<?xml version="1.0"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/">
  <channel>
    <title>openSUSE News</title>
    <link>https://news.opensuse.org</link>
    <description>Latest news from the openSUSE Project</description>
    <atom:link href="https://news.opensuse.org/feed.xml" rel="self" type="application/rss+xml"/>

    <item>
      <guid>https://news.opensuse.org/2026/07/24/planet-roundup/</guid>
      <title>Planet News Roundup</title>
      <pubDate>Fri, 24 Jul 2026 08:00:00 +0000</pubDate>
      <link>https://news.opensuse.org/2026/07/24/planet-roundup/</link>
      <author>admin@opensuse.org (Douglas DeMaio)</author>
      <enclosure url="https://news.opensuse.org/wp-content/uploads/2025/07/planet.png" length="78165" type="image/png" />
      <description>This is a roundup of articles from the openSUSE community listed on planet.opensuse.org. The community blog feed aggregator lists the featured highlights below from July 17 to 23. This week opened Call for Proposals for two 2027 Open Developers Summits (Barcelona and Dallas), and KDE published its Akademy 2026 schedule...</description>
      <content:encoded>&lt;p&gt;This is a roundup of articles from the openSUSE community listed on &lt;a href=&quot;https://planet.opensuse.org&quot;&gt;planet.opensuse.org&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;The community blog feed aggregator lists the featured highlights below from July 17 to 23. This week opened Call for Proposals for two 2027 Open Developers Summits (Barcelona and Dallas), and KDE published its Akademy 2026 schedule for Graz. A blog also confirms Akademy-es will be in Madrid. On the technical side, a PortProtonQt Polkit flaw (CVE-2026-59678) was fixed in 1.3.1, and Tumbleweed shipped five snapshots.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Here is a summary and links for each post:&lt;/strong&gt;&lt;/p&gt;

&lt;h2 id=&quot;slimbook-os-26-released-slimbooks-own-operating-system&quot;&gt;&lt;a href=&quot;https://www.kdeblog.com/lanzado-slimbook-os-26-el-sistema-operativo-de-slimbook.html&quot;&gt;Slimbook OS 26 Released, Slimbook’s Own Operating System&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;The &lt;a href=&quot;https://www.kdeblog.com/&quot;&gt;KDE Blog&lt;/a&gt; covers the launch of Slimbook OS 26, which jumps from the previous release to a base of Ubuntu 26.04 LTS and GNOME 50. Although tuned for Slimbook hardware, it works on any machine and bundles the Slimbook Control Panel and Service alongside Alpaca for optional, private local AI chat.&lt;/p&gt;

&lt;h2 id=&quot;thunderbird-153-released-the-new-extended-support-version-of-the-free-software-mail-client&quot;&gt;&lt;a href=&quot;https://victorhckinthefreeworld.com/2026/07/23/publicado-thunderbird-153-la-nueva-version-de-soporte-extendido-de-este-cliente-de-correo-de-software-libre/&quot;&gt;Thunderbird 153 Released, the New Extended Support Version of the Free Software Mail Client&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;&lt;a href=&quot;https://victorhckinthefreeworld.com/&quot;&gt;Victorhck&lt;/a&gt; reports that Thunderbird 153 becomes the new ESR release replacing Thunderbird 140. It gathers up everything that has landed month by month in the monthly release channel, including a new design, new features and bugfixes.&lt;/p&gt;

&lt;h2 id=&quot;flying-cursors-for-your-pc&quot;&gt;&lt;a href=&quot;https://www.kdeblog.com/cursores-volantes-para-tu-pc.html&quot;&gt;Flying Cursors for Your PC&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;The &lt;a href=&quot;https://www.kdeblog.com/&quot;&gt;KDE Blog&lt;/a&gt; introduces Volantes, a clean and minimal cursor theme for Linux desktops created by x-varlesh-x. Available in light and dark variants with sizes from 24 to 64 pixels, the cursors can be installed directly through KDE Plasma’s cursor theme settings via the “Get New Themes” option.&lt;/p&gt;

&lt;h2 id=&quot;syslog-ng-journald-source-how-to-avoid-log-bombs-on-errors&quot;&gt;&lt;a href=&quot;https://www.syslog-ng.com/community/b/blog/posts/syslog-ng-journald-source-how-to-avoid-log-bombs-on-errors&quot;&gt;Syslog-ng Journald Source: How to Avoid Log Bombs on Errors&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;&lt;a href=&quot;https://www.syslog-ng.com/&quot;&gt;Peter Czanik’s Blog&lt;/a&gt; explains a behavior change in syslog-ng regarding error handling when jumping to a saved systemd journal position. Up until version 4.12, syslog-ng would read the journal from the beginning upon encountering an error, but the latest version allows users to configure what happens in such cases.&lt;/p&gt;

&lt;h2 id=&quot;open-developers-summits-head-to-barcelona-and-dallas-in-2027&quot;&gt;&lt;a href=&quot;https://news.opensuse.org/2026/07/22/open-dev-summits/&quot;&gt;Open Developers Summits Head to Barcelona and Dallas in 2027&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;&lt;a href=&quot;https://news.opensuse.org/&quot;&gt;openSUSE News&lt;/a&gt; announces two Open Developers Summits planned for 2027, with calls for proposals now open. The first summit takes place Feb. 18 in Barcelona alongside SUSECON, while the second is scheduled for April 14 in Dallas, Texas.&lt;/p&gt;

&lt;h2 id=&quot;portprotonqt-custom-polkit-rule-allows-escalation-of-networkmanager-and-udisks2-privileges&quot;&gt;&lt;a href=&quot;https://security.opensuse.org/2026/07/22/port-proton-qt-polkit-rules.html&quot;&gt;PortProtonQt: Custom Polkit Rule Allows Escalation of NetworkManager and UDisks2 Privileges&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;The &lt;a href=&quot;https://security.suse.com/&quot;&gt;SUSE Security Team&lt;/a&gt; discloses CVE-2026-59678, a vulnerability in PortProtonQt where a custom Polkit rule allows arbitrary local users to modify NetworkManager connections or UDisks2 mounts. The issue, introduced in version 0.1.12, was fixed in version 1.3.1 by restricting elevated privileges to users in an active local session who are members of a dedicated portprotonqt group.&lt;/p&gt;

&lt;h2 id=&quot;you-are-the-asset-carles-tamayos-documentary-at-gnulinux-valència-event&quot;&gt;&lt;a href=&quot;https://www.kdeblog.com/el-activo-eres-tu-de-carles-tamayo-nuevo-evento-organizado-por-gnu-linux-valencia.html&quot;&gt;You Are the Asset: Carles Tamayo’s Documentary at GNU/Linux València Event&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;The &lt;a href=&quot;https://www.kdeblog.com/&quot;&gt;KDE Blog&lt;/a&gt; announces an event organized by GNU/Linux València featuring a debate on the documentary “El Activo Eres Tú” by Carles Tamayo, preceded by an Install Party on July 31.&lt;/p&gt;

&lt;h2 id=&quot;evaluating-toon-in-a-real-world-scenario&quot;&gt;&lt;a href=&quot;https://mslacken.github.io//programming/mcp/2026/07/21/too-evaluation.html&quot;&gt;Evaluating TOON in a Real-World Scenario&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;&lt;a href=&quot;https://github.com/mslacken&quot;&gt;Christian Goll&lt;/a&gt; presents real-world experiments testing Token-Oriented Notation (TOON) in the systemd-mcp server to reduce token usage in AI inference. The study found that TOON performs superiorly for complex multi-step tasks, keeping LLMs more focused by increasing information density and reducing distracting overhead.&lt;/p&gt;

&lt;h2 id=&quot;updating-the-signing-key-on-leap-micro&quot;&gt;&lt;a href=&quot;https://news.opensuse.org/2026/07/21/updated-signig-key/&quot;&gt;Updating the Signing Key on Leap Micro&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;&lt;a href=&quot;https://news.opensuse.org/&quot;&gt;openSUSE News&lt;/a&gt; explains how to resolve repository signature errors on Leap Micro following the recent signing key expiration. Users can force a refresh of the repository metadata by running &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;zypper ref -f&lt;/code&gt; within a transactional-update shell.&lt;/p&gt;

&lt;h2 id=&quot;gsoc-update-2-visual-redesign-and-responsive-svgs&quot;&gt;&lt;a href=&quot;https://mmarhin.github.io/gsoc2026blog/gsoc/opensuse/svg/golang/2026/07/20/update-2-visual-redesign-responsive-svgs.html&quot;&gt;GSoC Update 2: Visual Redesign and Responsive SVGs&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;&lt;a href=&quot;https://news.opensuse.org/&quot;&gt;openSUSE News&lt;/a&gt; shares Mario Marín’s Google Summer of Code progress on the obs-status-service SVG generation, focusing on visual consistency with Gitea’s UI. The update introduces native Gitea colors, a responsive compact mode for large project matrices, and dynamic layout calculations to prevent text overflow.&lt;/p&gt;

&lt;h2 id=&quot;the-case-for-sponsoring-opensuse&quot;&gt;&lt;a href=&quot;https://news.opensuse.org/2026/07/20/case-for-sponsoring-os/&quot;&gt;The Case for Sponsoring openSUSE&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;&lt;a href=&quot;https://news.opensuse.org/&quot;&gt;openSUSE News&lt;/a&gt; makes the case for companies to sponsor the openSUSE Project, highlighting the infrastructure value of Open Build Service, openQA, Tumbleweed, Leap, and Uyuni. Sponsorship takes three forms—money, hardware, or services—and helps maintain the development ecosystem that hardware vendors and enterprises rely on for Linux compatibility.&lt;/p&gt;

&lt;h2 id=&quot;akademy-2026-talk-schedule-published-for-graz-austria&quot;&gt;&lt;a href=&quot;https://www.kdeblog.com/publicado-el-programa-de-charlas-para-akademy-2026-de-graz-austria.html&quot;&gt;Akademy 2026 Talk Schedule Published for Graz, Austria&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;The &lt;a href=&quot;https://www.kdeblog.com/&quot;&gt;KDE Blog&lt;/a&gt; announces the published talk schedule for Akademy 2026 in Graz, Austria, taking place Sept. 19-24 as a special 30th anniversary edition. Talks will be held on Saturday and Sunday, covering topics such as KDE Linux, Dolphin, Plasma, QA, and community matters.&lt;/p&gt;

&lt;h2 id=&quot;real-time-weather-information-with-meteoclimatic-feeds--plasmoids-for-plasma-6-36&quot;&gt;&lt;a href=&quot;https://www.kdeblog.com/informacion-meteorologica-en-tiempo-real-con-meteoclimatic-feeds-plasmoides-para-plasma-6-36.html&quot;&gt;Real-Time Weather Information with Meteoclimatic Feeds – Plasmoids for Plasma 6 (36)&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;The &lt;a href=&quot;https://www.kdeblog.com/&quot;&gt;KDE Blog&lt;/a&gt; presents Meteoclimatic Feeds, the 36th entry in its Plasma 6 plasmoid series, connecting to the Meteoclimatic network of amateur weather stations for real-time data. Created by &lt;a href=&quot;https://victorhckinthefreeworld.com&quot;&gt;Victorhck&lt;/a&gt;, this plasmoid is based on the RSS feeds plasmoide and can be installed by copying the folder to &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;~/.local/share/plasma/plasmoids&lt;/code&gt;.&lt;/p&gt;

&lt;h2 id=&quot;linux-saloon-211-open-mic-night&quot;&gt;&lt;a href=&quot;https://cubiclenate.com/2026/07/18/linux-saloon-211-open-mic-night/?utm_source=rss&amp;amp;utm_medium=rss&amp;amp;utm_campaign=linux-saloon-211-open-mic-night&quot;&gt;Linux Saloon 211: Open Mic Night&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;&lt;a href=&quot;https://nathanwolfe.net/&quot;&gt;Nathan’s Blog&lt;/a&gt; covers discussions about user experiences with Fedora, job openings at Epic Games focused on Linux security, and IBM’s new chip architecture advancements. The episode also touches on Dell surpassing HP in U.S. PC sales amid a shrinking market.&lt;/p&gt;

&lt;h2 id=&quot;linux-saloon-210-early-edition-july&quot;&gt;&lt;a href=&quot;https://cubiclenate.com/2026/07/18/linux-saloon-210-early-edition-july/?utm_source=rss&amp;amp;utm_medium=rss&amp;amp;utm_campaign=linux-saloon-210-early-edition-july&quot;&gt;Linux Saloon 210: Early Edition July&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;&lt;a href=&quot;https://nathanwolfe.net/&quot;&gt;Nathan’s Blog&lt;/a&gt; discusses AI and the possibility of the bubble bursting. The episode also has discussions involving the Open Build Service and some joking about Tumbleweed.&lt;/p&gt;

&lt;h2 id=&quot;shadows-for-steam-and-discord--this-week-in-plasma&quot;&gt;&lt;a href=&quot;https://www.kdeblog.com/sombras-para-steam-y-discord-esta-semana-en-plasma.html&quot;&gt;Shadows for Steam and Discord – This Week in Plasma&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;The &lt;a href=&quot;https://www.kdeblog.com/&quot;&gt;KDE Blog&lt;/a&gt; translates Nate Graham’s weekly Plasma development update, highlighting KWin’s new automatic shadow, outline, and corner rounding effects for client-side decorated windows like Steam and Discord.&lt;/p&gt;

&lt;h2 id=&quot;opensuse-tumbleweed-review-of-week-29-of-2026&quot;&gt;openSUSE Tumbleweed Review of Week 29 of 2026&lt;/h2&gt;
&lt;p&gt;&lt;a href=&quot;https://victorhckinthefreeworld.com/2026/07/17/opensuse-tumbleweed-revision-de-la-semana-29-de-2026/&quot;&gt;Victorhck&lt;/a&gt; and &lt;a href=&quot;https://dominique.leuenberger.net/blog/2026/07/tumbleweed-review-of-the-week-2026-29/&quot;&gt;Dominique&lt;/a&gt; review five Tumbleweed snapshots published during the week. Highlights including SELinux Toolchain 3.11, KDE Frameworks 6.28.0, QEMU 11.0.2, GStreamer 1.28.5, and Rust 1.97. The reversion of gvim’s GTK4 build back to GTK3 was notable due to clipboard deadlocks in the current GTK4 port.&lt;/p&gt;

&lt;h2 id=&quot;akademy-es-2026-will-be-held-in-madrid&quot;&gt;&lt;a href=&quot;https://www.kdeblog.com/akademy-es-2026-se-celebrara-en-madrid-akademyes.html&quot;&gt;Akademy-es 2026 Will Be Held in Madrid&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;The &lt;a href=&quot;https://www.kdeblog.com/&quot;&gt;KDE Blog&lt;/a&gt; announces that Akademy-es 2026 will take place from Oct. 23-25 in Madrid. The event celebrates KDE’s 30th anniversary and Akademy-es’s 20th anniversary.&lt;/p&gt;

&lt;p&gt;View more blogs or learn to publish your own on &lt;a href=&quot;https://planet.opensuse.org&quot;&gt;planet.opensuse.org&lt;/a&gt;.&lt;/p&gt;

&lt;meta name=&quot;openSUSE, Open Source, development, Linux, secure operating systems, KDE, Plasma, Tumbleweed&quot; content=&quot;HTML,CSS,XML,JavaScript&quot; /&gt;

</content:encoded>
    </item>

    <item>
      <guid>https://news.opensuse.org/2026/07/22/open-dev-summits/</guid>
      <title>Open Developers Summits Head to Barcelona and Dallas in 2027</title>
      <pubDate>Wed, 22 Jul 2026 08:00:00 +0000</pubDate>
      <link>https://news.opensuse.org/2026/07/22/open-dev-summits/</link>
      <author>admin@opensuse.org (Douglas DeMaio)</author>
      <enclosure url="https://news.opensuse.org/wp-content/uploads/2026/07/ods.png" length="46033" type="image/png" />
      <description>The openSUSE community is planning two Open Developers Summits in 2027, and organizers are calling for proposals for both events now. The first summit is scheduled to take place on Feb. 18, 2027, in Barcelona, Spain, held alongside SUSECON. The second is scheduled to take place on April 14, 2027,...</description>
      <content:encoded>&lt;p&gt;The &lt;a href=&quot;https://www.opensuse.org/&quot;&gt;openSUSE&lt;/a&gt; community is planning two Open Developers Summits in 2027, and organizers are calling for proposals for both events now.&lt;/p&gt;

&lt;p&gt;The first summit is scheduled to take place on Feb. 18, 2027, in Barcelona, Spain, held alongside &lt;a href=&quot;https://www.suse.com/susecon/&quot;&gt;SUSECON&lt;/a&gt;. The second is scheduled to take place on April 14, 2027, in Dallas, Texas. Both are one-day summits that bring together SUSE partners, openSUSE contributors, open-source community projects and enthusiasts for a day of shared ideas and collaboration. Whether you’re deep in the code or just passionate about open source, there’s a place for you at each.&lt;/p&gt;

&lt;h2 id=&quot;open-developers-summit--barcelona&quot;&gt;Open Developers Summit — Barcelona&lt;/h2&gt;

&lt;p&gt;The Open Developers Summit in Barcelona is scheduled to take place Feb. 18, 2027, and align with SUSECON. The call for proposals is open until &lt;strong&gt;Nov. 20, 2026&lt;/strong&gt;.&lt;/p&gt;

&lt;p&gt;Talks can cover operating systems, new technologies, cloud, infrastructure, edge, IoT, AI, data, programming languages, toolchains, security, DevOps, automation and more. If you have insights to share or a project worth spotlighting, this is your invitation to take the stage.&lt;/p&gt;

&lt;p&gt;Submit your talk and join us in Barcelona. Come to learn, connect and help shape where open development goes next.&lt;/p&gt;

&lt;h2 id=&quot;open-developers-summit--dallas&quot;&gt;Open Developers Summit — Dallas&lt;/h2&gt;

&lt;p&gt;The Open Developers Summit is scheduled to take place in Dallas, Texas, on April 14, 2027. The call for proposals is open until &lt;strong&gt;Jan. 20, 2027&lt;/strong&gt;.&lt;/p&gt;

&lt;p&gt;As in Barcelona, talks can cover operating systems, new technologies, cloud, infrastructure, edge, IoT, AI, data, programming languages, toolchains, security, DevOps, automation and beyond. If you have insight to share or a project worth spotlighting, this is your invitation to take the stage.&lt;/p&gt;

&lt;p&gt;Submit your talk and join us in Texas. Come to learn, connect and help shape where open development goes next.&lt;/p&gt;

&lt;h2 id=&quot;sponsor-a-summit&quot;&gt;Sponsor a Summit&lt;/h2&gt;

&lt;p&gt;Both summits are free community events made possible thanks to the generous support of sponsors and community donors. Sponsorship keeps the events accessible to all and fosters collaboration and knowledge-sharing across open-source communities.&lt;/p&gt;

&lt;p&gt;Companies interested in sponsoring can review the prospectus for each event and reach out to Douglas DeMaio at &lt;a href=&quot;mailto:ddemaio@opensuse.org&quot;&gt;ddemaio@opensuse.org&lt;/a&gt;:&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;&lt;strong&gt;Barcelona:&lt;/strong&gt; &lt;a href=&quot;https://en.opensuse.org/images/9/9a/ODSB_Prospectus.pdf&quot;&gt;ODSB Prospectus&lt;/a&gt;&lt;/li&gt;
  &lt;li&gt;&lt;strong&gt;Dallas:&lt;/strong&gt; &lt;a href=&quot;https://en.opensuse.org/images/0/02/ODSD_Prospectus.pdf&quot;&gt;ODSD Prospectus&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Sponsorship levels for the events include a Diamond, Emerald and Jade sponsorship donation, each offering logo placement, event recognition and promotion. Individuals and small organizations can also contribute through community donations.&lt;/p&gt;

&lt;p&gt;More details are available at &lt;a href=&quot;https://events.opensuse.org&quot;&gt;events.opensuse.org&lt;/a&gt;.&lt;/p&gt;

&lt;meta name=&quot;openSUSE, community, project, conference, Open Source, summit, Barcelona, Dallas, Developers, Call for Papers&quot; content=&quot;HTML,CSS,XML,JavaScript&quot; /&gt;

</content:encoded>
    </item>

    <item>
      <guid>https://news.opensuse.org/2026/07/21/updated-signig-key/</guid>
      <title>Updating the Signing Key on Leap Micro</title>
      <pubDate>Tue, 21 Jul 2026 09:00:00 +0000</pubDate>
      <link>https://news.opensuse.org/2026/07/21/updated-signig-key/</link>
      <author>admin@opensuse.org (Lubos Kocman)</author>
      <enclosure url="https://news.opensuse.org/wp-content/uploads/2024/06/micro60rc.png" length="1932882" type="image/png" />
      <description>openSUSE Leap Micro was the last to the party to receive the extended openSUSE signing key following its recent expiration. We’re deeply sorry for the inconvenience. The underlying issue has now been resolved everywhere. If your system still encounters repository signature errors, you can refresh the repository metadata and fetch...</description>
      <content:encoded>&lt;p&gt;openSUSE Leap Micro was the last to the party to receive the extended openSUSE signing key following its &lt;a href=&quot;https://bugzilla.opensuse.org/show_bug.cgi?id=1271450&quot;&gt;recent expiration&lt;/a&gt;. We’re deeply sorry for the inconvenience. The underlying issue has now been resolved everywhere.&lt;/p&gt;

&lt;p&gt;If your system still encounters repository signature errors, you can refresh the repository metadata and fetch the updated signing key manually.&lt;/p&gt;

&lt;p&gt;The &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;zypper ref -f&lt;/code&gt; command forces a refresh of the repository metadata, including the new GPG signing key. Normally this should happen automatically, but the current version of libzypp may not always retrieve the updated key correctly. Forcing a refresh resolves the problem.
Just to note that the &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;zypper ref -f&lt;/code&gt; will force new key on any openSUSE distribution.&lt;/p&gt;

&lt;p&gt;Run the following commands:&lt;/p&gt;

&lt;div class=&quot;language-plaintext highlighter-rouge&quot;&gt;&lt;div class=&quot;highlight&quot;&gt;&lt;pre class=&quot;highlight&quot;&gt;&lt;code&gt;transactional-update shell
zypper ref -f
zypper dup
exit # from tu shell
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/div&gt;

&lt;p&gt;After rebooting into the new snapshot, your system should be using the updated signing key and repository refreshes should work normally again.&lt;/p&gt;

&lt;p&gt;Have a lot of fun!&lt;/p&gt;

&lt;meta name=&quot;openSUSE, Open Source, development, Linux, secure operating systems, open source, plasma, Tumbleweed, GCompris, Slimbooks, Governance, Firefox&quot; content=&quot;HTML,CSS,XML,JavaScript&quot; /&gt;

</content:encoded>
    </item>

    <item>
      <guid>https://news.opensuse.org/2026/07/20/case-for-sponsoring-os/</guid>
      <title>The Case for Sponsoring openSUSE</title>
      <pubDate>Mon, 20 Jul 2026 10:00:00 +0000</pubDate>
      <link>https://news.opensuse.org/2026/07/20/case-for-sponsoring-os/</link>
      <author>admin@opensuse.org (Douglas DeMaio)</author>
      <enclosure url="https://news.opensuse.org/wp-content/uploads/2026/07/os.png" length="31858" type="image/png" />
      <description>Infrastructure runs on Linux, and Linux hardware is only as good as the software that builds, packages, signs and distributes its drivers and libraries, work that has to happen across dozens of distributions and several CPU architectures, every single day. That work has a home. The openSUSE Project has spent...</description>
      <content:encoded>&lt;p&gt;Infrastructure runs on Linux, and Linux hardware is only as good as the software that builds, packages, signs and distributes its drivers and libraries, work that has to happen across dozens of distributions and several CPU architectures, every single day.&lt;/p&gt;

&lt;p&gt;That work has a home. The &lt;a href=&quot;https://www.opensuse.org/&quot;&gt;openSUSE Project&lt;/a&gt; has spent years assembling a development structure that hardware vendors and enterprises now lean on:&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;&lt;a href=&quot;https://openbuildservice.org/&quot;&gt;Open Build Service&lt;/a&gt; compiles a single source tree into signed packages for nearly any distribution or architecture;&lt;/li&gt;
  &lt;li&gt;&lt;a href=&quot;https://open.qa/&quot;&gt;openQA&lt;/a&gt; boots and tests the results the way a real user would;&lt;/li&gt;
  &lt;li&gt;The rolling release &lt;a href=&quot;https://get.opensuse.org/tumbleweed/&quot;&gt;Tumbleweed&lt;/a&gt; and stable &lt;a href=&quot;https://get.opensuse.org/leap/&quot;&gt;Leap&lt;/a&gt; distributions serve as both upstream and supporting structure for Enterprise as a proving ground and downstream anchor;&lt;/li&gt;
  &lt;li&gt;&lt;a href=&quot;https://www.uyuni-project.org/&quot;&gt;Uyuni Project&lt;/a&gt;, the upstream of &lt;a href=&quot;https://www.suse.com/products/multi-linux-manager/&quot;&gt;SUSE Multi-Linux Manager&lt;/a&gt; pioneers the space that keeps deployed fleets patched and accounted for long after the packages ship.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Together, these answer the question every hardware maker eventually faces; build once, validate everywhere and deliver with confidence.&lt;/p&gt;

&lt;p&gt;Companies whose revenue depends on silicon “just working” in Linux data centers may evaluate funding this layer as an investment, not as charity. It is one of the highest-leverage, lowest-cost investments available. But communities like openSUSE depend on sponsors so that the contributing community can grow, support and thrive.&lt;/p&gt;

&lt;p&gt;SUSE is the primary sponsor of openSUSE, and the project has other &lt;a href=&quot;https://en.opensuse.org/Sponsors&quot;&gt;companies that sponsor the project&lt;/a&gt;. The project welcomes additional backers. Sponsorship takes three practical forms; money, hardware, or services. Sponsorship has historically been organized into tiers: Platinum, Gold, and Silver. The sponsors gain visibility and developer reach. Hardware sponsors sign an &lt;a href=&quot;https://en.opensuse.org/images/f/f1/Equipment-Donation-Agreement.pdf&quot;&gt;Equipment Donation Agreement&lt;/a&gt;. Services provided to contributing developers make development more efficient. And the &lt;a href=&quot;https://geekos.org/sponsorship/&quot;&gt;Geeko Foundation&lt;/a&gt;, a not-for-profit, acts as fiscal steward, receiving and administering funds on the project’s behalf to support contributors, travel and events.&lt;/p&gt;

&lt;h2 id=&quot;the-return-on-a-sponsorship&quot;&gt;The return on a sponsorship&lt;/h2&gt;

&lt;h3 id=&quot;1-the-whole-ecosystem-not-just-one-distro&quot;&gt;1. The whole ecosystem, not just one distro&lt;/h3&gt;

&lt;p&gt;OBS builds on the order of 140,000 packages for more than a dozen base distributions across many architectures. A vendor that donates silicon and sponsors build capacity gets its drivers and libraries built and validated across that entire matrix; Fedora, Debian, Ubuntu, the SUSE family and more.&lt;/p&gt;

&lt;p&gt;This is not a static archive. In a typical week, Tumbleweed absorbs on the order of 500 accepted change requests, moving Mesa, the Linux kernel, QEMU, GCC, LLVM, Rust, GNOME and KDE forward in lockstep. Paying engineers to chase each target distribution independently is expensive; the same result comes far more cost-effectively from developers already working inside the openSUSE ecosystem. Hardware that works on Linux ships and sells faster.&lt;/p&gt;

&lt;h3 id=&quot;2-silicon-qa-at-scale&quot;&gt;2. Silicon QA at scale&lt;/h3&gt;

&lt;p&gt;Packaging is only half the problem; the other half is testing. That is where openQA comes in; openSUSE’s automated OS-testing service, which boots real images and drives real installs.&lt;/p&gt;

&lt;p&gt;Pair it with sponsored hardware and a vendor’s drivers get exercised continuously: every snapshot, every architecture, in front of tens of thousands of real users doing unpredictable things. The value shows in the ordinary weekly record; compiler transitions caught in dedicated staging projects before they reach users, individual test failures tracked down to a specific step in a specific run, unresolvable dependencies counted and driven back down. Regressions surface on actual silicon earlier, and far more cheaply, than any internal lab could manage.&lt;/p&gt;

&lt;h3 id=&quot;3-growing-the-architecture-your-chips-are-trying-to-sell&quot;&gt;3. Growing the architecture your chips are trying to sell&lt;/h3&gt;

&lt;p&gt;openSUSE does not treat &lt;a href=&quot;https://www.arm.com/&quot;&gt;arm&lt;/a&gt; as an afterthought. Tumbleweed on arm rolls continuously alongside x86, with its own openQA coverage, and a dedicated &lt;a href=&quot;https://en.opensuse.org/Armv9_project&quot;&gt;ARMv9 project&lt;/a&gt; rebuilds the core of the distribution to take advantage of the newer baseline. s390x is maintained in parallel. A chipmaker sponsoring arm build capacity is directly cultivating the soil its own products grow in. And would be doing it where the architecture is already a first-class citizen rather than a port.&lt;/p&gt;

&lt;h3 id=&quot;4-faster-driver-delivery-fewer-support-tickets&quot;&gt;4. Faster driver delivery, fewer support tickets&lt;/h3&gt;

&lt;p&gt;The model already exists: openSUSE’s NVIDIA driver packages are maintained by SUSE engineers, with spec files living in OBS and coordinated with NVIDIA. A &lt;a href=&quot;https://en.opensuse.org/openSUSE:Factory_development_model&quot;&gt;factory first&lt;/a&gt; policy, where development happens upstream, deepens that relationship. Dedicated hardware, closer coordination and sponsored maintainer time all shorten the lag between a driver release and users actually being able to install it. Every week shaved off that cycle is support load a vendor never has to absorb.&lt;/p&gt;

&lt;h3 id=&quot;5-strategic-influence-on-neutral-ground-without-lock-in&quot;&gt;5. Strategic influence on neutral ground, without lock-in&lt;/h3&gt;

&lt;p&gt;OBS, openQA and Uyuni are deliberately vendor-neutral. None is tied to a single vendor’s product line; all three build, test and manage systems well beyond the SUSE family. For a chipmaker, neutrality is the point; sponsorship keeps the packaging pipeline healthy and open, so no single competitor ends up controlling how silicon reaches Linux.&lt;/p&gt;

&lt;p&gt;Uyuni is upstream of &lt;a href=&quot;https://www.suse.com/products/multi-linux-manager/&quot;&gt;SUSE Multi-Linux Manager&lt;/a&gt;, and that relationship cuts the way a sponsor should want: the upstream project sets direction and the commercial product follows, not the reverse. It’s the same arrangement that governs most of the Linux stack a vendor already ships on. A sponsor influences the open project and gets the benefit downstream, without buying into any vendor’s roadmap.&lt;/p&gt;

&lt;h3 id=&quot;6-developer-mindshare-isv-reach-and-recruiting&quot;&gt;6. Developer mindshare, ISV reach, and recruiting&lt;/h3&gt;

&lt;p&gt;Sponsorship has always carried visibility in front of the developers and independent software vendors who decide what runs where. In a labor market where kernel, driver and systems talent is scarce, presence in the openSUSE community is a recruiting channel and a credibility signal to the wider open-source world.&lt;/p&gt;

&lt;h2 id=&quot;the-bottom-line&quot;&gt;The bottom line&lt;/h2&gt;

&lt;p&gt;Put these together and you get a flywheel of mutual benefit. The technology gets built by the community at a fraction of what in-house enablement would cost, and it gets built continuously, in public, with the failures visible and tracked rather than discovered by a customer. The community gets what it needs to keep going: travel to the conferences where the work gets shared, hardware to test on, and infrastructure that grows as fast as the ideas do.&lt;/p&gt;

&lt;p&gt;For a business valued in the hundreds of billions, an equipment donation or a sponsored service is a rounding error. It is also one of the cleanest ways a company can fund the building of the technology it sells build on open-source. &lt;a href=&quot;https://geekos.org/sponsorship/&quot;&gt;Donations acknowledging community efforts&lt;/a&gt; are also encouraged.&lt;/p&gt;

&lt;p&gt;If you are interested in sponsoring openSUSE, we are open to options or suggestions.&lt;/p&gt;

&lt;p&gt;Providing space for hosting an openSUSE event or sponsoring the openSUSE Conference provides a unique opportunity to connect with open source users, system administrators, developers, designers, and community leaders. Sponsoring the conference also provides an opportunity to showcase your brand to the open-source knowledge.&lt;/p&gt;

&lt;p&gt;For more information, email &lt;a href=&quot;mailto:ddemaio@opensuse.org&quot;&gt;ddemaio@opensuse.org&lt;/a&gt;.&lt;/p&gt;

&lt;meta name=&quot;openSUSE, Open Source, development, Linux, secure operating systems, SUSE, AMD, Fastly, rsync.net, B1 Systems, Core-Backbone, Heinlein, Marvell&quot; content=&quot;HTML,CSS,XML,JavaScript&quot; /&gt;

</content:encoded>
    </item>

    <item>
      <guid>https://news.opensuse.org/2026/07/17/planet-roundup/</guid>
      <title>Planet News Roundup</title>
      <pubDate>Fri, 17 Jul 2026 08:00:00 +0000</pubDate>
      <link>https://news.opensuse.org/2026/07/17/planet-roundup/</link>
      <author>admin@opensuse.org (Douglas DeMaio)</author>
      <enclosure url="https://news.opensuse.org/wp-content/uploads/2025/07/planet.png" length="78165" type="image/png" />
      <description>This is a roundup of articles from the openSUSE community listed on planet.opensuse.org. The community blog feed aggregator lists the featured highlights below from July 10 to 16. Blogs this week cover the third Plasma 6.7 bugfix release, a SUSE security advisory on SELinux userspace utilities, a call for host...</description>
      <content:encoded>&lt;p&gt;This is a roundup of articles from the openSUSE community listed on &lt;a href=&quot;https://planet.opensuse.org&quot;&gt;planet.opensuse.org&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;The community blog feed aggregator lists the featured highlights below from July 10 to 16.&lt;/p&gt;

&lt;p&gt;Blogs this week cover the third Plasma 6.7 bugfix release, a SUSE security advisory on SELinux userspace utilities, a call for host proposals for the openSUSE.Asia Summit 2027, syslog-ng packages for Ubuntu 26.04, a keynote recap on open source trust and the Cyber Resilience Act, audio recording arriving in Spectacle, a Meteoclimatic desktop plasmoid, a Krita June development report, Slimbook’s local AI workstation and more.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Here is a summary and links for each post:&lt;/strong&gt;&lt;/p&gt;

&lt;h2 id=&quot;display-the-meteoclimatic-data-on-your-desktop-with-this-plasmoid-for-plasma-6-from-kde&quot;&gt;&lt;a href=&quot;https://victorhckinthefreeworld.com/2026/07/16/muestra-los-datos-de-meteoclimatic-en-tu-escritorio-con-este-plasmoide-para-plasma-6-de-kde/&quot;&gt;Display the Meteoclimatic data on your desktop with this Plasmoid for Plasma 6 from KDE&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;&lt;a href=&quot;https://victorhckinthefreeworld.com/&quot;&gt;Victorhck&lt;/a&gt; shares information about Plasma 6 plasmoid that visualizes Meteoclimatic weather station data directly on the desktop. Building on an earlier text-mode plasmoid and terminal scripts, this version presents the data with emoji icons for a more elegant and visually appealing display. Victorhck invites users to share screenshots of their configurations on Mastodon.&lt;/p&gt;

&lt;h2 id=&quot;nexus-ai-workstation-the-proposal-to-have-local-ai-free-on-slimbook&quot;&gt;&lt;a href=&quot;https://www.kdeblog.com/nexus-ai-workstation-la-propuesta-para-tener-ia-local-libre-de-slimbook.html&quot;&gt;Nexus AI Workstation, the proposal to have local AI free on Slimbook&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;The &lt;a href=&quot;https://www.kdeblog.com/&quot;&gt;KDE Blog&lt;/a&gt; presents Slimbook’s Nexus AI Workstation, a server family designed for running local AI workloads without relying on cloud token subscriptions. The goal is to offer a platform prepared for executing and developing AI workloads locally, combining high performance with the flexibility professionals, companies, researchers and developers demand.&lt;/p&gt;

&lt;h2 id=&quot;krita-report-june-2026&quot;&gt;&lt;a href=&quot;https://www.kdeblog.com/informe-de-junio-de-2026-de-krita.html&quot;&gt;Krita Report June 2026&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;The &lt;a href=&quot;https://www.kdeblog.com/&quot;&gt;KDE Blog&lt;/a&gt; covers the June 2026 Krita development report, highlighting releases 5.3.2.1 and 6.0.2.1 that fix severe regressions related to layer selection and crashes when working with wait frames. Krita Plus for Android replaces old contributor badges with downloadable resource packs and a Google Play subscription, along with improved interface scaling, transform tool fixes with multiple layers, and crash fixes when undoing text operations.&lt;/p&gt;

&lt;h2 id=&quot;third-bugfix-update-for-plasma-67&quot;&gt;&lt;a href=&quot;https://www.kdeblog.com/tercera-actualizacion-de-plasma-6-7.html&quot;&gt;Third Bugfix Update for Plasma 6.7&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;The &lt;a href=&quot;https://www.kdeblog.com/&quot;&gt;KDE Blog&lt;/a&gt; announces the third bugfix release for Plasma 6.7, delivering stability improvements, better translations, and error resolution across the desktop environment. The post also recaps the major new features of Plasma 6.7, including per-monitor virtual desktops, a microphone volume test tool, quick theme switching, a Vietnamese lunar calendar, and a new print queue manager.&lt;/p&gt;

&lt;h2 id=&quot;selinux-userspace-utilities-local-denial-of-service-attack-vectors-in-seunshare&quot;&gt;&lt;a href=&quot;https://security.opensuse.org/2026/07/15/selinux-seunshare/&quot;&gt;SELinux Userspace Utilities: Local Denial-of-Service Attack Vectors in seunshare&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;The &lt;a href=&quot;https://security.opensuse.org/&quot;&gt;SUSE Security Team&lt;/a&gt; discloses two local denial-of-service vulnerabilities in the &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;seunshare&lt;/code&gt; program from SELinux userspace utilities version 3.10. A symlink race condition in &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;rm_rf()&lt;/code&gt; allows deletion of root-owned files, while the &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;killall()&lt;/code&gt; function can be exploited to kill root-owned processes running in the unconfined SELinux domain. Both issues were independently fixed upstream in version 3.11.&lt;/p&gt;

&lt;h2 id=&quot;opensuseasia-summit-2027-call-for-host&quot;&gt;&lt;a href=&quot;https://news.opensuse.org/2026/07/14/osas-cfh/&quot;&gt;openSUSE.Asia Summit 2027: Call for Host&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;&lt;a href=&quot;https://news.opensuse.org/&quot;&gt;openSUSE News&lt;/a&gt; invites local openSUSE communities across Asia to submit proposals to host the openSUSE.Asia Summit 2027. The proposal deadline is August 10 with the host announcement scheduled for October 31 following presentations at the 2026 summit in Yogyakarta, Indonesia. Proposals should cover venue, transportation, budget, catering, and the local organizing team’s experience.&lt;/p&gt;

&lt;h2 id=&quot;syslog-ng-4120-available-for-ubuntu-2604-resolute&quot;&gt;&lt;a href=&quot;https://www.syslog-ng.com/community/b/blog/posts/syslog-ng-4-12-0-available-for-ubuntu-26-04-resolute&quot;&gt;Syslog-ng 4.12.0 Available for Ubuntu 26.04 (Resolute)&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;&lt;a href=&quot;https://peter.czanik.hu/&quot;&gt;Peter Czanik’s Blog&lt;/a&gt; confirms that syslog-ng now supports Ubuntu 26.04 with ready-to-use packages alongside the 4.12.0 release. The post fills a gap in his usual coverage, which tends to focus on FreeBSD, Fedora and openSUSE.&lt;/p&gt;

&lt;h2 id=&quot;bare-weather--weather-information-on-your-desktop-with-plasmoids-for-plasma-6-35&quot;&gt;&lt;a href=&quot;https://www.kdeblog.com/informacion-meteorologica-en-tu-escritorio-con-bare-weather-plasmoides-para-plasma-6-35.html&quot;&gt;Bare Weather – Weather Information on Your Desktop with Plasmoids for Plasma 6 (35)&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;The &lt;a href=&quot;https://www.kdeblog.com/&quot;&gt;KDE Blog&lt;/a&gt; presents Bare Weather, the 35th entry in its Plasma 6 plasmoid series, which delivers interactive weather data directly on the desktop. The widget by corral76 offers two layouts: a card design with animated icons and color-coded headers, and a graph design with scrollable temperature and precipitation curves.&lt;/p&gt;

&lt;h2 id=&quot;bash-and-fish-scripts-to-display-meteoclimatic-weather-station-data&quot;&gt;&lt;a href=&quot;https://victorhckinthefreeworld.com/2026/07/13/script-en-bash-y-fish-para-mostrar-los-datos-de-una-estacion-metereologica-de-meteoclimatic/&quot;&gt;Bash and Fish Scripts to Display Meteoclimatic Weather Station Data&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;&lt;a href=&quot;https://victorhckinthefreeworld.com/&quot;&gt;Victorhck&lt;/a&gt; shares Bash and Fish terminal scripts that display real-time weather data from Meteoclimatic amateur stations. The scripts use &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;curl&lt;/code&gt; and &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;awk&lt;/code&gt; with emoji icons to present the information, and the first run prompts for a station ID which is saved to a config file.&lt;/p&gt;

&lt;h2 id=&quot;this-month-in-kde-linux-june-2026&quot;&gt;&lt;a href=&quot;https://www.kdeblog.com/este-mes-de-junio-en-kde-linux/&quot;&gt;This Month in KDE Linux: June 2026&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;The &lt;a href=&quot;https://www.kdeblog.com/&quot;&gt;KDE Blog&lt;/a&gt; translates Nate Graham’s monthly progress report on KDE Linux, the community’s upcoming operating system. The project has reached 78 percent completion toward its beta milestone. Updates include Audex replacing the old CD ripping tool, a built-in log collection utility, and UEFI-only boot support.&lt;/p&gt;

&lt;h2 id=&quot;when-the-code-remains-clean-but-trust-collapses-the-new-era-of-open-source&quot;&gt;&lt;a href=&quot;https://eiosifidis.blogspot.com/2026/07/open-source-trust-cra-ai-security.html&quot;&gt;When the Code Remains Clean but Trust Collapses: The New Era of Open Source&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;&lt;a href=&quot;https://eiosifidis.blogspot.com/&quot;&gt;Efstathios&lt;/a&gt; summarizes the openSUSE Conference 2026 keynote by Hans de Raad on the intersection of open source security, the Cyber Resilience Act, and AI tooling risks. The post examines the GSD framework incident where clean code masked a collapsed trust chain, drawing parallels to the xz-utils backdoor.&lt;/p&gt;

&lt;h2 id=&quot;audio-recording-in-spectacle--this-week-in-plasma&quot;&gt;&lt;a href=&quot;https://www.kdeblog.com/grabacion-de-audio-en-spectacle-esta-semana-en-plasma/&quot;&gt;Audio Recording in Spectacle – This Week in Plasma&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;The &lt;a href=&quot;https://www.kdeblog.com/&quot;&gt;KDE Blog&lt;/a&gt; translates Nate Graham’s weekly Plasma development update, which highlights audio recording arriving in Spectacle for screen captures in Plasma 6.8. The update also covers VRAM usage display in System Monitor, the Ethiopian calendar addition, improved combobox theming, tablet stylus support for Overview overlays, and numerous bugfix releases across Plasma 6.6.6, 6.7.3, and Frameworks 6.29.&lt;/p&gt;

&lt;h2 id=&quot;linux-saloon-209--fedora-44&quot;&gt;&lt;a href=&quot;https://cubiclenate.com/2026/07/12/linux-saloon-209-fedora-44/&quot;&gt;Linux Saloon 209 | Fedora 44&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;&lt;a href=&quot;https://cubiclenate.com/&quot;&gt;Nathan’s Blog&lt;/a&gt; covers the latest Linux and technology news, including the Warthunder Sim Rig hardware build, font management in Linux, and the retirement of the “Father of the Internet.” The episode also discusses Firefox updates, the Steam Machine launch, and Fedora governance changes alongside the Fedora 44 release.&lt;/p&gt;

&lt;h2 id=&quot;kde-frameworks-6280-update&quot;&gt;&lt;a href=&quot;https://www.kdeblog.com/vigesimoctava-actualizacion-de-kde-frameworks-6-y-libreria-kcodecs.html&quot;&gt;KDE Frameworks 6.28.0 Update&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;The &lt;a href=&quot;https://www.kdeblog.com/&quot;&gt;KDE Blog&lt;/a&gt; announces KDE Frameworks 6.28 and continues its series describing each library in the framework collection. This month focuses on KCodecs, a Tier 1 library responsible for character set detection, XML entity translation, and email address validation across KDE applications.&lt;/p&gt;

&lt;h2 id=&quot;colors-graphics-and-performance-in-plasma-67&quot;&gt;&lt;a href=&quot;https://www.kdeblog.com/colores-graficos-y-rendimiento-en-plasma-6-7.html&quot;&gt;Colors, Graphics, and Performance in Plasma 6.7&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;The &lt;a href=&quot;https://www.kdeblog.com/&quot;&gt;KDE Blog&lt;/a&gt; covers the under-the-hood improvements in Plasma 6.7 related to color management, graphics rendering, and energy efficiency. Users can now use ICC color profiles and HDR content simultaneously. There is a new toggle to control reddish tinting at low brightness on AMD laptops. The team also achieved performance gains and reduced power consumption for CPU-rendered applications and Intel integrated GPUs.&lt;/p&gt;

&lt;h2 id=&quot;opensuse-tumbleweed-review-of-week-28-of-2026&quot;&gt;openSUSE Tumbleweed Review of Week 28 of 2026&lt;/h2&gt;
&lt;p&gt;&lt;a href=&quot;https://victorhckinthefreeworld.com/2026/07/10/opensuse-tumbleweed-revision-de-la-semana-28-de-2026/&quot;&gt;Victorhck&lt;/a&gt; and &lt;a href=&quot;https://dominique.leuenberger.net/blog/2026/07/tumbleweed-review-of-the-week-2026-28/&quot;&gt;Dominique Leuenberger&lt;/a&gt; provide a Spanish and English language review of four Tumbleweed snapshots (0702, 0703, 0707, and 0708) published during the week. Highlights include the removal of Python 3.11 modules while keeping the interpreter and pip, KDE Gear 26.04.3, Plasma 6.7.2, Linux kernel 7.1.2 and 7.1.3, Mesa 26.1.4, and systemd 260.3. Upcoming packages include GStreamer 1.28.5, SELinux toolchain 3.11, and GCC 16 as the default compiler.&lt;/p&gt;

&lt;p&gt;View more blogs or learn to publish your own on &lt;a href=&quot;https://planet.opensuse.org&quot;&gt;planet.opensuse.org&lt;/a&gt;.&lt;/p&gt;

&lt;meta name=&quot;openSUSE, Open Source, development, Linux, secure operating systems, KDE, Plasma, Tumbleweed, Frameworks, SELinux, Cyber Resilience Act, KDE Linux, syslog-ng, Meteoclimatic, AMD, Intel&quot; content=&quot;HTML,CSS,XML,JavaScript&quot; /&gt;

</content:encoded>
    </item>

    <item>
      <guid>https://news.opensuse.org/2026/07/14/osas-cfh/</guid>
      <title>openSUSE Asia Summit 2027 Call For Host</title>
      <pubDate>Tue, 14 Jul 2026 17:00:00 +0000</pubDate>
      <link>https://news.opensuse.org/2026/07/14/osas-cfh/</link>
      <author>admin@opensuse.org (openSUSE Asia Summit Team)</author>
      <enclosure url="https://news.opensuse.org/wp-content/uploads/2026/07/osas-2025.png" length="378615" type="image/png" />
      <description>openSUSE.Asia Summit 2027: Call for Host The openSUSE.Asia Summit is an annual conference that brings together openSUSE contributors, users, and Free and Open Source Software (FOSS) enthusiasts from across Asia. It provides a unique opportunity for the community to meet in person, exchange ideas, share technical knowledge, and strengthen collaboration....</description>
      <content:encoded>&lt;h1 id=&quot;opensuseasia-summit-2027-call-for-host&quot;&gt;openSUSE.Asia Summit 2027: Call for Host&lt;/h1&gt;

&lt;p&gt;The &lt;strong&gt;openSUSE.Asia Summit&lt;/strong&gt; is an annual conference that brings together openSUSE contributors, users, and Free and Open Source Software (FOSS) enthusiasts from across Asia. It provides a unique opportunity for the community to meet in person, exchange ideas, share technical knowledge, and strengthen collaboration.&lt;/p&gt;

&lt;p&gt;As the &lt;strong&gt;openSUSE.Asia Summit 2026&lt;/strong&gt; will be held in &lt;strong&gt;Yogyakarta, Indonesia&lt;/strong&gt;, the &lt;strong&gt;openSUSE.Asia Organization Committee&lt;/strong&gt; is now inviting local openSUSE communities to submit proposals to host the &lt;strong&gt;2027 summit&lt;/strong&gt;.&lt;/p&gt;

&lt;p&gt;Hosting the summit is a rewarding opportunity to showcase your local community, promote open source technologies, and connect with contributors from across Asia. The organizing committee will work closely with the selected team, providing guidance and sharing experiences from previous events throughout the planning process.&lt;/p&gt;

&lt;h2 id=&quot;important-dates&quot;&gt;Important Dates&lt;/h2&gt;

&lt;ul&gt;
  &lt;li&gt;&lt;strong&gt;10 August 2026&lt;/strong&gt; — Proposal submission deadline&lt;/li&gt;
  &lt;li&gt;&lt;strong&gt;4 October 2026&lt;/strong&gt; — Host proposal presentation during openSUSE.Asia Summit 2026 in Yogyakarta, Indonesia&lt;/li&gt;
  &lt;li&gt;&lt;strong&gt;31 October 2026&lt;/strong&gt; — Announcement of the openSUSE.Asia Summit 2027 host&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Applicants are encouraged to join our regular online meetings before the summit. This is a great opportunity to learn about the event organization process, ask questions, and interact with organizers from previous years.&lt;/p&gt;

&lt;h2 id=&quot;how-to-submit&quot;&gt;How to Submit&lt;/h2&gt;

&lt;p&gt;Please send your proposal to both:&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;&lt;strong&gt;summit@lists.opensuse.org&lt;/strong&gt;&lt;/li&gt;
  &lt;li&gt;&lt;strong&gt;opensuseasia-summit@googlegroups.com&lt;/strong&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Since &lt;strong&gt;summit@lists.opensuse.org&lt;/strong&gt; does not accept email attachments, please upload your proposal to a file-sharing service (such as Nextcloud, Google Drive, or Dropbox) and include the download link in your email.&lt;/p&gt;

&lt;h2 id=&quot;proposal-guidelines&quot;&gt;Proposal Guidelines&lt;/h2&gt;

&lt;p&gt;Your proposal should include at least the following information:&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;&lt;strong&gt;Host city and venue&lt;/strong&gt;&lt;/li&gt;
  &lt;li&gt;&lt;strong&gt;Transportation&lt;/strong&gt;
    &lt;ul&gt;
      &lt;li&gt;International access to your city&lt;/li&gt;
      &lt;li&gt;Local transportation to the venue&lt;/li&gt;
    &lt;/ul&gt;
  &lt;/li&gt;
  &lt;li&gt;&lt;strong&gt;Estimated budget&lt;/strong&gt;
    &lt;ul&gt;
      &lt;li&gt;Venue&lt;/li&gt;
      &lt;li&gt;Catering (coffee break, lunch, dinner)&lt;/li&gt;
      &lt;li&gt;Conference dinner&lt;/li&gt;
      &lt;li&gt;Conference tour (optional)&lt;/li&gt;
      &lt;li&gt;T-shirts and event materials&lt;/li&gt;
      &lt;li&gt;Other operational expenses&lt;/li&gt;
    &lt;/ul&gt;
  &lt;/li&gt;
  &lt;li&gt;&lt;strong&gt;Local organizing team&lt;/strong&gt;
    &lt;ul&gt;
      &lt;li&gt;Introduction to your local openSUSE community&lt;/li&gt;
      &lt;li&gt;Experience organizing conferences or community events&lt;/li&gt;
      &lt;li&gt;Expected volunteers and organizing structure&lt;/li&gt;
    &lt;/ul&gt;
  &lt;/li&gt;
  &lt;li&gt;&lt;strong&gt;Tentative event schedule&lt;/strong&gt;&lt;/li&gt;
  &lt;li&gt;&lt;strong&gt;Potential local sponsors or partners&lt;/strong&gt; (optional but recommended)&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Before preparing your proposal, please read the &lt;strong&gt;openSUSE.Asia Summit Tips for Organizers&lt;/strong&gt;:&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;&lt;a href=&quot;https://en.opensuse.org/openSUSE:Asia_Summit_Tips_for_Organizers&quot;&gt;https://en.opensuse.org/openSUSE:Asia_Summit_Tips_for_Organizers&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;We look forward to receiving your proposal and welcoming a new host community for &lt;strong&gt;openSUSE.Asia Summit 2027&lt;/strong&gt;. We hope to see your community become the next destination for the openSUSE community in Asia!&lt;/p&gt;
</content:encoded>
    </item>

    <item>
      <guid>https://news.opensuse.org/2026/07/10/planet-roundup/</guid>
      <title>Planet News Roundup</title>
      <pubDate>Fri, 10 Jul 2026 08:00:00 +0000</pubDate>
      <link>https://news.opensuse.org/2026/07/10/planet-roundup/</link>
      <author>admin@opensuse.org (Douglas DeMaio)</author>
      <enclosure url="https://news.opensuse.org/wp-content/uploads/2025/07/planet.png" length="78165" type="image/png" />
      <description>This is a roundup of articles from the openSUSE community listed on planet.opensuse.org. The community blog feed aggregator lists the featured highlights below from July 3 to 9. Blogs this week cover usability and printer improvements in Plasma 6.7, a sixth bugfix update for Plasma 6.6, and openSUSE’s support for...</description>
      <content:encoded>&lt;p&gt;This is a roundup of articles from the openSUSE community listed on &lt;a href=&quot;https://planet.opensuse.org&quot;&gt;planet.opensuse.org&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;The community blog feed aggregator lists the featured highlights below from July 3 to 9.&lt;/p&gt;

&lt;p&gt;Blogs this week cover usability and printer improvements in Plasma 6.7, a sixth bugfix update for Plasma 6.6, and openSUSE’s support for the XBOOTLDR partition to ease systemd-boot migration. Posts also include a GSoC update on SVG build badges, a new Meteoclimatic plasmoid, a Tellico collection manager update, the July Krita drawing challenge, a retro LCD clock plasmoid, a critique of traditional AI benchmarks, a gVim Wayland guide, Tumbleweed snapshots for week 27, KDE Gear 26.04.3, animation improvements in Plasma, and the Linux Saloon podcast.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Here is a summary and links for each post:&lt;/strong&gt;&lt;/p&gt;

&lt;h2 id=&quot;syslog-ng-java-destination-disabled&quot;&gt;&lt;a href=&quot;https://peter.czanik.hu/other/syslog-ng-java-destination-disabled/&quot;&gt;Syslog-ng Java Destination Disabled&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;&lt;a href=&quot;https://peter.czanik.hu/&quot;&gt;Peter Czanik’s Blog&lt;/a&gt; announces that Java support is being disabled in all of his syslog-ng packages as a “scream test.” Native C libraries now cover Elasticsearch and Kafka, HDFS has practically disappeared, and the Java drivers were removed from the source code years ago without complaint. The change has already landed in the official openSUSE package, with Fedora Rawhide and git snapshot packages next, and users relying on their own Java driver code are asked to speak up.&lt;/p&gt;

&lt;h2 id=&quot;kdenlive-26043-released&quot;&gt;&lt;a href=&quot;https://www.kdeblog.com/lanzado-de-kdenlive-26-04-3.html&quot;&gt;Kdenlive 26.04.3 Released&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;The &lt;a href=&quot;https://www.kdeblog.com/&quot;&gt;KDE Blog&lt;/a&gt; covers the release of Kdenlive 26.04.3, the final maintenance update of the 26.04 series. The update fixes crashes when undoing sequence creation and when recording audio without an audio device. It also continues the cycle’s security hardening by preventing unwanted command execution on MLT versions older than 7.40.&lt;/p&gt;

&lt;h2 id=&quot;thunderbird-listens-to-its-community-to-improve-the-desktop-application&quot;&gt;&lt;a href=&quot;https://victorhckinthefreeworld.com/2026/07/08/thunderbird-escucha-a-las-personas-que-lo-usan-para-mejorar-su-aplicacion-de-escritorio/&quot;&gt;Thunderbird Listens to Its Community to Improve the Desktop Application&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;&lt;a href=&quot;https://victorhckinthefreeworld.com/&quot;&gt;Victorhck&lt;/a&gt; translates Thunderbird’s summary of hour-long interviews with ten users about how they manage preferences and settings in the desktop client. Findings include a “set and forget” configuration habit, a desire to cut clutter and cognitive noise from dense settings menus, and confusion caused by overly technical terminology.&lt;/p&gt;

&lt;h2 id=&quot;scmci-project-links-and-better-handling-of-disconnected-branches&quot;&gt;&lt;a href=&quot;https://openbuildservice.org/2026/07/08/scm-ci-update/&quot;&gt;SCM/CI: Project Links and Better Handling of Disconnected Branches&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;The &lt;a href=&quot;https://openbuildservice.org/&quot;&gt;Open Build Service Blog&lt;/a&gt; announces an extension to the SCM/CI integration with a new link project step, letting users create project links directly in their workflows. This fills a missing piece needed to allow full project rebuilds for PR/MR sources such as stagings. The update also improves how OBS handles Git branches that do not contain a workflow definition file.&lt;/p&gt;

&lt;h2 id=&quot;usability-improvements-in-plasma-67&quot;&gt;&lt;a href=&quot;https://www.kdeblog.com/mejoras-en-la-usabilidad-en-plasma-6-7.html&quot;&gt;Usability Improvements in Plasma 6.7&lt;/a&gt;&lt;/h2&gt;

&lt;p&gt;The &lt;a href=&quot;https://www.kdeblog.com/&quot;&gt;KDE Blog&lt;/a&gt; covers the usability enhancements in Plasma 6.7, including drag-and-drop favorites management, a more intuitive Discover software center, and faster virtual desktop switching in the Overview effect. The update also introduces an autocomplete mode for desktop file selection and easier time zone comparison in the Digital Clock widget.&lt;/p&gt;

&lt;h2 id=&quot;the-illusion-of-benchmarks-traditional-kpis-dont-make-sense-for-measuring-llms&quot;&gt;&lt;a href=&quot;https://assuntonerd.com.br/2026/07/07/a-ilusao-dos-benchmarks-kpis-tradicionais-nao-fazem-sentido-para-medir-llms/&quot;&gt;The Illusion of Benchmarks: Traditional KPIs Don’t Make Sense for Measuring LLMs&lt;/a&gt;&lt;/h2&gt;

&lt;p&gt;&lt;a href=&quot;https://assuntonerd.com.br/&quot;&gt;Alessandro’s Blog&lt;/a&gt; argues that traditional benchmarks and KPIs are misleading when applied to large language models. Unlike conventional software, LLMs behave probabilistically and may ace academic tests while failing at real-world business tasks. The post warns that benchmark scores have increasingly become marketing tools rather than meaningful measures of actual capability.&lt;/p&gt;

&lt;h2 id=&quot;sixth-bugfix-update-for-plasma-66&quot;&gt;&lt;a href=&quot;https://www.kdeblog.com/sexta-actualizacion-de-plasma-6-6.html&quot;&gt;Sixth Bugfix Update for Plasma 6.6&lt;/a&gt;&lt;/h2&gt;

&lt;p&gt;The &lt;a href=&quot;https://www.kdeblog.com/&quot;&gt;KDE Blog&lt;/a&gt; announces the sixth bugfix release for Plasma 6.6, arriving nearly two months after the initial release. The update continues KDE’s regular maintenance cycle with stability improvements, better translations, and error resolution across the desktop environment.&lt;/p&gt;

&lt;h2 id=&quot;support-of-xbootldr-in-opensuse&quot;&gt;&lt;a href=&quot;https://news.opensuse.org/2026/07/07/xbootldr/&quot;&gt;Support of XBOOTLDR in openSUSE&lt;/a&gt;&lt;/h2&gt;

&lt;p&gt;&lt;a href=&quot;https://news.opensuse.org/&quot;&gt;openSUSE News&lt;/a&gt; explains how the XBOOTLDR partition provides an escape hatch for systems with insufficient ESP space when migrating to systemd-boot. The new partition can live anywhere on the disk and frees the ESP from storing kernel and initrd files. The post includes practical steps for creating the partition, configuring mount points, and migrating boot entries.&lt;/p&gt;

&lt;h2 id=&quot;meteoclimatic-plasmoid-for-the-kde-plasma-desktop&quot;&gt;&lt;a href=&quot;https://victorhckinthefreeworld.com/2026/07/07/plasmoide-para-mostrar-la-informacion-de-meteoclimatic-en-el-escritorio-plasma-de-kde/&quot;&gt;Meteoclimatic Plasmoid for the KDE Plasma Desktop&lt;/a&gt;&lt;/h2&gt;

&lt;p&gt;&lt;a href=&quot;https://victorhckinthefreeworld.com/&quot;&gt;Victorhck&lt;/a&gt; introduces his first KDE Plasma 6 plasmoid, which displays real-time weather data from Meteoclimatic amateur weather stations directly on the desktop. The widget supports configurable font size, color, opacity, and background visibility. The code is hosted on Codeberg for easy installation and customization.&lt;/p&gt;

&lt;h2 id=&quot;printer-improvements-in-plasma-67&quot;&gt;&lt;a href=&quot;https://www.kdeblog.com/mejoras-para-las-impresoras-en-plasma-6-7.html&quot;&gt;Printer Improvements in Plasma 6.7&lt;/a&gt;&lt;/h2&gt;

&lt;p&gt;The &lt;a href=&quot;https://www.kdeblog.com/&quot;&gt;KDE Blog&lt;/a&gt; highlights the printing enhancements in Plasma 6.7, including a system tray printer icon that now shows active job counts. A new print queue management tool offers advanced multi-printer administration while remaining accessible for home use, and connecting to shared printers on Windows networks has been simplified.&lt;/p&gt;

&lt;h2 id=&quot;krita-july-2026-drawing-challenge-kritachallenge&quot;&gt;&lt;a href=&quot;https://www.kdeblog.com/concurso-de-dibujo-krita-de-julio-2026-kritachallenge.html&quot;&gt;Krita July 2026 Drawing Challenge #KritaChallenge&lt;/a&gt;&lt;/h2&gt;

&lt;p&gt;The &lt;a href=&quot;https://www.kdeblog.com/&quot;&gt;KDE Blog&lt;/a&gt; promotes the monthly Krita drawing challenge for July 2026 with the theme “An Imaginary Friend.” Entries must be at least 90% created in Krita with no AI-generated content allowed. The winner earns the right to choose the next month’s theme and receives a featured spot on the site.&lt;/p&gt;

&lt;h2 id=&quot;new-tellico-update&quot;&gt;&lt;a href=&quot;https://www.kdeblog.com/nueva-actualizacion-de-tellico.html&quot;&gt;New Tellico Update&lt;/a&gt;&lt;/h2&gt;

&lt;p&gt;The &lt;a href=&quot;https://www.kdeblog.com/&quot;&gt;KDE Blog&lt;/a&gt; announces Tellico 4.2.1, the latest release of KDE’s collection manager. The update refreshes data sources for Google Books, Google Scholar, and Colnect, and adds support for multiple ISBN values and a user-defined data fetch argument. The release continues the application’s migration to Qt6 and KDE Frameworks 6.&lt;/p&gt;

&lt;h2 id=&quot;the-machinist&quot;&gt;&lt;a href=&quot;https://blog.jimmac.eu/posts/the-machinist/&quot;&gt;The Machinist&lt;/a&gt;&lt;/h2&gt;

&lt;p&gt;&lt;a href=&quot;https://blog.jimmac.eu/&quot;&gt;Jakub Steiner&lt;/a&gt; shares a brief personal reflection prompted by a recovered memory during a run, recommending Christian Bale’s film “The Machinist.” The post praises the movie’s mood, acting, and the director’s use of industrial imagery without revealing plot details.&lt;/p&gt;

&lt;h2 id=&quot;gsoc-update-1-can-svg-build-badges-update-themselves&quot;&gt;&lt;a href=&quot;https://mmarhin.github.io/gsoc2026blog/gsoc/opensuse/svg/javascript/2026/07/05/update-1-svg-javascript-limitations.html&quot;&gt;GSoC Update 1: Can SVG Build Badges Update Themselves?&lt;/a&gt;&lt;/h2&gt;

&lt;p&gt;&lt;a href=&quot;https://mmarhin.github.io/gsoc2026blog/&quot;&gt;Mario’s GSoC Blog&lt;/a&gt; explores whether SVG build badges generated by obs-status-service can self-update in Gitea. Testing reveals that JavaScript inside SVG runs when embedded as an &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;&amp;lt;object&amp;gt;&lt;/code&gt; or &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;&amp;lt;iframe&amp;gt;&lt;/code&gt;, but not as an &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;&amp;lt;img&amp;gt;&lt;/code&gt;, which is how Markdown renders images by default. The post concludes that live-updating badges are possible if Gitea serves them as objects, with a fallback to static server-side rendering for img contexts.&lt;/p&gt;

&lt;h2 id=&quot;retro-lcd-7-segment-clock--plasmoids-for-plasma-6-34&quot;&gt;&lt;a href=&quot;https://www.kdeblog.com/reloj-retro-lcd-7-segment-clock-plasmoides-para-plasma-6-34.html&quot;&gt;Retro LCD 7-Segment Clock – Plasmoids for Plasma 6 (34)&lt;/a&gt;&lt;/h2&gt;

&lt;p&gt;The &lt;a href=&quot;https://www.kdeblog.com/&quot;&gt;KDE Blog&lt;/a&gt; presents the 34th installment in its plasmoid series, featuring a retro LCD 7-segment clock widget for Plasma 6. Created by corral76, the minimalist widget offers customizable colors, font, time format, blinking colon, shadow toggle, date display, and an alarm feature.&lt;/p&gt;

&lt;h2 id=&quot;linux-saloon-208--news-flight-early-edition&quot;&gt;&lt;a href=&quot;https://cubiclenate.com/2026/07/04/linux-saloon-208-news-flight-early-edition/&quot;&gt;Linux Saloon 208 | News Flight Early Edition&lt;/a&gt;&lt;/h2&gt;

&lt;p&gt;&lt;a href=&quot;https://cubiclenate.com/&quot;&gt;Nathan Wolf’s Blog&lt;/a&gt; covers the latest Linux and technology news, including hardware builds like the Warthunder Sim Rig, font management in Linux, and Firefox updates. The episode also discusses the Steam Machine launch, Fedora governance changes, and the retirement of the “Father of the Internet.”&lt;/p&gt;

&lt;h2 id=&quot;improving-animations--this-week-in-plasma&quot;&gt;&lt;a href=&quot;https://www.kdeblog.com/mejorando-las-animaciones-esta-semana-en-plasma.html&quot;&gt;Improving Animations – This Week in Plasma&lt;/a&gt;&lt;/h2&gt;

&lt;p&gt;The &lt;a href=&quot;https://www.kdeblog.com/&quot;&gt;KDE Blog&lt;/a&gt; translates Nate Graham’s weekly Plasma report, highlighting animation improvements coming in Plasma 6.8 with better physics models and smoother notification sliding. The post also covers bugfixes across Plasma 6.6.6, 6.7.2, and 6.7.3, including KWin crash fixes, display corrections, and security hardening for task manager widgets.&lt;/p&gt;

&lt;h2 id=&quot;make-gvim-clientserver-work-with-wayland&quot;&gt;&lt;a href=&quot;https://www.freeaptitude.altervista.org/articles/make-gvim-clientserver-work-with-wayland.html&quot;&gt;Make gVim clientserver work with Wayland&lt;/a&gt;&lt;/h2&gt;

&lt;p&gt;&lt;a href=&quot;https://www.freeaptitude.altervista.org/&quot;&gt;FreeAptitude’s Blog&lt;/a&gt; provides a guide for getting gVim’s clientserver functionality working under Wayland, building on a previous Dolphin service menu for opening files in gVim tabs. The post addresses the compatibility challenges between the X11-based clientserver protocol and Wayland’s security model.&lt;/p&gt;

&lt;h2 id=&quot;tumbleweed--review-of-the-week-202627&quot;&gt;Tumbleweed – Review of the Week 2026/27&lt;/h2&gt;

&lt;p&gt;&lt;a href=&quot;https://victorhckinthefreeworld.com/2026/07/03/opensuse-tumbleweed-revision-de-la-semana-27-de-2026/&quot;&gt;Victorhck&lt;/a&gt; and &lt;a href=&quot;https://dominique.leuenberger.net/blog/2026/07/tumbleweed-review-of-the-week-2026-27/&quot;&gt;Dominique Leuenberger&lt;/a&gt; report on three published Tumbleweed snapshots (0627, 0628, 0630) with updates to libzio 1.15, Mozilla Firefox 152.0.3, gpgme 2.1.1, and Pango 1.58.0. In-progress staging includes KDE Gear 26.04.3, KDE Plasma 6.7.2, Linux kernel 7.1.2, Mesa 26.1.4, Podman 6.0.0, and Qemu 11.0.0 dropping 32-bit host support.&lt;/p&gt;

&lt;h2 id=&quot;third-update-of-kde-gear-2604&quot;&gt;&lt;a href=&quot;https://www.kdeblog.com/tercera-actualizacion-de-kde-gear-26-04.html&quot;&gt;Third Update of KDE Gear 26.04&lt;/a&gt;&lt;/h2&gt;

&lt;p&gt;The &lt;a href=&quot;https://www.kdeblog.com/&quot;&gt;KDE Blog&lt;/a&gt; announces KDE Gear 26.04.3, the third bugfix update for the KDE applications suite. Notable fixes include Elisa properly switching audio output devices when the global output changes, KDE Connect resolving file transfer issues when notification sending is enabled, and Kdenlive fixing the playback head disappearing during preview.&lt;/p&gt;

&lt;p&gt;View more blogs or learn to publish your own on &lt;a href=&quot;https://planet.opensuse.org&quot;&gt;planet.opensuse.org&lt;/a&gt;.&lt;/p&gt;

&lt;meta name=&quot;openSUSE, Open Source, development, Linux, secure operating systems&quot; content=&quot;HTML,CSS,XML,JavaScript&quot; /&gt;

</content:encoded>
    </item>

    <item>
      <guid>https://news.opensuse.org/2026/07/07/xbootldr/</guid>
      <title>Support of XBOOTLDR in openSUSE</title>
      <pubDate>Tue, 07 Jul 2026 15:00:00 +0000</pubDate>
      <link>https://news.opensuse.org/2026/07/07/xbootldr/</link>
      <author>admin@opensuse.org (Alberto Planas)</author>
      <enclosure url="https://news.opensuse.org/wp-content/uploads/2026/05/microos.png" length="36247" type="image/png" />
      <description>More Space openSUSE moved to BLS some time ago using the bootloaders systemd-boot and GRUB2-BLS that nowadays is mostly a repackaging of the traditional GRUB2, as the main patches are already merged since 2.16. This decision also required more space in the ESP partition, as now the kernel and initrds...</description>
      <content:encoded>&lt;h2 id=&quot;more-space&quot;&gt;More Space&lt;/h2&gt;

&lt;p&gt;openSUSE moved to &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;BLS&lt;/code&gt; some time ago using the bootloaders &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;systemd-boot&lt;/code&gt; and &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;GRUB2-BLS&lt;/code&gt; that nowadays is mostly a repackaging of the traditional &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;GRUB2&lt;/code&gt;, as the main patches are already merged since 2.16.&lt;/p&gt;

&lt;p&gt;This decision also required more space in the &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;ESP&lt;/code&gt; partition, as now the kernel and &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;initrd&lt;/code&gt;s of all snapshots are stored in &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;/boot/efi/$TOKEN&lt;/code&gt;, where &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;$TOKEN&lt;/code&gt; can be the &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;machine-id&lt;/code&gt;, &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;opensuse-tumbleweed&lt;/code&gt; or &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;opensuse-microos&lt;/code&gt;, depending on the installation.  For new installations, this is not a problem since the installer (&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;YaST&lt;/code&gt; or &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;Agama&lt;/code&gt;) will recommend a large (1 GB) partition; for older installations, the migration can be problematic, to the extreme that if the partition cannot be resized. It is advisable to keep the old &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;GRUB2-EFI&lt;/code&gt; bootloader.&lt;/p&gt;

&lt;p&gt;But if we decide to use &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;systemd-boot&lt;/code&gt;, there is a escape hatch: &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;XBOOTLDR&lt;/code&gt;&lt;/p&gt;

&lt;h2 id=&quot;a-new-partition&quot;&gt;A New Partition&lt;/h2&gt;

&lt;p&gt;&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;XBOOTLDR&lt;/code&gt; is a new partition that can live anywhere in the disk.  The &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;ESP&lt;/code&gt; has some limitations in that regard, and usually is the first partition in the system.  If present, &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;systemd-boot&lt;/code&gt; will look for the menu entries and the kernel / &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;initrd&lt;/code&gt;s in there, freeing the &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;ESP&lt;/code&gt; of that responsibility.&lt;/p&gt;

&lt;p&gt;The file system of this partition needs to be also &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;FAT32&lt;/code&gt;, like the &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;ESP&lt;/code&gt; as this is a limitation of the &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;UEFI&lt;/code&gt;, and during the creation needs have a specific &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;GPT&lt;/code&gt; identifier (&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;GUID&lt;/code&gt;).  With &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;fsdisk&lt;/code&gt;, we can create a new partition and assign the type &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;142&lt;/code&gt; or &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;xbootldr&lt;/code&gt;; this will assign the correct &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;GUID&lt;/code&gt; into the partition table and &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;systemd-boot&lt;/code&gt; will recognize it.&lt;/p&gt;

&lt;h2 id=&quot;mount-points&quot;&gt;Mount Points&lt;/h2&gt;

&lt;p&gt;Because of this new partition, the mount points needs to change too.  As commented, the traditional place where openSUSE put the &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;ESP&lt;/code&gt; is in &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;/boot/efi&lt;/code&gt; but now we have two places.  The UAPI recommendation is to have always the boot entries and the kernel in &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;/boot&lt;/code&gt;, and only if there is a separated partition for the boot loader, then this will be placed in &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;/efi&lt;/code&gt;.  Because this is the case now, we will need to update out &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;/etc/fstab&lt;/code&gt;:&lt;/p&gt;

&lt;div class=&quot;language-plaintext highlighter-rouge&quot;&gt;&lt;div class=&quot;highlight&quot;&gt;&lt;pre class=&quot;highlight&quot;&gt;&lt;code&gt;UUID=4165-E891 /efi  vfat utf8,dmask=0077,noexec,nodev,nosuid,nosymfollow 0 2
UUID=414C-528C /boot vfat utf8,dmask=0077,noexec,nodev,nosuid,nosymfollow 0 2
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/div&gt;

&lt;p&gt;Change the &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;UUID&lt;/code&gt; to point to the correct device.&lt;/p&gt;

&lt;p&gt;&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;sdbootutil&lt;/code&gt; can find both partitions and write in the correct place now, depending if we are updating the bootloader or adding new entries.&lt;/p&gt;

&lt;p&gt;Now we can move the boot entries and the kernel directories, both placed in the old &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;/boot/efi/loader&lt;/code&gt; path.  We can manually move it into the new partition, just keep &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;loader/random-seed&lt;/code&gt; and &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;loader/loader.conf&lt;/code&gt; in the old place, but the rest of the &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;loader/&lt;/code&gt; directory can be moved.&lt;/p&gt;

&lt;p&gt;More information about a more detailed description can be found in the following section:&lt;/p&gt;

&lt;h2 id=&quot;further-documentation&quot;&gt;Further Documentation&lt;/h2&gt;

&lt;ul&gt;
  &lt;li&gt;&lt;a href=&quot;https://en.opensuse.org/Portal:MicroOS/FDE#Migrating_from_GRUB2-EFI&quot;&gt;Migrating from GRUB2-EFI&lt;/a&gt;&lt;/li&gt;
  &lt;li&gt;&lt;a href=&quot;https://en.opensuse.org/Portal:MicroOS/FDE#XBOOTLDR&quot;&gt;MicroOS FDE&lt;/a&gt;&lt;/li&gt;
  &lt;li&gt;&lt;a href=&quot;https://uapi-group.org/specifications/specs/boot_loader_specification/&quot;&gt;UAPI.1 The Boot Loader Specification&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
</content:encoded>
    </item>

    <item>
      <guid>https://news.opensuse.org/2026/07/03/planet-roundup/</guid>
      <title>Planet News Roundup</title>
      <pubDate>Fri, 03 Jul 2026 08:00:00 +0000</pubDate>
      <link>https://news.opensuse.org/2026/07/03/planet-roundup/</link>
      <author>admin@opensuse.org (Douglas DeMaio)</author>
      <enclosure url="https://news.opensuse.org/wp-content/uploads/2025/07/planet.png" length="78165" type="image/png" />
      <description>This is a roundup of articles from the openSUSE community listed on planet.opensuse.org. The community blog feed aggregator lists the featured highlights below from June 26 to July 2. Blogs this week cover Hans de Raad’s openSUSE Conference keynote on the Cyber Resilience Act and sovereign open-source assurance, a Google...</description>
      <content:encoded>&lt;p&gt;This is a roundup of articles from the openSUSE community listed on &lt;a href=&quot;https://planet.opensuse.org&quot;&gt;planet.opensuse.org&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;The community blog feed aggregator lists the featured highlights below from June 26 to July 2.&lt;/p&gt;

&lt;p&gt;Blogs this week cover Hans de Raad’s openSUSE Conference keynote on the Cyber Resilience Act and sovereign open-source assurance, a Google Summer of Code midterm report on building a local offline AI assistant for openSUSE Leap, and the Tumbleweed Monthly Update for June with major version bumps across the stack. Posts also include KDE Plasma 6.7 bugfix updates, Germany mandating ODF across its public administration, Meta’s Brain2Qwerty brain-computer interface research, OpenCV 5.0.0, and a hardware fix for the Heltec ESP32 Lora32 V3 OLED issue.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Here is a summary and links for each post:&lt;/strong&gt;&lt;/p&gt;

&lt;h2 id=&quot;heltec-esp32-lora32-v3-oled-issue-fix&quot;&gt;&lt;a href=&quot;https://seifesrants.blogspot.com/2026/07/heltec-esp32-lora32-v3-oled-issue-fix.html&quot;&gt;Heltec ESP32 Lora32 V3 OLED issue fix&lt;/a&gt;&lt;/h2&gt;

&lt;p&gt;&lt;a href=&quot;https://seifesrants.blogspot.com/&quot;&gt;Stefan Seyfried’s Blog&lt;/a&gt; documents a hardware-level fix for the Heltec ESP32 Lora32 V3 board whose OLED display would not initialize with standard libraries. The solution requires enabling the VEXT pin by pulling its GPIO low in the setup() function, which was otherwise well hidden in Heltec’s own hacked library versions.&lt;/p&gt;

&lt;h2 id=&quot;free-software-foundation-july-2026-newsletter-roundup&quot;&gt;&lt;a href=&quot;https://victorhckinthefreeworld.com/2026/07/02/recopilacion-del-boletin-de-noticias-de-la-free-software-foundation-julio-de-2026/&quot;&gt;Free Software Foundation July 2026 Newsletter Roundup&lt;/a&gt;&lt;/h2&gt;

&lt;p&gt;&lt;a href=&quot;https://victorhckinthefreeworld.com/&quot;&gt;Victorhck&lt;/a&gt; provides a Spanish compilation and translation of the Free Software Foundation’s July 2026 newsletter. Highlights include the FSFE’s position on Android DMA interoperability calling for the right to fully uninstall machine learning features, a piece on vendor lock-in being about document formats rather than applications, and the FSF’s monthly free software advocacy roundup.&lt;/p&gt;

&lt;h2 id=&quot;whats-new-in-plasma-67-global-themes&quot;&gt;&lt;a href=&quot;https://www.kdeblog.com/novedades-en-los-temas-globales-de-plasma-6-7.html&quot;&gt;What’s New in Plasma 6.7 Global Themes&lt;/a&gt;&lt;/h2&gt;

&lt;p&gt;The &lt;a href=&quot;https://www.kdeblog.com/&quot;&gt;KDE Blog&lt;/a&gt; highlights the global theme changes in Plasma 6.7. Classic KDE 4 themes Oxygen and Air have been revived and updated to match the Breeze standard, including restored wallpapers and adaptive transparency support. A new Union theming system is introduced as a technical preview, allowing Plasma, QtQuick, and QtWidgets applications to be styled with a single CSS file.&lt;/p&gt;

&lt;h2 id=&quot;tumbleweed-monthly-update---june-2026&quot;&gt;&lt;a href=&quot;https://news.opensuse.org/2026/07/01/tw-monthly-update-june/&quot;&gt;Tumbleweed Monthly Update - June 2026&lt;/a&gt;&lt;/h2&gt;

&lt;p&gt;&lt;a href=&quot;https://news.opensuse.org/&quot;&gt;openSUSE News&lt;/a&gt; summarizes the June snapshot cycle for Tumbleweed. Major version bumps include Samba 4.24.3 with seven CVE fixes, MariaDB advancing from 11.8 to 12.3.2, and Flatpak 1.18.0. The second half of June was headlined by KDE Plasma 6.7.0 and KDE Frameworks 6.27.0. OpenSSL, WebKitGTK, and the Linux kernel each received extensive rounds of security fixes.&lt;/p&gt;

&lt;h2 id=&quot;7-months-and-only-7-donations--kde-blog-seeks-community-support&quot;&gt;&lt;a href=&quot;https://www.kdeblog.com/7-meses-y-solo-7-donaciones-kde-blog-solicita-colaboracion-de-la-comunidad.html&quot;&gt;7 Months and Only 7 Donations – KDE Blog Seeks Community Support&lt;/a&gt;&lt;/h2&gt;

&lt;p&gt;The &lt;a href=&quot;https://www.kdeblog.com/&quot;&gt;KDE Blog&lt;/a&gt; reflects on running the blog independently after a hosting transition to Neodigit, with only seven donations received in seven months. The post renews the call for community support to cover roughly 130 euros per year in hosting and domain costs, and invites readers to contribute through small donations or sponsored articles related to digital topics.&lt;/p&gt;

&lt;h2 id=&quot;opencv-500-the-biggest-evolution-of-opencv-in-years&quot;&gt;&lt;a href=&quot;https://assuntonerd.com.br/2026/07/01/opencv-5-0-0-a-maior-evolucao-do-opencv-em-anos/&quot;&gt;OpenCV 5.0.0: The Biggest Evolution of OpenCV in Years&lt;/a&gt;&lt;/h2&gt;

&lt;p&gt;&lt;a href=&quot;https://assuntonerd.com.br/&quot;&gt;Alessandro’s Blog&lt;/a&gt; covers the OpenCV 5.0.0 release. The major version requires C++17, drops the legacy C API and Python 2 support, and introduces new data types including bfloat16, uint32, uint64, and boolean matrices. Modules have been reorganized with features2d becoming features. New deep-learning-based local features include ALIKED, DISK, and LightGlue matcher.&lt;/p&gt;

&lt;h2 id=&quot;second-bugfix-update-for-plasma-67&quot;&gt;&lt;a href=&quot;https://www.kdeblog.com/segunda-actualizacion-de-plasma-6-7.html&quot;&gt;Second Bugfix Update for Plasma 6.7&lt;/a&gt;&lt;/h2&gt;

&lt;p&gt;The &lt;a href=&quot;https://www.kdeblog.com/&quot;&gt;KDE Blog&lt;/a&gt; announces the second bugfix release for Plasma 6.7, arriving a few weeks after the initial release. The update continues KDE’s regular maintenance cycle with stability improvements, better translations, and error resolution across the desktop environment.&lt;/p&gt;

&lt;h2 id=&quot;brain2qwerty-typing-with-the-brain&quot;&gt;&lt;a href=&quot;https://assuntonerd.com.br/2026/06/30/brain2qwerty-digitando-com-o-cerebro/&quot;&gt;Brain2Qwerty: Typing with the Brain&lt;/a&gt;&lt;/h2&gt;

&lt;p&gt;&lt;a href=&quot;https://assuntonerd.com.br/&quot;&gt;Alessandro’s Blog&lt;/a&gt; covers Meta AI Research’s Brain2Qwerty v2, a non-invasive brain-computer interface that decodes typed sentences from MEG and EEG signals. The model achieves up to 78% word-level accuracy on the best participant and over half of sentences were decoded with at most one word error. The post discusses the technology’s potential for communication aids and the ethical considerations around neural data privacy.&lt;/p&gt;

&lt;h2 id=&quot;building-a-local-offline-opensuse-assistant-for-gsoc&quot;&gt;&lt;a href=&quot;https://news.opensuse.org/2026/06/29/building-local-offline-opensuse-assistant/&quot;&gt;Building a Local, Offline openSUSE Assistant for GSoC&lt;/a&gt;&lt;/h2&gt;

&lt;p&gt;&lt;a href=&quot;https://news.opensuse.org/&quot;&gt;openSUSE News&lt;/a&gt; shares a GSoC midterm update on suse-assist, which combines a Small Language Model with retrieval-augmented generation over official openSUSE documentation. The assistant runs on Leap 16.0 in a BCI-based container built by OBS, benchmarks six GGUF models with Gemma 4 E4B as the default, and supports offline bundles with checksums for machines without internet access.&lt;/p&gt;

&lt;h2 id=&quot;kde-seeks-its-next-goals-submissions-open-to-shape-the-projects-future&quot;&gt;&lt;a href=&quot;https://www.kdeblog.com/kde-busca-sus-proximas-metas-se-abre-el-plazo-para-disenar-el-futuro-del-proyecto.html&quot;&gt;KDE Seeks Its Next Goals: Submissions Open to Shape the Project’s Future&lt;/a&gt;&lt;/h2&gt;

&lt;p&gt;The &lt;a href=&quot;https://www.kdeblog.com/&quot;&gt;KDE Blog&lt;/a&gt; reports that KDE e.V. has opened the goal-setting process for the project’s next development priorities. Following previous cycles focused on Wayland adoption, accessibility, and application development simplification, the community is now invited to propose new goals through a dedicated workspace. Proposals are accepted through August 8, with the final announcement at Akademy on September 19.&lt;/p&gt;

&lt;h2 id=&quot;whats-new-in-plasma-67-plasmoids&quot;&gt;&lt;a href=&quot;https://www.kdeblog.com/las-novedades-en-los-plasmoides-en-plasma-6-7.html&quot;&gt;What’s New in Plasma 6.7 Plasmoids&lt;/a&gt;&lt;/h2&gt;

&lt;p&gt;The &lt;a href=&quot;https://www.kdeblog.com/&quot;&gt;KDE Blog&lt;/a&gt; covers the new features in Plasma 6.7 plasmoids. Highlights include the ability to switch between light and dark modes directly from the Brightness and Color plasmoid, a new Background Applications entry in the system tray for better oversight of running services, and the addition of the Vietnamese lunar calendar for broader international support.&lt;/p&gt;

&lt;h2 id=&quot;opensuse-tumbleweed-review--weeks-25--26-of-2026&quot;&gt;&lt;a href=&quot;https://victorhckinthefreeworld.com/2026/06/27/opensuse-tumbleweed-revision-de-las-semanas-25-y-26-de-2026/&quot;&gt;openSUSE Tumbleweed Review – Weeks 25 &amp;amp; 26 of 2026&lt;/a&gt;&lt;/h2&gt;

&lt;p&gt;&lt;a href=&quot;https://victorhckinthefreeworld.com/&quot;&gt;Victorhck&lt;/a&gt; and &lt;a href=&quot;https://dominique.leuenberger.net/blog/2026/06/tumbleweed-review-of-the-weeks-2026-25-26/&quot;&gt;Dominique Leuenberger&lt;/a&gt; report on 11 snapshots published during a two-week period bridging the openSUSE Conference in Nuremberg. Key updates include KDE Plasma 6.7.0 and 6.7.1, KDE Frameworks 6.27.0, Linux kernel 7.0.12, Mesa 26.1.3, MariaDB 12.3.2, Mozilla Firefox 152.0.2, and GStreamer 1.28.4. Staging topics include Qemu 11.0.0 dropping 32-bit host support and Linux kernel 7.1 testing.&lt;/p&gt;

&lt;h2 id=&quot;bug-fixes-after-67--this-week-in-plasma&quot;&gt;&lt;a href=&quot;https://www.kdeblog.com/correccion-de-errores-tras-la-6-7-esta-semana-en-plasma.html&quot;&gt;Bug Fixes After 6.7 – This Week in Plasma&lt;/a&gt;&lt;/h2&gt;

&lt;p&gt;The &lt;a href=&quot;https://www.kdeblog.com/&quot;&gt;KDE Blog&lt;/a&gt; translates Nate Graham’s This Week in Plasma, covering the post-Plasma 6.7 bugfix sprint. Plasma 6.7.1 shipped with fixes for KWin crashes on NVIDIA GPUs, DisplayLink monitor support, and dual-GPU laptop display freezes. Plasma 6.7.2 addresses variable refresh rate crashes on multi-monitor setups.&lt;/p&gt;

&lt;h2 id=&quot;when-the-code-stays-clean-and-trust-collapses-anyway&quot;&gt;&lt;a href=&quot;https://news.opensuse.org/2026/06/26/when-code-stays-clear-turst-collapses-anyway/&quot;&gt;When the Code Stays Clean and Trust Collapses Anyway&lt;/a&gt;&lt;/h2&gt;

&lt;p&gt;&lt;a href=&quot;https://news.opensuse.org/&quot;&gt;openSUSE News&lt;/a&gt; publishes Hans de Raad’s keynote article from the openSUSE Conference on why Europe’s third way needs sovereign open-source assurance. The post examines the GSD project’s trust-state inversion, the xz backdoor, and how the Cyber Resilience Act turns sovereignty into an evidence problem. It argues that open-source assurance is no longer only about scanning code but about governing the chain of authority around it, and calls for funding maintainers as supply-chain risk reduction.&lt;/p&gt;

&lt;h2 id=&quot;germany-makes-odf-mandatory-across-its-public-administration&quot;&gt;&lt;a href=&quot;https://www.kdeblog.com/alemania-hace-obligatorio-usar-odf-en-toda-su-administracion-publica.html&quot;&gt;Germany Makes ODF Mandatory Across Its Public Administration&lt;/a&gt;&lt;/h2&gt;

&lt;p&gt;The &lt;a href=&quot;https://www.kdeblog.com/&quot;&gt;KDE Blog&lt;/a&gt; reports on Germany mandating the Open Document Format as the obligatory standard within its sovereign digital infrastructure framework, the Deutschland-Stack. Public administration documents must use ODF formats (.odt, .ods, .odp, .odg, .odb) instead of proprietary formats. The PDF/UA accessibility standard is also included. Florian Effenberger of The Document Foundation called it a confirmation that open formats are fundamental infrastructure for democratic and interoperable public administration.&lt;/p&gt;

&lt;p&gt;View more blogs or learn to publish your own on &lt;a href=&quot;https://planet.opensuse.org&quot;&gt;planet.opensuse.org&lt;/a&gt;.&lt;/p&gt;

&lt;meta name=&quot;openSUSE, Open Source, development, Linux, secure operating systems, open source, plasma, KDE, Frameworks, Tumbleweed, GSoC, OpenCV, ESP32, Brain2Qwerty, FSF, CRA, ODF, Plasma 6.7&quot; content=&quot;HTML,CSS,XML,JavaScript&quot; /&gt;

</content:encoded>
    </item>

    <item>
      <guid>https://news.opensuse.org/2026/07/01/tw-monthly-update-june/</guid>
      <title>Tumbleweed Monthly Update - June 2026</title>
      <pubDate>Wed, 01 Jul 2026 11:00:00 +0000</pubDate>
      <link>https://news.opensuse.org/2026/07/01/tw-monthly-update-june/</link>
      <author>admin@opensuse.org (Douglas DeMaio)</author>
      <enclosure url="https://news.opensuse.org/wp-content/uploads/2026/07/tw.png" length="16874" type="image/png" />
      <description>Contributors to openSUSE had a great time at the openSUSE Conference in June. Even as many of them gathered in Nuremberg to discuss how to drive development of the rolling release forward, software package updates for openSUSE Tumbleweed kept rolling out. June brought major version bumps across the stack with...</description>
      <content:encoded>&lt;p&gt;Contributors to openSUSE had a great time at the &lt;a href=&quot;https://events.opensuse.org/conferences/oSC26&quot;&gt;openSUSE Conference&lt;/a&gt; in June. Even as many of them gathered in Nuremberg to discuss how to drive development of the rolling release forward, software package updates for &lt;a href=&quot;https://get.opensuse.org/tumbleweed/&quot;&gt;openSUSE Tumbleweed&lt;/a&gt; kept rolling out.&lt;/p&gt;

&lt;p&gt;June brought major version bumps across the stack with &lt;a href=&quot;https://www.samba.org/&quot;&gt;Samba&lt;/a&gt; jumping to 4.24.3 carrying seven &lt;a href=&quot;https://en.wikipedia.org/wiki/Common_Vulnerabilities_and_Exposures&quot;&gt;Common Vulnerabilities and Exposures&lt;/a&gt; fixes, &lt;a href=&quot;https://github.com/mariadb&quot;&gt;MariaDB&lt;/a&gt; advancing from 11.8 to 12.3.2, and &lt;a href=&quot;https://flatpak.org/&quot;&gt;Flatpak&lt;/a&gt; reaching 1.18.0.&lt;/p&gt;

&lt;p&gt;&lt;a href=&quot;https://kde.org/announcements/gear/26.04.2/&quot;&gt;KDE Gear 26.04.2&lt;/a&gt; landed as the second bugfix release of the series, and &lt;a href=&quot;https://gstreamer.freedesktop.org/&quot;&gt;GStreamer&lt;/a&gt; progressed to 1.28.4 with security and playback fixes. &lt;a href=&quot;https://www.openssl.org/&quot;&gt;OpenSSL&lt;/a&gt; received a massive security update and both &lt;a href=&quot;https://webkitgtk.org/&quot;&gt;WebKitGTK&lt;/a&gt; and the &lt;a href=&quot;https://www.kernel.org/&quot;&gt;Linux kernel&lt;/a&gt; received extensive rounds of vulnerability fixes.&lt;/p&gt;

&lt;p&gt;The second half of June was headlined by &lt;a href=&quot;https://kde.org/announcements/plasma/6/6.7.0/&quot;&gt;KDE Plasma 6.7.0&lt;/a&gt; and &lt;a href=&quot;https://kde.org/announcements/frameworks/6/6.27.0/&quot;&gt;KDE Frameworks 6.27.0&lt;/a&gt;. &lt;a href=&quot;https://networkmanager.dev/&quot;&gt;NetworkManager&lt;/a&gt; advanced to 1.56.1 and &lt;a href=&quot;https://cryptography.io/&quot;&gt;python-cryptography&lt;/a&gt; reached 49.0.0 with post-quantum ML-DSA signing support. &lt;a href=&quot;https://www.freerdp.com/&quot;&gt;FreeRDP&lt;/a&gt; 3.27.1 raised the minimum TLS version to 1.2 while addressing multiple CVEs. &lt;a href=&quot;https://www.virtualbox.org/&quot;&gt;VirtualBox&lt;/a&gt; 7.2.10 added Linux kernel 7.1 support and Wayland clipboard sharing.&lt;/p&gt;

&lt;p&gt;As always, be sure to roll back using &lt;a href=&quot;https://github.com/openSUSE/snapper&quot;&gt;snapper&lt;/a&gt; if any issues arise.&lt;/p&gt;

&lt;p&gt;For more details on the change logs for the month, visit the &lt;a href=&quot;https://lists.opensuse.org/archives/list/factory@lists.opensuse.org/&quot;&gt;openSUSE Factory mailing list&lt;/a&gt;.&lt;/p&gt;

&lt;h2 id=&quot;new-features-and-enhancements&quot;&gt;New Features and Enhancements&lt;/h2&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.samba.org/&quot;&gt;Samba 4.24.3&lt;/a&gt;&lt;/strong&gt;: A major version bump from the 4.23 series brings a major security refresh with several CVE fixes. Notable changes include a fix for unauthenticated remote code execution in the AD DC, SAMR remote code execution, and group policy certificate enrollment without validation.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://flatpak.org/&quot;&gt;Flatpak 1.18.0&lt;/a&gt;&lt;/strong&gt;: This major update improves error handling and printed output of &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;flatpak-coredumpctl&lt;/code&gt;, adds support for the AMD vendor-specific compute interface (&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;/dev/kfd&lt;/code&gt;) via DRI device permissions, and improves startup time for fish shell integration. Ignoring system bus failures in parental controls check and replacing deprecated GTimeVal with &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;g_get_real_time()&lt;/code&gt; round out the release.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.gnupg.org/software/gpgme/&quot;&gt;GPGME 2.1.0&lt;/a&gt;&lt;/strong&gt;: This update introduces new flags &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;is_de_vs&lt;/code&gt; and &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;beta_compliance&lt;/code&gt; for encryption results, a new decryption flag &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;GPGME_DECRYPT_SESSION_HASH&lt;/code&gt;, and support for setting CMS signature attributes via &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;gpgme_sig_notation_add&lt;/code&gt;. A new context flag &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;export-filter&lt;/code&gt; is also added. Several locking and passphrase handling fixes are included, along with the companion &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;gpgmepp&lt;/code&gt; 2.1.0 and &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;qgpgme&lt;/code&gt; 2.1.0 updates.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://github.com/mariadb&quot;&gt;MariaDB 12.3.2&lt;/a&gt;&lt;/strong&gt;: A major version jump from 11.8.8 brings the database server to the 12.3 series. This release carries multiple security fixes alongside a changelog of improvements documented in the upstream release notes.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://kde.org/announcements/gear/26.04.2/&quot;&gt;KDE Gear 26.04.2&lt;/a&gt;&lt;/strong&gt;: &lt;a href=&quot;https://apps.kde.org/dolphin/&quot;&gt;Dolphin&lt;/a&gt; fixes a dangling pointer access in SettingsDataSource and a swapActiveView crash. &lt;a href=&quot;https://apps.kde.org/kate/&quot;&gt;Kate&lt;/a&gt; corrects working directory handling when invoking git and fixes urlinfo for relative files. &lt;a href=&quot;https://apps.kde.org/konsole/&quot;&gt;Konsole&lt;/a&gt; fixes a copy command causing unwanted scroll-to-bottom. &lt;a href=&quot;https://apps.kde.org/kitinerary/&quot;&gt;Kitinerary&lt;/a&gt; adds extractors for BDŽ (Bulgarian State Railways) PDF tickets and Condor PKPass. &lt;a href=&quot;https://apps.kde.org/korganizer/&quot;&gt;KOrganizer&lt;/a&gt; fixes recurring event start-end time display and &lt;a href=&quot;https://apps.kde.org/kleopatra/&quot;&gt;Kleopatra&lt;/a&gt; now requires GpgME 1.24.2 (at the beginning of the month in Tumbleweed updated to version 2.1.0).&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://gstreamer.freedesktop.org/&quot;&gt;GStreamer 1.28.4&lt;/a&gt;&lt;/strong&gt;: The &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;rtspsrc2&lt;/code&gt; element receives major feature expansion with support for SRTP, authentication, HTTP tunnelling, keep-alive, TLS validation, and latency configuration. Wavpack audio receives channel and channel-mask related fixes. Debug logging performance is improved, and memory leaks across caps allocation, buffer pools, and the GL upload path are resolved. The &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;d3d12decoder&lt;/code&gt; gets a fix for Qualcomm GPUs on ARM64 Windows.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;http://www.graphicsmagick.org/&quot;&gt;GraphicsMagick 1.3.47&lt;/a&gt;&lt;/strong&gt;: DPX subsampling validation is corrected to avoid divide-by-zero. The JNG writer properly handles NULL returns from &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;ImageToBlob()&lt;/code&gt;, and the MNG writer enforces a 256-color palette limit. The PS/PS2/PS3 coders enforce dimension limits to prevent Ghostscript-based denial-of-service. SVG gains validations for element id syntax and rejects attribute values with single quotes. The XCF reader reports errors for layerless images and fixes two unsigned integer overflow cases.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://fwupd.org/&quot;&gt;fwupd 2.1.4 &amp;amp; 2.1.5&lt;/a&gt;&lt;/strong&gt;: The firmware update daemon received two updates during June. Version 2.1.4 adds support for Compal BIOS version format, NixOS quickstart, encrypted swap detection below device-mapper, and removes the flashrom plugin. Dozens of bounds checks and validation fixes are included across Dell dock, Novatek, Goodix MoC, Synaptics RMI, CCGX DMC, and other device updaters. The 2.1.5 follow-up fixes a msgpack regression for &lt;a href=&quot;https://www.huddly.com/conference-cameras/&quot;&gt;Huddly cameras&lt;/a&gt;, adds Elan touchscreen support, and expands the netlink socket buffer to prevent packet loss during event floods.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.libsdl.org/&quot;&gt;SDL3 3.4.10&lt;/a&gt;&lt;/strong&gt;: This update adds depth texture array support in the GPU API, GameInput v3 controller sensor support, rumble support for the new Steam Controller, and GameCube rumble support when the adapter is in PC mode. Several new controllers are supported including the GameSir Super Nova and PDP Afterglow Wave Wireless. The X11 Synchronization Extension is disabled by default and can be re-enabled via &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;SDL_HINT_VIDEO_X11_ENABLE_XSYNC_EXT&lt;/code&gt;.&lt;/p&gt;

&lt;h2 id=&quot;key-package-updates&quot;&gt;Key Package Updates&lt;/h2&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.kernel.org/&quot;&gt;Linux kernel&lt;/a&gt; 7.0.11 &amp;amp; 7.0.12&lt;/strong&gt;: The kernel received two updates during June with a heavy security focus. Version 7.0.11 carried an extensive set of CVE fixes spanning BPF (end-of-list detection in cgroup storage, negative CO-RE accessor indices), netfilter (divide-by-zero in nfnetlink_osf, IEEE1394 ARP payload handling, arp_tables), ALSA USB audio UAC2 rate parsing, and more. Version 7.0.12 added fixes for NFC LLCP use-after-free, xfrm underflow, netfilter ebtables OOB read, nf_tables dst corruption, tun/tap XDP page handling, ethtool RSS context handling, ALSA HDA cs35l56 and OSS setup UAF, and HSR OOB access in supervision frame handling.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://webkitgtk.org/&quot;&gt;WebKitGTK&lt;/a&gt; 2.52.4&lt;/strong&gt;: A security-focused update fixing 16 CVEs in the web rendering engine. The release adds support for half-width fonts, improves content filter compilation, improves handling of out-of-disk-space conditions in the NetworkProcess cache, fixes scrollbar painting during width changes, fixes playback of certain YouTube videos with low frame rates, and addresses several crashes and rendering issues.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://imagemagick.org/&quot;&gt;ImageMagick&lt;/a&gt; 7.1.2.25&lt;/strong&gt;: A security-focused update rejecting malformed HDR, PGX, RLA, FITS, SGI, and DDS files with invalid dimensions. Polynomial distortion argument count validation is added, and an out-of-bounds read of GPS rationals in &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;GetEXIFProperty&lt;/code&gt; is fixed.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.mesa3d.org/&quot;&gt;Mesa&lt;/a&gt; 26.1.2&lt;/strong&gt;: The update resolves graphical corruption on older Intel integrated GPUs (e.g., i5-2400) introduced in 26.1.0 and fixes a crash in ANV’s ASTC texture handling on Xe3 when floating-point exceptions are enabled. Vulkan drivers see important corrections: RADV adds workarounds for &lt;a href=&quot;https://store.steampowered.com/app/2483190/Forza_Horizon_6/&quot;&gt;Forza Horizon 6&lt;/a&gt; and &lt;a href=&quot;https://store.steampowered.com/agecheck/app/3321460/&quot;&gt;Crimson Desert&lt;/a&gt;, ANV restores Android external format compatibility in debug builds, and PanVK/Turnip improve memory reporting and depth state handling. More details are available in the &lt;a href=&quot;https://docs.mesa3d.org/relnotes/26.1.2&quot;&gt;Mesa 26.1.2 release notes&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://gitlab.gnome.org/GNOME/mutter&quot;&gt;mutter&lt;/a&gt; 50.2&lt;/strong&gt;: Fixes size increases when quickly unmaximizing windows by drag, cursor position hint for Xwayland with scaling, fullscreening of edge-tiled windows, tablet tool cursor hotspot scaling, alt-tab with sloppy/mouse focus, and broken switch-monitor mapping on stylus buttons. Support for version 2 of the &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;text_input_v3&lt;/code&gt; protocol is implemented, and DND with tablets now works across surfaces.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://flatpak.org/&quot;&gt;flatpak&lt;/a&gt; 1.18.0&lt;/strong&gt;: This update adds support for the AMD compute interface (&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;/dev/kfd&lt;/code&gt;) via the DRI device permission, enabling GPU compute access for Flatpak applications on AMD hardware. The output of &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;flatpak update&lt;/code&gt; is improved with clearer failure causes, and &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;flatpak-coredumpctl&lt;/code&gt; gains better error handling. Fish shell integration startup time is improved. Bug fixes include ignoring system bus failures in parental controls checks and replacing deprecated &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;GTimeVal&lt;/code&gt; usage.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://github.com/OpenPrinting/cups-filters&quot;&gt;cups-filters&lt;/a&gt;&lt;/strong&gt;: The &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;cups-browsed&lt;/code&gt; service is now provided as a separate sub-package, allowing users to uninstall it to avoid the security risk of automatic print queue creation from any DNS-SD announcement on the local network.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://github.com/openSUSE/libzypp&quot;&gt;libzypp&lt;/a&gt; 17.38.13&lt;/strong&gt;: Two security fixes in the package management library. A &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;path=&lt;/code&gt; entry in &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;.repo&lt;/code&gt; files must not refer to a location outside the repo (CVE-2026-44942), and repo &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;keyhint&lt;/code&gt; must denote a filename not a path (CVE-2026-44941).&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://github.com/openSUSE/wicked&quot;&gt;wicked&lt;/a&gt; 0.6.79&lt;/strong&gt;: Fixes an indirect remote shell command injection via unsanitized DHCP strings and leaseinfo dump (CVE-2026-44932). Single-quote escaping is added to leaseinfo dump output, and &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;posix-tz-dbname&lt;/code&gt; processing now permits only valid characters per RFC 4833.&lt;/p&gt;

&lt;h2 id=&quot;security-updates&quot;&gt;Security Updates&lt;/h2&gt;

&lt;h3 id=&quot;openssl-3&quot;&gt;&lt;strong&gt;&lt;a href=&quot;https://www.openssl.org/&quot;&gt;OpenSSL 3&lt;/a&gt;&lt;/strong&gt;:&lt;/h3&gt;

&lt;ul&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-45447.html&quot;&gt;CVE-2026-45447&lt;/a&gt;&lt;/strong&gt;: Fixes a heap use-after-free in &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;PKCS7_verify()&lt;/code&gt; that could lead to memory corruption.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-45446.html&quot;&gt;CVE-2026-45446&lt;/a&gt;&lt;/strong&gt;: Addresses incorrect tag processing for empty messages in AES-GCM-SIV and AES-SIV modes.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-42770.html&quot;&gt;CVE-2026-42770&lt;/a&gt;&lt;/strong&gt;: Resolves FFC-DH peer validation using attacker-supplied &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;q&lt;/code&gt;, potentially weakening key exchange.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-45445.html&quot;&gt;CVE-2026-45445&lt;/a&gt;&lt;/strong&gt;: Fixes AES-OCB IV being ignored on the EVP_Cipher() path.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-42767.html&quot;&gt;CVE-2026-42767&lt;/a&gt;&lt;/strong&gt;: Addresses a NULL pointer dereference in CRMF EncryptedValue decryption.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-42768.html&quot;&gt;CVE-2026-42768&lt;/a&gt;&lt;/strong&gt;: Resolves a multi-recipient Bleichenbacher oracle in &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;CMS_decrypt()&lt;/code&gt; and &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;PKCS7_decrypt()&lt;/code&gt;.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-42769.html&quot;&gt;CVE-2026-42769&lt;/a&gt;&lt;/strong&gt;: Fixes trust-anchor substitution via cert/issuer typo in CMP &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;rootCaKeyUpdate&lt;/code&gt;.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-42766.html&quot;&gt;CVE-2026-42766&lt;/a&gt;&lt;/strong&gt;: Addresses a possible NULL dereference in password-based CMS decryption.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-34183.html&quot;&gt;CVE-2026-34183&lt;/a&gt;&lt;/strong&gt;: Resolves unbounded memory growth in the QUIC PATH_CHALLENGE handler.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-42764.html&quot;&gt;CVE-2026-42764&lt;/a&gt;&lt;/strong&gt;: Fixes a NULL pointer dereference in QUIC server initial packet handling.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-34182.html&quot;&gt;CVE-2026-34182&lt;/a&gt;&lt;/strong&gt;: Addresses CMS AuthEnvelopedData processing that could accept forged messages.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-9076.html&quot;&gt;CVE-2026-9076&lt;/a&gt;&lt;/strong&gt;: Fixes an out-of-bounds read in CMS password-based decryption.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-7383.html&quot;&gt;CVE-2026-7383&lt;/a&gt;&lt;/strong&gt;: Resolves a possible heap buffer overflow in ASN.1 multibyte string conversion.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-34180.html&quot;&gt;CVE-2026-34180&lt;/a&gt;&lt;/strong&gt;: Addresses a heap buffer over-read in ASN.1 content parsing.&lt;/p&gt;
  &lt;/li&gt;
&lt;/ul&gt;

&lt;h3 id=&quot;linux-kernel-7011&quot;&gt;&lt;strong&gt;&lt;a href=&quot;https://www.kernel.org/&quot;&gt;Linux kernel&lt;/a&gt; 7.0.11&lt;/strong&gt;:&lt;/h3&gt;

&lt;ul&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-45838.html&quot;&gt;CVE-2026-45838&lt;/a&gt;&lt;/strong&gt;: Fixes end-of-list detection in BPF cgroup storage.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-45839.html&quot;&gt;CVE-2026-45839&lt;/a&gt;&lt;/strong&gt;: Addresses negative CO-RE accessor indices in BPF.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-45840.html&quot;&gt;CVE-2026-45840&lt;/a&gt;&lt;/strong&gt;: Resolves an upcall PID array size issue in &lt;a href=&quot;https://www.openvswitch.org/&quot;&gt;openvswitch&lt;/a&gt;.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-45841.html&quot;&gt;CVE-2026-45841&lt;/a&gt;&lt;/strong&gt;: Fixes a divide-by-zero in netfilter nfnetlink_osf.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-45842.html&quot;&gt;CVE-2026-45842&lt;/a&gt;&lt;/strong&gt;: Addresses VJ receive packet rejection on SLIP instances.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-45843.html&quot;&gt;CVE-2026-45843&lt;/a&gt;&lt;/strong&gt;: Resolves compressed decode bounds in SLIP.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-46242.html&quot;&gt;CVE-2026-46242&lt;/a&gt;&lt;/strong&gt;: Fixes an eventpoll struct issue in &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;ep_remove&lt;/code&gt;.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-45844.html&quot;&gt;CVE-2026-45844&lt;/a&gt;&lt;/strong&gt;: Addresses IEEE1394 ARP payload handling in netfilter arp_tables.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-45845.html&quot;&gt;CVE-2026-45845&lt;/a&gt;&lt;/strong&gt;: Fixes a NULL pointer dereference in net/sched taprio.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-45846.html&quot;&gt;CVE-2026-45846&lt;/a&gt;&lt;/strong&gt;: Resolves a NULL pointer dereference in bareudp.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-43494.html&quot;&gt;CVE-2026-43494&lt;/a&gt;&lt;/strong&gt;: Fixes zerocopy page pin reset in net/rds.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-46300.html&quot;&gt;CVE-2026-46300&lt;/a&gt;&lt;/strong&gt;: Addresses shared frag marker preservation in skbuff.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-43503.html&quot;&gt;CVE-2026-43503&lt;/a&gt;&lt;/strong&gt;: Resolves shared frag marker propagation through skbuff.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-46243.html&quot;&gt;CVE-2026-46243&lt;/a&gt;&lt;/strong&gt;: Fixes SMB client rejection of userspace cifs.spnego descriptions.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-46018.html&quot;&gt;CVE-2026-46018&lt;/a&gt;&lt;/strong&gt;: Addresses ALSA USB audio UAC2 rate parsing at MAX_NR_RATES.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-45993.html&quot;&gt;CVE-2026-45993&lt;/a&gt;&lt;/strong&gt;: Resolves a LoongArch spectre boundary for syscall dispatch.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-46006.html&quot;&gt;CVE-2026-46006&lt;/a&gt;&lt;/strong&gt;: Fixes a u32 overflow in Nouveau pushbuf relocation.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-46041.html&quot;&gt;CVE-2026-46041&lt;/a&gt;&lt;/strong&gt;: Addresses a sleep-in-atomic context in greybus gb-beagleplay.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-46022.html&quot;&gt;CVE-2026-46022&lt;/a&gt;&lt;/strong&gt;: Fixes an OOB MMIO read in ibmasm.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-45994.html&quot;&gt;CVE-2026-45994&lt;/a&gt;&lt;/strong&gt;: Addresses OOB reads in ibmasm command file write.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-46064.html&quot;&gt;CVE-2026-46064&lt;/a&gt;&lt;/strong&gt;: Resolves a heap over-read in ibmasm I2O message send.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-46100.html&quot;&gt;CVE-2026-46100&lt;/a&gt;&lt;/strong&gt;: Fixes an AFS mmap_prepare revert.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-46017.html&quot;&gt;CVE-2026-46017&lt;/a&gt;&lt;/strong&gt;: Addresses deferred split queue races during migration in mm.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-46080.html&quot;&gt;CVE-2026-46080&lt;/a&gt;&lt;/strong&gt;: Fixes transaction splits in OCFS2 DIO completion.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-46097.html&quot;&gt;CVE-2026-46097&lt;/a&gt;&lt;/strong&gt;: Addresses a use-after-free in edt-ft5x06 input debugfs.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-46089.html&quot;&gt;CVE-2026-46089&lt;/a&gt;&lt;/strong&gt;: Fixes partial discard endio handling in zram.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-46092.html&quot;&gt;CVE-2026-46092&lt;/a&gt;&lt;/strong&gt;: Addresses a PCI upstream bridge existence check in rtw88 WiFi driver.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-46069.html&quot;&gt;CVE-2026-46069&lt;/a&gt;&lt;/strong&gt;: Fixes a use-after-free in mwifiex adapter.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-46036.html&quot;&gt;CVE-2026-46036&lt;/a&gt;&lt;/strong&gt;: Addresses VFIO CDX serialization of device IRQ setting.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-46034.html&quot;&gt;CVE-2026-46034&lt;/a&gt;&lt;/strong&gt;: Resolves a NULL pointer dereference in VFIO CDX interrupt handling.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-46021.html&quot;&gt;CVE-2026-46021&lt;/a&gt;&lt;/strong&gt;: Fixes thermal zone governor cleanup.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-45996.html&quot;&gt;CVE-2026-45996&lt;/a&gt;&lt;/strong&gt;: Addresses a use-after-free on SPI IMX unbind.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-46074.html&quot;&gt;CVE-2026-46074&lt;/a&gt;&lt;/strong&gt;: Fixes memory leaks on SPI CH341 probe failures.&lt;/p&gt;
  &lt;/li&gt;
&lt;/ul&gt;

&lt;h3 id=&quot;webkitgtk-2524&quot;&gt;&lt;strong&gt;&lt;a href=&quot;https://webkitgtk.org/&quot;&gt;WebKitGTK&lt;/a&gt; 2.52.4&lt;/strong&gt;:&lt;/h3&gt;

&lt;ul&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-28847.html&quot;&gt;CVE-2026-28847&lt;/a&gt;&lt;/strong&gt;: Fixes a WebKit memory handling issue that could cause an unexpected crash.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-28883.html&quot;&gt;CVE-2026-28883&lt;/a&gt;&lt;/strong&gt;: Addresses a flaw where processing malicious web content could lead to memory corruption.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-28901.html&quot;&gt;CVE-2026-28901&lt;/a&gt;&lt;/strong&gt;: Resolves a WebKit vulnerability where processing malicious web content could lead to an unexpected crash.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-28902.html&quot;&gt;CVE-2026-28902&lt;/a&gt;&lt;/strong&gt;: Fixes a WebKit issue where processing malicious web content could lead to memory corruption.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-28903.html&quot;&gt;CVE-2026-28903&lt;/a&gt;&lt;/strong&gt;: Addresses a flaw where visiting a malicious website could lead to unexpected behavior.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-28904.html&quot;&gt;CVE-2026-28904&lt;/a&gt;&lt;/strong&gt;: Resolves a WebKit memory corruption issue when processing malicious web content.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-28905.html&quot;&gt;CVE-2026-28905&lt;/a&gt;&lt;/strong&gt;: Fixes a logic issue where a malicious website could access restricted resources.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-28907.html&quot;&gt;CVE-2026-28907&lt;/a&gt;&lt;/strong&gt;: Addresses a WebKit vulnerability that could cause an unexpected crash.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-28942.html&quot;&gt;CVE-2026-28942&lt;/a&gt;&lt;/strong&gt;: Resolves a cross-origin issue in WebKit’s Navigation API.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-28946.html&quot;&gt;CVE-2026-28946&lt;/a&gt;&lt;/strong&gt;: Fixes a WebKit memory handling issue that could lead to an unexpected process crash.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-28947.html&quot;&gt;CVE-2026-28947&lt;/a&gt;&lt;/strong&gt;: Addresses a WebKit flaw where processing malicious web content could bypass the Same Origin Policy.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-28953.html&quot;&gt;CVE-2026-28953&lt;/a&gt;&lt;/strong&gt;: Resolves a logic issue where a malicious website could access script message handlers intended for other origins.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-28955.html&quot;&gt;CVE-2026-28955&lt;/a&gt;&lt;/strong&gt;: Fixes a WebKit memory handling issue that could cause an unexpected process crash.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-28958.html&quot;&gt;CVE-2026-28958&lt;/a&gt;&lt;/strong&gt;: Addresses an authorization flaw where a maliciously crafted webpage could fingerprint the user.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-43658.html&quot;&gt;CVE-2026-43658&lt;/a&gt;&lt;/strong&gt;: Resolves a WebKit sandbox issue where restricted content could be processed outside the sandbox.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-43660.html&quot;&gt;CVE-2026-43660&lt;/a&gt;&lt;/strong&gt;: Fixes a logic flaw where visiting a malicious website could lead to a cross-site scripting attack.&lt;/p&gt;
  &lt;/li&gt;
&lt;/ul&gt;

&lt;h3 id=&quot;samba-4243&quot;&gt;&lt;strong&gt;&lt;a href=&quot;https://www.samba.org/&quot;&gt;Samba&lt;/a&gt; 4.24.3&lt;/strong&gt;:&lt;/h3&gt;

&lt;ul&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-4480.html&quot;&gt;CVE-2026-4480&lt;/a&gt;&lt;/strong&gt;: Fixes unauthenticated remote code execution in the AD DC.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-4408.html&quot;&gt;CVE-2026-4408&lt;/a&gt;&lt;/strong&gt;: Addresses remote code execution in the SAMR protocol.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-3238.html&quot;&gt;CVE-2026-3238&lt;/a&gt;&lt;/strong&gt;: Resolves an unauthenticated UDP packet crash in the AD DC NBT server.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-3012.html&quot;&gt;CVE-2026-3012&lt;/a&gt;&lt;/strong&gt;: Fixes group policy certificate enrollment using HTTP without validation.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-1933.html&quot;&gt;CVE-2026-1933&lt;/a&gt;&lt;/strong&gt;: Addresses a missing access check on reparse point operations.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-2340.html&quot;&gt;CVE-2026-2340&lt;/a&gt;&lt;/strong&gt;: Resolves a vfs_worm not blocking directory modification.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-40170.html&quot;&gt;CVE-2026-40170&lt;/a&gt;&lt;/strong&gt;: Addresses a third-party ngtcp2 update requirement.&lt;/p&gt;
  &lt;/li&gt;
&lt;/ul&gt;

&lt;h3 id=&quot;openexr-3412&quot;&gt;&lt;strong&gt;&lt;a href=&quot;https://openexr.com/&quot;&gt;OpenEXR&lt;/a&gt; 3.4.12&lt;/strong&gt;:&lt;/h3&gt;

&lt;ul&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-45696.html&quot;&gt;CVE-2026-45696&lt;/a&gt;&lt;/strong&gt;: Fixes a heap-buffer-overflow READ via codestream/channel width mismatch in HTJ2K decode.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-44663.html&quot;&gt;CVE-2026-44663&lt;/a&gt;&lt;/strong&gt;: Addresses an integer overflow in the HTJ2K decoder leading to heap-buffer-overflow.&lt;/p&gt;
  &lt;/li&gt;
&lt;/ul&gt;

&lt;h3 id=&quot;graphicsmagick-1347&quot;&gt;&lt;strong&gt;&lt;a href=&quot;http://www.graphicsmagick.org/&quot;&gt;GraphicsMagick&lt;/a&gt; 1.3.47&lt;/strong&gt;:&lt;/h3&gt;

&lt;ul&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-25799.html&quot;&gt;CVE-2026-25799&lt;/a&gt;&lt;/strong&gt;: Fixes YUV sampling-factor argument validation to prevent potential security issues.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-26284.html&quot;&gt;CVE-2026-26284&lt;/a&gt;&lt;/strong&gt;: Fixes a security vulnerability in GraphicsMagick image processing.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-28690.html&quot;&gt;CVE-2026-28690&lt;/a&gt;&lt;/strong&gt;: Addresses MNG writer enforcing a 256-color palette limit to prevent excessive memory usage.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-30883.html&quot;&gt;CVE-2026-30883&lt;/a&gt;&lt;/strong&gt;: Fixes detection and reporting of excessively large profiles in the PNG writer.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-33535.html&quot;&gt;CVE-2026-33535&lt;/a&gt;&lt;/strong&gt;: Addresses a static buffer overflow in MagickXImageWindowCommand when a numeric key is held depressed.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-42050.html&quot;&gt;CVE-2026-42050&lt;/a&gt;&lt;/strong&gt;: Fixes an off-by-one error in GraphicsMagick.&lt;/p&gt;
  &lt;/li&gt;
&lt;/ul&gt;

&lt;h3 id=&quot;mariadb-1188&quot;&gt;&lt;strong&gt;&lt;a href=&quot;https://github.com/mariadb&quot;&gt;MariaDB&lt;/a&gt; 11.8.8&lt;/strong&gt;:&lt;/h3&gt;

&lt;ul&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-49261.html&quot;&gt;CVE-2026-49261&lt;/a&gt;&lt;/strong&gt;: Fixes a security vulnerability in the MariaDB server.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-48165.html&quot;&gt;CVE-2026-48165&lt;/a&gt;&lt;/strong&gt;: Addresses a security vulnerability in MariaDB.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-48163.html&quot;&gt;CVE-2026-48163&lt;/a&gt;&lt;/strong&gt;: Resolves a security vulnerability in MariaDB.&lt;/p&gt;
  &lt;/li&gt;
&lt;/ul&gt;

&lt;h3 id=&quot;python-tornado6-657&quot;&gt;&lt;strong&gt;&lt;a href=&quot;https://pypi.org/project/tornado/&quot;&gt;python-tornado6&lt;/a&gt; 6.5.7&lt;/strong&gt;:&lt;/h3&gt;

&lt;ul&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-49853.html&quot;&gt;CVE-2026-49853&lt;/a&gt;&lt;/strong&gt;: Fixes credentials and cookies not being stripped when following redirects to a different origin.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-49855.html&quot;&gt;CVE-2026-49855&lt;/a&gt;&lt;/strong&gt;: Addresses a denial-of-service via large compressed responses bypassing &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;max_body_size&lt;/code&gt;.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-49854.html&quot;&gt;CVE-2026-49854&lt;/a&gt;&lt;/strong&gt;: Resolves an out-of-bounds read of up to three bytes past an input array in the C extension.&lt;/p&gt;
  &lt;/li&gt;
&lt;/ul&gt;

&lt;h3 id=&quot;7-zip-2601&quot;&gt;&lt;strong&gt;&lt;a href=&quot;https://7-zip.org/&quot;&gt;7-Zip&lt;/a&gt; 26.01&lt;/strong&gt;:&lt;/h3&gt;

&lt;ul&gt;
  &lt;li&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-48095.html&quot;&gt;CVE-2026-48095&lt;/a&gt;&lt;/strong&gt;: Fixes a heap buffer write overflow that could be triggered by crafted archives.&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 id=&quot;sshfs-376&quot;&gt;&lt;strong&gt;&lt;a href=&quot;https://github.com/libfuse/sshfs&quot;&gt;sshfs&lt;/a&gt; 3.7.6&lt;/strong&gt;:&lt;/h3&gt;

&lt;ul&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-47187.html&quot;&gt;CVE-2026-47187&lt;/a&gt;&lt;/strong&gt;: Fixes a symlink escape vulnerability where a rogue SFTP server could read or write local files.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-48711.html&quot;&gt;CVE-2026-48711&lt;/a&gt;&lt;/strong&gt;: Addresses an argument injection vulnerability in SSH command handling.&lt;/p&gt;
  &lt;/li&gt;
&lt;/ul&gt;

&lt;h3 id=&quot;php8-857&quot;&gt;&lt;strong&gt;&lt;a href=&quot;https://www.php.net/&quot;&gt;php8&lt;/a&gt; 8.5.7&lt;/strong&gt;:&lt;/h3&gt;

&lt;ul&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-44927.html&quot;&gt;CVE-2026-44927&lt;/a&gt;&lt;/strong&gt;: Fixes pointer difference truncation to int in uriparser that could lead to incorrect URI handling.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-44928.html&quot;&gt;CVE-2026-44928&lt;/a&gt;&lt;/strong&gt;: Addresses a flaw where the &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;EqualsUri&lt;/code&gt; function could misclassify two unequal URIs as equal.&lt;/p&gt;
  &lt;/li&gt;
&lt;/ul&gt;

&lt;h3 id=&quot;libzypp-173813&quot;&gt;&lt;strong&gt;&lt;a href=&quot;https://github.com/openSUSE/libzypp&quot;&gt;libzypp&lt;/a&gt; 17.38.13&lt;/strong&gt;:&lt;/h3&gt;

&lt;ul&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-44942.html&quot;&gt;CVE-2026-44942&lt;/a&gt;&lt;/strong&gt;: Fixes a &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;path=&lt;/code&gt; entry in &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;.repo&lt;/code&gt; files that could refer to locations outside the repository base.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-44941.html&quot;&gt;CVE-2026-44941&lt;/a&gt;&lt;/strong&gt;: Addresses a repo &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;keyhint&lt;/code&gt; entry that could specify a path instead of a filename.&lt;/p&gt;
  &lt;/li&gt;
&lt;/ul&gt;

&lt;h3 id=&quot;wicked-0679&quot;&gt;&lt;strong&gt;&lt;a href=&quot;https://github.com/openSUSE/wicked&quot;&gt;wicked&lt;/a&gt; 0.6.79&lt;/strong&gt;:&lt;/h3&gt;

&lt;ul&gt;
  &lt;li&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-44932.html&quot;&gt;CVE-2026-44932&lt;/a&gt;&lt;/strong&gt;: Fixes an indirect remote shell command injection via unsanitized DHCP strings and leaseinfo dump.&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 id=&quot;perl-cpanel-json-xs-441&quot;&gt;&lt;strong&gt;&lt;a href=&quot;https://metacpan.org/pod/Cpanel::JSON::XS&quot;&gt;perl-Cpanel-JSON-XS&lt;/a&gt; 4.41&lt;/strong&gt;:&lt;/h3&gt;

&lt;ul&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-9516.html&quot;&gt;CVE-2026-9516&lt;/a&gt;&lt;/strong&gt;: Fixes a BOM-shift PV-corruption that could cause a SIGABRT.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-9334.html&quot;&gt;CVE-2026-9334&lt;/a&gt;&lt;/strong&gt;: Addresses a type confusion in &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;dupkeys_as_arrayref&lt;/code&gt; handling.&lt;/p&gt;
  &lt;/li&gt;
&lt;/ul&gt;

&lt;h3 id=&quot;openssh&quot;&gt;&lt;strong&gt;&lt;a href=&quot;https://www.openssh.com/&quot;&gt;openssh&lt;/a&gt;&lt;/strong&gt;:&lt;/h3&gt;

&lt;ul&gt;
  &lt;li&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-3497.html&quot;&gt;CVE-2026-3497&lt;/a&gt;&lt;/strong&gt;: Fixes a possible information disclosure or denial of service due to uninitialized variables in GSSAPI key exchange patches.&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 id=&quot;python-pip-2612&quot;&gt;&lt;strong&gt;&lt;a href=&quot;https://pip.pypa.io/&quot;&gt;python-pip&lt;/a&gt; 26.1.2&lt;/strong&gt;:&lt;/h3&gt;

&lt;ul&gt;
  &lt;li&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-8643.html&quot;&gt;CVE-2026-8643&lt;/a&gt;&lt;/strong&gt;: Fixes &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;console_scripts&lt;/code&gt; and &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;gui_scripts&lt;/code&gt; entry points whose name would install a script outside the scripts directory.&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 id=&quot;opensc&quot;&gt;&lt;strong&gt;&lt;a href=&quot;https://github.com/OpenSC/OpenSC&quot;&gt;OpenSC&lt;/a&gt;&lt;/strong&gt;:&lt;/h3&gt;

&lt;ul&gt;
  &lt;li&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-10275.html&quot;&gt;CVE-2026-10275&lt;/a&gt;&lt;/strong&gt;: Fixes a global buffer overflow during key pair generation tests due to missing input validation.&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 id=&quot;python-m2crypto-0480&quot;&gt;&lt;strong&gt;&lt;a href=&quot;https://gitlab.com/m2crypto/m2crypto&quot;&gt;python-M2Crypto&lt;/a&gt; 0.48.0&lt;/strong&gt;:&lt;/h3&gt;

&lt;ul&gt;
  &lt;li&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-0672.html&quot;&gt;CVE-2026-0672&lt;/a&gt;&lt;/strong&gt;: Fixes authcookie handling of CookieError from Python 3.13.12+ to prevent potential security issues.&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 id=&quot;freeipmi-1618&quot;&gt;&lt;strong&gt;&lt;a href=&quot;https://www.gnu.org/software/freeipmi/&quot;&gt;freeipmi&lt;/a&gt; 1.6.18&lt;/strong&gt;:&lt;/h3&gt;

&lt;ul&gt;
  &lt;li&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-50031.html&quot;&gt;CVE-2026-50031&lt;/a&gt;&lt;/strong&gt;: Fixes potential stack corruption in Dell and Fujitsu IPMI OEM commands and a potential buffer overflow in Fujitsu SEL entry handling.&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 id=&quot;graphite2-1315&quot;&gt;&lt;strong&gt;&lt;a href=&quot;https://github.com/silnrsi/graphite&quot;&gt;graphite2&lt;/a&gt; 1.3.15&lt;/strong&gt;:&lt;/h3&gt;

&lt;ul&gt;
  &lt;li&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-50593.html&quot;&gt;CVE-2026-50593&lt;/a&gt;&lt;/strong&gt;: Fixes a security vulnerability in the graphite font shaping library.&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 id=&quot;ldns-192&quot;&gt;&lt;strong&gt;&lt;a href=&quot;https://nlnetlabs.nl/projects/ldns/about/&quot;&gt;ldns&lt;/a&gt; 1.9.2&lt;/strong&gt;:&lt;/h3&gt;

&lt;ul&gt;
  &lt;li&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-10846.html&quot;&gt;CVE-2026-10846&lt;/a&gt;&lt;/strong&gt;: Fixes insufficient verification that DNS responses belong to a query, enabling potential cache poisoning.&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 id=&quot;glib-networking&quot;&gt;&lt;strong&gt;&lt;a href=&quot;https://gitlab.gnome.org/GNOME/glib-networking&quot;&gt;glib-networking&lt;/a&gt;&lt;/strong&gt;:&lt;/h3&gt;

&lt;ul&gt;
  &lt;li&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-10028.html&quot;&gt;CVE-2026-10028&lt;/a&gt;&lt;/strong&gt;: Fixes a cycle detection issue when setting the issuer property in the TLS certificate chain.&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 id=&quot;perl-gd-286&quot;&gt;&lt;strong&gt;&lt;a href=&quot;https://metacpan.org/pod/GD&quot;&gt;perl-GD&lt;/a&gt; 2.86&lt;/strong&gt;:&lt;/h3&gt;

&lt;ul&gt;
  &lt;li&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-11526.html&quot;&gt;CVE-2026-11526&lt;/a&gt;&lt;/strong&gt;: Fixes a command injection via 2-arg &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;open()&lt;/code&gt; in &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;_make_filehandle&lt;/code&gt;.&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 id=&quot;perl-html-parser-385&quot;&gt;&lt;strong&gt;&lt;a href=&quot;https://metacpan.org/pod/HTML::Parser&quot;&gt;perl-HTML-Parser&lt;/a&gt; 3.85&lt;/strong&gt;:&lt;/h3&gt;

&lt;ul&gt;
  &lt;li&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-8829.html&quot;&gt;CVE-2026-8829&lt;/a&gt;&lt;/strong&gt;: Fixes a heap-use-after-free in &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;_decode_entities&lt;/code&gt;.&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 id=&quot;djvulibre-3530&quot;&gt;&lt;strong&gt;&lt;a href=&quot;https://djvu.sourceforge.net/&quot;&gt;djvulibre&lt;/a&gt; 3.5.30&lt;/strong&gt;:&lt;/h3&gt;

&lt;ul&gt;
  &lt;li&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2021-46312.html&quot;&gt;CVE-2021-46312&lt;/a&gt;&lt;/strong&gt;: Fixes a security vulnerability in DjVu file processing.&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 id=&quot;rav1e&quot;&gt;&lt;strong&gt;&lt;a href=&quot;https://github.com/xiph/rav1e&quot;&gt;rav1e&lt;/a&gt;&lt;/strong&gt;:&lt;/h3&gt;

&lt;ul&gt;
  &lt;li&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2025-58160.html&quot;&gt;CVE-2025-58160&lt;/a&gt;&lt;/strong&gt;: Fixes a security vulnerability in Rust AV1 encoder dependencies.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Users are advised to update to the latest versions to mitigate these vulnerabilities.&lt;/p&gt;

&lt;h2 id=&quot;conclusion&quot;&gt;Conclusion&lt;/h2&gt;

&lt;p&gt;June came with some heavy security hardening across &lt;a href=&quot;https://get.opensuse.org/tumbleweed/&quot;&gt;openSUSE Tumbleweed&lt;/a&gt;. &lt;a href=&quot;https://www.samba.org/&quot;&gt;Samba&lt;/a&gt; jumped to the 4.24 series with many CVE fixes, &lt;a href=&quot;https://github.com/mariadb&quot;&gt;MariaDB&lt;/a&gt; advanced to 12.3.2, and &lt;a href=&quot;https://flatpak.org/&quot;&gt;Flatpak&lt;/a&gt; reached 1.18.0. &lt;a href=&quot;https://www.openssl.org/&quot;&gt;OpenSSL&lt;/a&gt; received an extensive security refresh, while &lt;a href=&quot;https://webkitgtk.org/&quot;&gt;WebKitGTK&lt;/a&gt; and the &lt;a href=&quot;https://www.kernel.org/&quot;&gt;Linux kernel&lt;/a&gt; each received large rounds of vulnerability fixes. &lt;a href=&quot;https://kde.org/announcements/gear/26.04.2/&quot;&gt;KDE Gear 26.04.2&lt;/a&gt; continued the steady cadence of KDE application refinements, &lt;a href=&quot;https://gstreamer.freedesktop.org/&quot;&gt;GStreamer&lt;/a&gt; 1.28.4 delivered major RTSP infrastructure improvements, and &lt;a href=&quot;http://www.graphicsmagick.org/&quot;&gt;GraphicsMagick&lt;/a&gt; 1.3.47 rolled up years of accumulated upstream security patches. The openSUSE Conference in Nuremberg provided the community backdrop for planning the next phase of the rolling release.&lt;/p&gt;

&lt;h2 id=&quot;slowroll-arrivals&quot;&gt;Slowroll Arrivals&lt;/h2&gt;
&lt;p&gt;Please note that these updates also apply to &lt;a href=&quot;https://en.opensuse.org/openSUSE:Slowroll&quot;&gt;Slowroll&lt;/a&gt; and arrive between an average of 5 to 10 days after being released in Tumbleweed snapshot. This monthly approach has been consistent for many months, ensuring stability and timely enhancements for users. Updated packages for Slowroll are regularly published in emails on &lt;a href=&quot;https://lists.opensuse.org/archives/list/factory@lists.opensuse.org/&quot;&gt;openSUSE Factory mailing list&lt;/a&gt;.&lt;/p&gt;

&lt;h2 id=&quot;contributing-to-opensuse-tumbleweed&quot;&gt;Contributing to openSUSE Tumbleweed&lt;/h2&gt;
&lt;p&gt;Stay updated with the latest snapshots by subscribing to the openSUSE Factory mailing list.
For those Tumbleweed users who want to contribute or want to engage with detailed technological discussions, subscribe to the &lt;a href=&quot;https://lists.opensuse.org/archives/list/factory@lists.opensuse.org/&quot;&gt;openSUSE Factory mailing list &lt;/a&gt;. The openSUSE team encourages users to continue participating through bug reports, feature suggestions and discussions.&lt;/p&gt;

&lt;p&gt;Your contributions and feedback make openSUSE Tumbleweed better with every update. Whether reporting bugs, suggesting features, or participating in community discussions, your involvement is highly valued.&lt;/p&gt;

&lt;meta name=&quot;openSUSE, Open Source, development, Linux, secure operating systems, open source, Tumbleweed, KDE, Gear, GNOME, GStreamer, OpenSSL, Samba, MariaDB, Flatpak, WebKitGTK, GraphicsMagick, Linux kernel, CVE, Steam&quot; content=&quot;HTML,CSS,XML,JavaScript&quot; /&gt;

</content:encoded>
    </item>

  </channel>
</rss>

