft.com>
Signed-off-by: Krzesimir Nowak <knowak@microsoft.com>
…ases

Signed-off-by: Krzesimir Nowak <knowak@microsoft.com>
Signed-off-by: Krzesimir Nowak <knowak@microsoft.com>
Signed-off-by: Krzesimir Nowak <knowak@microsoft.com>
Signed-off-by: Krzesimir Nowak <knowak@microsoft.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

Status: ⚒️ In Progress

1 participant