apache2
- Fix the following bugs / CVEs:
  * bsc#1267976 / CVE-2026-29167
  * bsc#1267977 / CVE-2026-29170
  * bsc#1267978 / CVE-2026-34355
  * bsc#1267955 / CVE-2026-34356
  * bsc#1267956 / CVE-2026-42535
  * bsc#1267962 / CVE-2026-42536
  * bsc#1267963 / CVE-2026-43951
  * bsc#1267965 / CVE-2026-44119
  * bsc#1267969 / CVE-2026-44185
  * bsc#1267970 / CVE-2026-44186
  * bsc#1267971 / CVE-2026-44631
  * bsc#1267972 / CVE-2026-48913
  * bsc#1267503 / CVE-2026-49975
- Add patch files:
  * CVE-2026-29167.patch
  * CVE-2026-29170.patch
  * CVE-2026-34355.patch
  * CVE-2026-34356.patch
  * CVE-2026-42535.patch
  * CVE-2026-42536.patch
  * CVE-2026-43951.patch
  * CVE-2026-44119.patch
  * CVE-2026-44185.patch
  * CVE-2026-44186.patch
  * CVE-2026-44631.patch
  * CVE-2026-48913.patch
  * CVE-2026-49975.patch

- Update to 2.4.66 (jsc#PED-16334).
- Update apache2.keyring with the 2.4.66 release signing key
- Refresh apache2-loadmodule.conf for the module set in 2.4.66
- Fix bsc#1263957 / CVE-2026-23918.
- Fix bsc#1263935 / CVE-2026-24072.
- Fix bsc#1264163 / CVE-2026-28780.
- Fix bsc#1264150 / CVE-2026-29168.
- Fix bsc#1263956 / CVE-2026-29169.
- Fix bsc#1263955 / CVE-2026-33006.
- Fix bsc#1263954 / CVE-2026-33007.
- Fix bsc#1263953 / CVE-2026-33523.
- Fix bsc#1263952 / CVE-2026-33857.
- Fix bsc#1263951 / CVE-2026-34032.
- Fix bsc#1263950 / CVE-2026-34059.
- Add the following security patches:
  * CVE-2026-23918.patch
  * CVE-2026-24072.patch
  * CVE-2026-28780.patch
  * CVE-2026-29168.patch
  * CVE-2026-29169.patch
  * CVE-2026-33006.patch
  * CVE-2026-33007.patch
  * CVE-2026-33523.patch
  * CVE-2026-33857.patch
  * CVE-2026-34032.patch
  * CVE-2026-34059.patch
- Drop CVE patches now fixed in 2.4.66:
  * apache2-CVE-2006-20001.patch
  * apache2-CVE-2021-44224.patch
  * apache2-CVE-2021-44790.patch
  * apache2-CVE-2022-22719.patch
  * apache2-CVE-2022-22720.patch
  * apache2-CVE-2022-22721.patch
  * apache2-CVE-2022-23943.patch
  * apache2-CVE-2022-26377.patch
  * apache2-CVE-2022-28614.patch
  * apache2-CVE-2022-28615.patch
  * apache2-CVE-2022-29404.patch
  * apache2-CVE-2022-30522.patch
  * apache2-CVE-2022-30556.patch
  * apache2-CVE-2022-31813.patch
  * apache2-CVE-2022-36760.patch
  * apache2-CVE-2022-37436.patch
  * apache2-CVE-2023-25690.patch
  * apache2-CVE-2023-27522.patch
  * apache2-CVE-2023-31122.patch
  * apache2-CVE-2023-38709.patch
  * apache2-CVE-2023-45802.patch
  * apache2-CVE-2024-24795.patch
  * apache2-CVE-2024-27316.patch
  * apache2-CVE-2024-38473-1.patch
  * apache2-CVE-2024-38473-2.patch
  * apache2-CVE-2024-38473-3.patch
  * apache2-CVE-2024-38473-4.patch
  * apache2-CVE-2024-38474.patch
  * apache2-CVE-2024-38475-1.patch
  * apache2-CVE-2024-38475-2.patch
  * apache2-CVE-2024-38475-3.patch
  * apache2-CVE-2024-38476-1.patch
  * apache2-CVE-2024-38476-2.patch
  * apache2-CVE-2024-38476-3.patch
  * apache2-CVE-2024-38476-4.patch
  * apache2-CVE-2024-38476-5.patch
  * apache2-CVE-2024-38476-6.patch
  * apache2-CVE-2024-38476-7.patch
  * apache2-CVE-2024-38476-8.patch
  * apache2-CVE-2024-38476-9.patch
  * apache2-CVE-2024-38476-10.patch
  * apache2-CVE-2024-38476-11.patch
  * apache2-CVE-2024-38477.patch
  * apache2-CVE-2024-39573.patch
  * apache2-CVE-2024-39884.patch
  * apache2-CVE-2024-40725.patch
  * CVE-2024-42516.patch
  * CVE-2024-43204.patch
  * CVE-2024-47252.patch
  * CVE-2025-23048.patch
  * CVE-2025-49630.patch
  * CVE-2025-49812.patch
  * CVE-2025-53020-1.patch
  * CVE-2025-53020-2.patch
  * CVE-2025-55753.patch
  * CVE-2025-58098.patch
  * CVE-2025-65082.patch
  * CVE-2025-66200.patch
- Drop feature and bug-fix backports now included upstream:
  * apache2-bsc1207327-fix-mod_proxy-handling-long-urls.patch
  * apache2-bsc1208708-fix-passing-health-check-recover-worker-from-error-state.patch
  * apache2-bsc1214357-mod_proxy_http2_apply-standard-content-type.patch
  * apache2-core-mpm-add-hook-child_stopped-that-gets-called-whe.patch
  * apache2-core-prefork-run-new-hook-child_stopped-only-on-clea.patch
  * apache2-issue-444.patch
  * apache2-mod_watchdog-add-assertions-to-cleanup-code.patch
  * apache2-mod_watchdog-do-not-call-a-watchdog-instance-for.patch
  * apache2-mod_watchdog-replace-the-new-volatile-with-atomic-ac.patch
  * apache2-mod_watchdog-use-hook-child_stopping-to-signal-watch.patch
  * apache2-mod_watchdog-use-the-child_stopping-and-child_stoppe.patch
  * apache2-mpm-winnt-add-running-the-child_stopping-hook.patch
- Replace the obsolete httpd-* patches with the maintained patch set:
  * Drop:
    httpd-2.0.54-envvars.dif
    httpd-2.2.0-apxs-a2enmod.dif
    httpd-2.4.9-bnc690734.patch
    httpd-2.4.x-fate317766-config-control-two-protocol-options.diff
    httpd-2.x.x-logresolve.patch
    httpd-apachectl.patch
    httpd-implicit-pointer-decl.patch
  * Add:
    apache2-apachectl.patch
    apache2-logresolve-tmp-security.patch
    apache2-HttpContentLengthHeadZero-HttpExpectStrict.patch
    apache2-LimitRequestFieldSize-limits-headers.patch
- Drop deprecated-scripts-arch.patch
- Drop httpd-visibility.patch and remove -fvisibility=hidden from
  CFLAGS, so the ap_* symbols stay visible to dynamically loaded
  modules
bind
- Security Fixes:
  * Amplification vulnerabilities via self-pointed glue records.
    (CVE-2026-3592)
    [bsc#1265592, bind-9.16-CVE-2026-3592.patch]
  * Server memory exhaustion during GSS-API TKEY negotiation.
    (CVE-2026-3039)
    [bsc#1265591, bind-9.16-CVE-2026-3039.patch]
  * Invalid handling of CLASS != IN.
    (CVE-2026-5946)
    [bsc#1265594, bind-9.16-CVE-2026-5946.patch]
cifs-utils
- CVE-2026-12505: cifs.upcall: remove getpwuid() dependency
  (bsc#1267389)
  * add cifs.upcall-remove-getpwuid-dependency.patch
containerd
- Add patch for CVE-2026-34986 (bsc#1262948)
  * 0003-CVE-2026-34986-Bump-go-jose-to-v3.0.5.patch
- Add patch for CVE-2026-39821 (bsc#1266640)
  * 0004-CVE-2026-39821-idna-update-from-x-text-fix-ToUnicode.patch
- Add patch for CVE-2026-33814 (bsc#1265794)
  * 0005-CVE-2026-33814-http2-prevent-hanging-Transport-due-t.patch

- Add patch for CVE-2026-33186 (bsc#1260296):
  * 0002-CVE-2026-33186-containerd-google.golang.org-grpc-aut.patch
coreutils
- proc: Use affinity mask even on systems with more than 1024 CPUs (bsc#1259327)
  - add coreutils-gnulib-nproc-Use-affinity-mask-even-on-systems-with-more-th.patch
cups
- cups-2.2.7-CVE-2026-39314.patch is based on
  https://github.com/OpenPrinting/cups/commit/928a86b1b794f738f0a3dc87561b2e054bff7ce4
  backported to CUPS 2.2.7 to fix CVE-2026-39314
  "Integer underflow in `_ppdCreateFromIPP` causes root cupsd crash
  via negative `job-password-supported`"
  https://github.com/OpenPrinting/cups/security/advisories/GHSA-pp8w-2g52-7vj7
  bsc#1261743
  "negative `job-password-supported` attribute
  can lead to a denial of service"

- cups-2.2.7-CVE-2026-39316.patch is based on
  https://github.com/OpenPrinting/cups/commit/0142eeb58e0d718b7d2e1f0d5dd214bd2192cc7f
  backported to CUPS 2.2.7 to fix CVE-2026-39316
  "Use-after-free in `cupsdDeleteTemporaryPrinters`
  via dangling subscription pointer"
  https://github.com/OpenPrinting/cups/security/advisories/GHSA-pjv5-prqp-46rg
  bsc#1261742
  "dangling subscription pointer can lead to a denial of service"

- cups-2.2.7-CVE-2026-27447.patch is based on
  https://github.com/OpenPrinting/cups/commit/a0c62c1e69604ff061089b750073199fab5a1beb
  plus the fix for the regression
  https://github.com/OpenPrinting/cups/commit/6d97ee39fedf12a7a5429a74f4156ef9bb67f562
  https://github.com/OpenPrinting/cups/issues/1555
  "Fix for CVE-2026-27447 introduces SEGV if user does not exist"
  plus the fix for the other regression
  https://github.com/OpenPrinting/cups/commit/849fba7d7a1144e48d45c5e6ba2504765912ece0
  https://github.com/OpenPrinting/cups/issues/1557
  "Another regression in the fix for CVE-2026-27447:
  Non-users cannot print to unauthenticated queue"
  backported to CUPS 2.2.7 to fix CVE-2026-27447
  "Authorization bypass via case-insensitive group-member lookup"
  https://github.com/OpenPrinting/cups/security/advisories/GHSA-v987-m8hp-phj9
  bsc#1261572

- Fixed cups-2.2.7-CVE-2026-34980.patch (bsc#1261569)
  according to
  https://github.com/OpenPrinting/cups/commit/3f2bdc293243bca938c6de23ba50e6d783189629
  in https://github.com/OpenPrinting/cups/issues/1562
  "keyword is never incremented, which leads to handling
  keywords[0] element only"

- cups-2.2.7-CVE-2026-34978.patch is based on
  https://github.com/OpenPrinting/cups/commit/730347c5bbd5e1271149c6739aa858c0c83a7568
  backported to CUPS 2.2.7 to fix CVE-2026-34978
  "Path traversal in RSS notify-recipient-uri enables file write
  outside CacheDir/rss (and clobbering of job.cache)"
  https://github.com/OpenPrinting/cups/security/advisories/GHSA-f53q-7mxp-9gcr
  bsc#1261571

- cups-2.2.7-CVE-2026-34979.patch is based on
  https://github.com/OpenPrinting/cups/commit/0ff8897367c7341f2500770c3977038cdd7c0214
  backported to CUPS 2.2.7 to fix CVE-2026-34979
  "Heap overflow in `get_options()`"
  https://github.com/OpenPrinting/cups/security/advisories/GHSA-6qxf-7jx6-86fh
  bsc#1261570

- cups-2.2.7-CVE-2026-34980.patch is based on
  https://github.com/OpenPrinting/cups/commit/8d0f51cac24cb5bf949c5b6a221e51a150d982e3
  backported to CUPS 2.2.7 to fix CVE-2026-34980
  "Shared PostScript queue lets anonymous Print-Job requests
  reach `lp` code execution over the network"
  https://github.com/OpenPrinting/cups/security/advisories/GHSA-4852-v58g-6cwf
  bsc#1261569
docker
- Ensure correct certificate is used for TSA auth
  (bsc#1262346, CVE-2026-39984)
  * 0007-CVE-2026-39984-Ensure-correct-certificate-is-used-fo.patch
- http2: prevent hanging Transport due to bad SETTINGS
  (bsc#1265782, CVE-2026-33814)
  * 0008-CVE-2026-33814-http2-prevent-hanging-Transport-due-t.patch
- idna: update from x/text, fix ToUnicode and all-ASCII xn-- labels
  (bsc#1266625, CVE-2026-39821)
  * 0009-CVE-2026-39821-idna-update-from-x-text-fix-ToUnicode.patch
- daemon: Decompress archives before entering container filesystem
  (bsc#1267827, CVE-2026-41567)
  * 0010-CVE-2026-41567-daemon-Decompress-archives-before-ent.patch
dracut
- Update to version 055+suse.402.g2720eea:
  * fix(network-legacy): sanitize DHCP values in dhclient-script.sh (bsc#1268322, CVE-2026-6893)
  * fix(network-legacy): add input validation to RFC 3442 route parser
google-guest-agent
- Update to version 20260529.00
  * Dependency updates (#616) (bsc#1266603, CVE-2026-39821)
    (bsc#1266171, CVE-2026-39827, CVE-2026-39834, CVE-2026-39828,
    CVE-2026-39829, CVE-2026-39831, CVE-2026-42508, CVE-2026-39833,
    CVE-2026-39830, CVE-2026-39832, CVE-2026-46597, CVE-2026-46598,
    CVE-2026-46595, CVE-2026-39835)
- from version 20260522.00
  * Fix improper umask calculation on socket creation (#614)
- from version 20260520.01
  * Update OWNERS (#609)

- Packaging improvements:
  * Remove define github project name components no longer needed
  * Define shortname corresponding to binary name when different
    from package name. Use shortname where applicable to normalize
    common lines across Go app packages, similar to name macro.
  * Drop BuildRequires: golang-packaging. The original macros for
    file movements into GOPATH are obsolete with Go modules. Macro
    go_nostrip is no longer needed with current binutils and Go.
  * Remove go_nostrip macro which is no longer recommended
  * Re-enable binary stripping and debuginfo boo#1210938
  * Remove goprep macro which is no longer recommended
  * Build PIE with pattern that may become recommended procedure:
    %%ifnarch ppc64 GOFLAGS="-buildmode=pie" %%endif go build
    A go toolchain buildmode default config would be preferable
    but none exist at this time.
  * Drop export CGO_ENABLED="0". Use the default unless there is a
    defined requirement or benefit.
  * For this package, we were seeing the expected error
    "-buildmode=pie requires external (cgo) linking, but cgo is not
    enabled" when using buildmode=pie and CGO_ENABLED=0. The error
    manifested only on s390x and i586 architectures, which was not
    expected. Resolve by using default CGO_ENABLED.
  * Remove ldflags -s (Omit symbol table and debug info) and -w
    (Omit DWARF symbol table). This information is used to produce
    separate debuginfo packages and binaries are stripped for
    reduced size by GNU strip during RPM build.
  * Remove ldflags -X entry for embedding build version metadata.
    This information is embedded in binaries with go1.18+ and
    available via go version -m or runtime/debug.ReadBuildInfo().
  * Drop mod=vendor, go1.14+ will detect vendor dir and auto-enable

- Update to version 20260430.00
  * Update OWNERS (#609)
  * Update THIRD_PARTY_LICENSES to be package specific location. (#608)
  * Update dependencies and go version to 1.26.2 (#607)
    (bsc#1265762, CVE-2026-33814)
  * Bump github.com/go-jose/go-jose/v4 from 4.1.3 to 4.1.4 (#604)
    (bsc#1260264, CVE-2026-33186)
  * Backport oslogin changes for sles16 to legacy agent (#603)
  * Bump go.opentelemetry.io/otel/sdk from 1.37.0 to 1.40.0 (#596)
  * Bump google.golang.org/grpc from 1.75.0 to 1.79.3 (#602) (bsc#1260264, CVE-2026-33186)
  * Actually finally fix the RPM spec (#601)
  * Correct guest telemetry build target (#600)
  * Add packaging for new telemetry extension (#599)
  * Implement new scheduled job for routes monitor (#598)
  * Add packaging changes for locally bundled extensions feature support (#593)
  * Ensure the uninstall script handles GCE metadata endpoint unavailability. (#591)
  * Disable certificates when security keys are enabled (#588)
  * Move sourcing of per-user configs to the end of sshd_config, fixing 2FA logins. (#590)
  * Source the contents of /var/google-users.d config files. (#586)
  * Force remove core plugin configuration for windows (#587)
  * network: force address manager to always consolidate the OS state (#585)
  * Bump golang.org/x/crypto from 0.41.0 to 0.45.0 (#583)
    (bsc#1239334, CVE-2025-22869, bsc#1253889, CVE-2025-58181)
  * Don't delete the authorized_keys file when an empty key list
    is passed to updateAuthorizedKeysFile (#582)
  * Add Tyler, Saswat, Hank to OWNERS (#577)
  * Honor core plugin setting on windows package update (#576)
  * Restart agent if core plugin is disabled (#575)
  * Add extra debug logging around toggling OS Login (#572)
  * Update go version to 1.25 (#565)
  * Add compat adapt script to windows in agent sysprep (#569)
  * Fix adapt to use more portable shebang line (#567)
  * Remove routes script from packaging (#566)
  * Update adapt script to run on startup/shutdown both (#561)
  * Update agent_uninstall.ps1 (#558)
  * Stop core plugin before removing agent package (#554)
  * Startup scripts should start after agent manager instead (#553)
  * Update presets and install dependencies on systemd units (#552)
  * Ensure agent service is disabled (#551)
  * Disable legacy agent to enable core plugin (#550)
  * Final fix for RHEL packaging for routes setup (#549)
  * Fix RHEL packaging for routes scripts (#548)
  * Packaging changes to include routes script installation (#542)
  * Update CLI name in packaging (#543)
  * systemd should manage only the main process (#544)
- from version 20260424.00
  * Bring topic-stable up to latest point. (#606)
  * Bring stable branch up to 822ad49fd52b4d29869604af836a33cb22a667ba (#592)
  * fix start mode for windows on stable release (#584)
  * Update agent_uninstall.ps1 (#558) (#580)
  * Update go version for stable branch to 1.25 (#571)
  * Add adapt script in stable branch as per #569 (#570)
  * Backport fix from #567 to stable branch (#568)
  * Revert compat behavior and call known binary directly (#560)
  * Revert compat behavior and call known binary directly (#559)
  * Build rollforward package to re-enable original agent and disable core plugin (#557)
- from version 20260423.01
  * Update THIRD_PARTY_LICENSES to be package specific location. (#608)
- from version 20260423.00
  * Update dependencies and go version to 1.26.2 (#607)
  * Bump github.com/go-jose/go-jose/v4 from 4.1.3 to 4.1.4 (#604)
  * Backport oslogin changes for sles16 to legacy agent (#603)
  * Bump go.opentelemetry.io/otel/sdk from 1.37.0 to 1.40.0 (#596)
  * Bump google.golang.org/grpc from 1.75.0 to 1.79.3 (#602)
  * Actually finally fix the RPM spec (#601)
  * Correct guest telemetry build target (#600)
  * Add packaging for new telemetry extension (#599)
  * Implement new scheduled job for routes monitor (#598)
  * Add packaging changes for locally bundled extensions feature support (#593)
  * Ensure the uninstall script handles GCE metadata endpoint unavailability. (#591)
  * Disable certificates when security keys are enabled (#588)
  * Move sourcing of per-user configs to the end of sshd_config, fixing 2FA logins. (#590)
  * Source the contents of /var/google-users.d config files. (#586)
  * Force remove core plugin configuration for windows (#587)
  * network: force address manager to always consolidate the OS state (#585)
  * Bump golang.org/x/crypto from 0.41.0 to 0.45.0 (#583)
  * Don't delete the authorized_keys file when an empty key
    list is passed to updateAuthorizedKeysFile (#582)
  * Add Tyler, Saswat, Hank to OWNERS (#577)
  * Honor core plugin setting on windows package update (#576)
  * Restart agent if core plugin is disabled (#575)
  * Add extra debug logging around toggling OS Login (#572)
  * Update go version to 1.25 (#565)
  * Add compat adapt script to windows in agent sysprep (#569)
  * Fix adapt to use more portable shebang line (#567)
  * Remove routes script from packaging (#566)
  * Update adapt script to run on startup/shutdown both (#561)
  * Update agent_uninstall.ps1 (#558)
  * Stop core plugin before removing agent package (#554)
  * Startup scripts should start after agent manager instead (#553)
  * Update presets and install dependencies on systemd units (#552)
  * Ensure agent service is disabled (#551)
  * Disable legacy agent to enable core plugin (#550)
  * Final fix for RHEL packaging for routes setup (#549)
  * Fix RHEL packaging for routes scripts (#548)
  * Packaging changes to include routes script installation (#542)
  * Update CLI name in packaging (#543)
  * systemd should manage only the main process (#544)
- from version 20260422.01
  * Bring topic-stable up to latest point. (#606)
  * Bring stable branch up to 822ad49fd52b4d29869604af836a33cb22a667ba (#592)
  * fix start mode for windows on stable release (#584)
  * Update agent_uninstall.ps1 (#558) (#580)
  * Update go version for stable branch to 1.25 (#571)
  * Add adapt script in stable branch as per #569 (#570)
  * Backport fix from #567 to stable branch (#568)
  * Revert compat behavior and call known binary directly (#560)
  * Revert compat behavior and call known binary directly (#559)
  * Build rollforward package to re-enable original agent and disable core plugin (#557)
- from version 20260422.00
  * Update dependencies and go version to 1.26.2 (#607)
  * Bump github.com/go-jose/go-jose/v4 from 4.1.3 to 4.1.4 (#604)
  * Backport oslogin changes for sles16 to legacy agent (#603)
  * Bump go.opentelemetry.io/otel/sdk from 1.37.0 to 1.40.0 (#596)
  * Bump google.golang.org/grpc from 1.75.0 to 1.79.3 (#602)
  * Actually finally fix the RPM spec (#601)
  * Correct guest telemetry build target (#600)
  * Add packaging for new telemetry extension (#599)
  * Implement new scheduled job for routes monitor (#598)
  * Add packaging changes for locally bundled extensions feature support (#593)
  * Ensure the uninstall script handles GCE metadata endpoint unavailability. (#591)
  * Disable certificates when security keys are enabled (#588)
  * Move sourcing of per-user configs to the end of sshd_config, fixing 2FA logins. (#590)
  * Source the contents of /var/google-users.d config files. (#586)
  * Force remove core plugin configuration for windows (#587)
  * network: force address manager to always consolidate the OS state (#585)
  * Bump golang.org/x/crypto from 0.41.0 to 0.45.0 (#583)
  * Don't delete the authorized_keys file when an empty key
    list is passed to updateAuthorizedKeysFile (#582)
  * Add Tyler, Saswat, Hank to OWNERS (#577)
  * Honor core plugin setting on windows package update (#576)
  * Restart agent if core plugin is disabled (#575)
  * Add extra debug logging around toggling OS Login (#572)
  * Update go version to 1.25 (#565)
  * Add compat adapt script to windows in agent sysprep (#569)
  * Fix adapt to use more portable shebang line (#567)
  * Remove routes script from packaging (#566)
  * Update adapt script to run on startup/shutdown both (#561)
  * Update agent_uninstall.ps1 (#558)
  * Stop core plugin before removing agent package (#554)
  * Startup scripts should start after agent manager instead (#553)
  * Update presets and install dependencies on systemd units (#552)
  * Ensure agent service is disabled (#551)
  * Disable legacy agent to enable core plugin (#550)
  * Final fix for RHEL packaging for routes setup (#549)
  * Fix RHEL packaging for routes scripts (#548)
  * Packaging changes to include routes script installation (#542)
  * Update CLI name in packaging (#543)
  * systemd should manage only the main process (#544)
- from version 20260421.00
  * Bring topic-stable up to latest point. (#606)
  * Bring stable branch up to 822ad49fd52b4d29869604af836a33cb22a667ba (#592)
  * fix start mode for windows on stable release (#584)
  * Update agent_uninstall.ps1 (#558) (#580)
  * Update go version for stable branch to 1.25 (#571)
  * Add adapt script in stable branch as per #569 (#570)
  * Backport fix from #567 to stable branch (#568)
  * Revert compat behavior and call known binary directly (#560)
  * Revert compat behavior and call known binary directly (#559)
  * Build rollforward package to re-enable original agent and disable core plugin (#557)
- from version 20260414.00
  * Bump github.com/go-jose/go-jose/v4 from 4.1.3 to 4.1.4 (#604)
- Bump Go API version to 1.26
- Drop CVE-2026-34986.patch, merged upstream

- Add CVE-2026-34986.patch to fix crafted JWE input with a missing encrypted
  key can lead to a denial of service (bsc#1262926, CVE-2026-34986)

- Update to version 20260402.00: (bsc#1257010)
  * Backport oslogin changes for sles16 to legacy agent (#603)
  * Bump go.opentelemetry.io/otel/sdk from 1.37.0 to 1.40.0 (#596)
  * Bump google.golang.org/grpc from 1.75.0 to 1.79.3 (#602)
  * Actually finally fix the RPM spec (#601)
  * Correct guest telemetry build target (#600)
  * Add packaging for new telemetry extension (#599)
  * Implement new scheduled job for routes monitor (#598)
  * Add packaging changes for locally bundled extensions feature support (#593)
  * Ensure the uninstall script handles GCE metadata endpoint unavailability. (#591)
  * Disable certificates when security keys are enabled (#588)
  * Move sourcing of per-user configs to the end of sshd_config, fixing 2FA logins. (#590)

- Update to version 20260108.00
  * Source the contents of /var/google-users.d config files. (#586)

- Update to version 20251223.00
  * Force remove core plugin configuration for windows (#587)
  * network: force address manager to always consolidate the OS state (#585)
  * Bump golang.org/x/crypto from 0.41.0 to 0.45.0 (#583)
  * Don't delete the authorized_keys file when an empty key list
    is passed to updateAuthorizedKeysFile (#582)
  * Add Tyler, Saswat, Hank to OWNERS (#577)
  * Honor core plugin setting on windows package update (#576)
  * Restart agent if core plugin is disabled (#575)
  * Add extra debug logging around toggling OS Login (#572)
  * Update go version to 1.25 (#565)
  * Add compat adapt script to windows in agent sysprep (#569)
  * Fix adapt to use more portable shebang line (#567)
  * Remove routes script from packaging (#566)
  * Update adapt script to run on startup/shutdown both (#561)
  * Update agent_uninstall.ps1 (#558)
  * Stop core plugin before removing agent package (#554)
  * Startup scripts should start after agent manager instead (#553)
  * Update presets and install dependencies on systemd units (#552)
  * Ensure agent service is disabled (#551)
  * Disable legacy agent to enable core plugin (#550)
  * Final fix for RHEL packaging for routes setup (#549)
  * Fix RHEL packaging for routes scripts (#548)
  * Packaging changes to include routes script installation (#542)
  * Update CLI name in packaging (#543)
  * systemd should manage only the main process (#544)
- from version 20251218.01
  * fix start mode for windows on stable release (#584)
  * Update agent_uninstall.ps1 (#558) (#580)
  * Update go version for stable branch to 1.25 (#571)
  * Add adapt script in stable branch as per #569 (#570)
  * Backport fix from #567 to stable branch (#568)
  * Revert compat behavior and call known binary directly (#560)
  * Revert compat behavior and call known binary directly (#559)
  * Build rollforward package to re-enable original agent and disable core plugin (#557)
- from version 20251218.00
  * Force remove core plugin configuration for windows (#587)
  * network: force address manager to always consolidate the OS state (#585)
  * Bump golang.org/x/crypto from 0.41.0 to 0.45.0 (#583)
  * Don't delete the authorized_keys file when an empty key list
    is passed to updateAuthorizedKeysFile (#582)
  * Add Tyler, Saswat, Hank to OWNERS (#577)
  * Honor core plugin setting on windows package update (#576)
  * Restart agent if core plugin is disabled (#575)
  * Add extra debug logging around toggling OS Login (#572)
  * Update go version to 1.25 (#565)
  * Add compat adapt script to windows in agent sysprep (#569)
  * Fix adapt to use more portable shebang line (#567)
  * Remove routes script from packaging (#566)
  * Update adapt script to run on startup/shutdown both (#561)
  * Update agent_uninstall.ps1 (#558)
  * Stop core plugin before removing agent package (#554)
  * Startup scripts should start after agent manager instead (#553)
  * Update presets and install dependencies on systemd units (#552)
  * Ensure agent service is disabled (#551)
  * Disable legacy agent to enable core plugin (#550)
  * Final fix for RHEL packaging for routes setup (#549)
  * Fix RHEL packaging for routes scripts (#548)
  * Packaging changes to include routes script installation (#542)
  * Update CLI name in packaging (#543)
  * systemd should manage only the main process (#544)
- from version 20251216.00
  * fix start mode for windows on stable release (#584)
  * Update agent_uninstall.ps1 (#558) (#580)
  * Update go version for stable branch to 1.25 (#571)
  * Add adapt script in stable branch as per #569 (#570)
  * Backport fix from #567 to stable branch (#568)
  * Revert compat behavior and call known binary directly (#560)
  * Revert compat behavior and call known binary directly (#559)
  * Build rollforward package to re-enable original agent and disable core plugin (#557)
- from version 20251215.00
  * Force remove core plugin configuration for windows (#587)
  * network: force address manager to always consolidate the OS state (#585)
  * Bump golang.org/x/crypto from 0.41.0 to 0.45.0 (#583)
  * Don't delete the authorized_keys file when an empty key list
    is passed to updateAuthorizedKeysFile (#582)
  * Add Tyler, Saswat, Hank to OWNERS (#577)
  * Honor core plugin setting on windows package update (#576)
  * Restart agent if core plugin is disabled (#575)
  * Add extra debug logging around toggling OS Login (#572)
  * Update go version to 1.25 (#565)
  * Add compat adapt script to windows in agent sysprep (#569)
  * Fix adapt to use more portable shebang line (#567)
  * Remove routes script from packaging (#566)
  * Update adapt script to run on startup/shutdown both (#561)
  * Update agent_uninstall.ps1 (#558)
  * Stop core plugin before removing agent package (#554)
  * Startup scripts should start after agent manager instead (#553)
  * Update presets and install dependencies on systemd units (#552)
  * Ensure agent service is disabled (#551)
  * Disable legacy agent to enable core plugin (#550)
  * Final fix for RHEL packaging for routes setup (#549)
  * Fix RHEL packaging for routes scripts (#548)
  * Packaging changes to include routes script installation (#542)
  * Update CLI name in packaging (#543)
  * systemd should manage only the main process (#544)
- from version 20251210.00
  * fix start mode for windows on stable release (#584)
  * Update agent_uninstall.ps1 (#558) (#580)
  * Update go version for stable branch to 1.25 (#571)
  * Add adapt script in stable branch as per #569 (#570)
  * Backport fix from #567 to stable branch (#568)
  * Revert compat behavior and call known binary directly (#560)
  * Revert compat behavior and call known binary directly (#559)
  * Build rollforward package to re-enable original agent and disable core plugin (#557)
- from version 20251209.00
  * Force remove core plugin configuration for windows (#587)

- Update to version 20251208.00
  * network: force address manager to always consolidate the OS state (#585)
  * Bump golang.org/x/crypto from 0.41.0 to 0.45.0 (#583)
  * Don't delete the authorized_keys file when an empty key list is passed
    to updateAuthorizedKeysFile (#582)
  * Add Tyler, Saswat, Hank to OWNERS (#577)
  * Honor core plugin setting on windows package update (#576)
  * Restart agent if core plugin is disabled (#575)
  * Add extra debug logging around toggling OS Login (#572)
  * Update go version to 1.25 (#565)
  * Add compat adapt script to windows in agent sysprep (#569)
  * Fix adapt to use more portable shebang line (#567)
  * Remove routes script from packaging (#566)
  * Update adapt script to run on startup/shutdown both (#561)
  * Update agent_uninstall.ps1 (#558)
  * Stop core plugin before removing agent package (#554)
  * Startup scripts should start after agent manager instead (#553)
  * Update presets and install dependencies on systemd units (#552)
  * Ensure agent service is disabled (#551)
  * Disable legacy agent to enable core plugin (#550)
  * Final fix for RHEL packaging for routes setup (#549)
  * Fix RHEL packaging for routes scripts (#548)
  * Packaging changes to include routes script installation (#542)
  * Update CLI name in packaging (#543)
  * systemd should manage only the main process (#544)
- from version 20251206.00
  * fix start mode for windows on stable release (#584)
  * Update agent_uninstall.ps1 (#558) (#580)
  * Update go version for stable branch to 1.25 (#571)
  * Add adapt script in stable branch as per #569 (#570)
  * Backport fix from #567 to stable branch (#568)
  * Revert compat behavior and call known binary directly (#560)
  * Revert compat behavior and call known binary directly (#559)
  * Build rollforward package to re-enable original agent and disable core plugin (#557)
- from version 20251205.00
  * network: force address manager to always consolidate the OS state (#585)
  * Bump golang.org/x/crypto from 0.41.0 to 0.45.0 (#583)
  * Don't delete the authorized_keys file when an empty key list
    is passed to updateAuthorizedKeysFile (#582)
  * Add Tyler, Saswat, Hank to OWNERS (#577)
  * Honor core plugin setting on windows package update (#576)
  * Restart agent if core plugin is disabled (#575)
  * Add extra debug logging around toggling OS Login (#572)
  * Update go version to 1.25 (#565)
  * Add compat adapt script to windows in agent sysprep (#569)
  * Fix adapt to use more portable shebang line (#567)
  * Remove routes script from packaging (#566)
  * Update adapt script to run on startup/shutdown both (#561)
  * Update agent_uninstall.ps1 (#558)
  * Stop core plugin before removing agent package (#554)
  * Startup scripts should start after agent manager instead (#553)
  * Update presets and install dependencies on systemd units (#552)
  * Ensure agent service is disabled (#551)
  * Disable legacy agent to enable core plugin (#550)
  * Final fix for RHEL packaging for routes setup (#549)
  * Fix RHEL packaging for routes scripts (#548)
  * Packaging changes to include routes script installation (#542)
  * Update CLI name in packaging (#543)
  * systemd should manage only the main process (#544)

- Update to version 20251120.01
  * fix start mode for windows on stable release (#584)
  * Update agent_uninstall.ps1 (#558) (#580)
  * Update go version for stable branch to 1.25 (#571)
  * Add adapt script in stable branch as per #569 (#570)
  * Backport fix from #567 to stable branch (#568)
  * Revert compat behavior and call known binary directly (#560)
  * Revert compat behavior and call known binary directly (#559)
  * Build rollforward package to re-enable original agent and disable core plugin (#557)
- from version 20251120.00
  * Don't delete the authorized_keys file when an empty key list
    is passed to updateAuthorizedKeysFile (#582)
  * Add Tyler, Saswat, Hank to OWNERS (#577)
  * Honor core plugin setting on windows package update (#576)
  * Restart agent if core plugin is disabled (#575)
  * Add extra debug logging around toggling OS Login (#572)
  * Update go version to 1.25 (#565)
  * Add compat adapt script to windows in agent sysprep (#569)
  * Fix adapt to use more portable shebang line (#567)
  * Remove routes script from packaging (#566)
  * Update adapt script to run on startup/shutdown both (#561)
  * Update agent_uninstall.ps1 (#558)
  * Stop core plugin before removing agent package (#554)
  * Startup scripts should start after agent manager instead (#553)
  * Update presets and install dependencies on systemd units (#552)
  * Ensure agent service is disabled (#551)
  * Disable legacy agent to enable core plugin (#550)
  * Final fix for RHEL packaging for routes setup (#549)
  * Fix RHEL packaging for routes scripts (#548)
  * Packaging changes to include routes script installation (#542)
  * Update CLI name in packaging (#543)
  * systemd should manage only the main process (#544)
- from version 20251117.00
  * Update agent_uninstall.ps1 (#558) (#580)
  * Update go version for stable branch to 1.25 (#571)
  * Add adapt script in stable branch as per #569 (#570)
  * Backport fix from #567 to stable branch (#568)
  * Revert compat behavior and call known binary directly (#560)
  * Revert compat behavior and call known binary directly (#559)
  * Build rollforward package to re-enable original agent and disable core plugin (#557)
- from version 20251115.00
  * Don't delete the authorized_keys file when an empty key list is
    passed to updateAuthorizedKeysFile (#582)
  * Add Tyler, Saswat, Hank to OWNERS (#577)
  * Honor core plugin setting on windows package update (#576)
  * Restart agent if core plugin is disabled (#575)
  * Add extra debug logging around toggling OS Login (#572)
  * Update go version to 1.25 (#565)
  * Add compat adapt script to windows in agent sysprep (#569)
  * Fix adapt to use more portable shebang line (#567)
  * Remove routes script from packaging (#566)
  * Update adapt script to run on startup/shutdown both (#561)
  * Update agent_uninstall.ps1 (#558)
  * Stop core plugin before removing agent package (#554)
  * Startup scripts should start after agent manager instead (#553)
  * Update presets and install dependencies on systemd units (#552)
  * Ensure agent service is disabled (#551)
  * Disable legacy agent to enable core plugin (#550)
  * Final fix for RHEL packaging for routes setup (#549)
  * Fix RHEL packaging for routes scripts (#548)
  * Packaging changes to include routes script installation (#542)
  * Update CLI name in packaging (#543)
  * systemd should manage only the main process (#544)
- from version 20251108.00
  * Update agent_uninstall.ps1 (#558) (#580)
  * Update go version for stable branch to 1.25 (#571)
  * Add adapt script in stable branch as per #569 (#570)
  * Backport fix from #567 to stable branch (#568)
  * Revert compat behavior and call known binary directly (#560)
  * Revert compat behavior and call known binary directly (#559)
  * Build rollforward package to re-enable original agent and disable core plugin (#557)
- from version 20251107.01
  * Don't delete the authorized_keys file when an empty key list is
    passed to updateAuthorizedKeysFile (#582)
  * Add Tyler, Saswat, Hank to OWNERS (#577)
  * Honor core plugin setting on windows package update (#576)
  * Restart agent if core plugin is disabled (#575)
  * Add extra debug logging around toggling OS Login (#572)
  * Update go version to 1.25 (#565)
  * Add compat adapt script to windows in agent sysprep (#569)
  * Fix adapt to use more portable shebang line (#567)
  * Remove routes script from packaging (#566)
  * Update adapt script to run on startup/shutdown both (#561)
  * Update agent_uninstall.ps1 (#558)
  * Stop core plugin before removing agent package (#554)
  * Startup scripts should start after agent manager instead (#553)
  * Update presets and install dependencies on systemd units (#552)
  * Ensure agent service is disabled (#551)
  * Disable legacy agent to enable core plugin (#550)
  * Final fix for RHEL packaging for routes setup (#549)
  * Fix RHEL packaging for routes scripts (#548)
  * Packaging changes to include routes script installation (#542)
  * Update CLI name in packaging (#543)
  * systemd should manage only the main process (#544)
- from version 20251031.00
  * Update agent_uninstall.ps1 (#558) (#580)
  * Update go version for stable branch to 1.25 (#571)
  * Add adapt script in stable branch as per #569 (#570)
  * Backport fix from #567 to stable branch (#568)
  * Revert compat behavior and call known binary directly (#560)
  * Revert compat behavior and call known binary directly (#559)
  * Build rollforward package to re-enable original agent and disable core plugin (#557)
- from version 20251030.02
  * Add Tyler, Saswat, Hank to OWNERS (#577)
  * Honor core plugin setting on windows package update (#576)
  * Restart agent if core plugin is disabled (#575)
  * Add extra debug logging around toggling OS Login (#572)
  * Update go version to 1.25 (#565)
  * Add compat adapt script to windows in agent sysprep (#569)
  * Fix adapt to use more portable shebang line (#567)
  * Remove routes script from packaging (#566)
  * Update adapt script to run on startup/shutdown both (#561)
  * Update agent_uninstall.ps1 (#558)
  * Stop core plugin before removing agent package (#554)
  * Startup scripts should start after agent manager instead (#553)
  * Update presets and install dependencies on systemd units (#552)
  * Ensure agent service is disabled (#551)
  * Disable legacy agent to enable core plugin (#550)
  * Final fix for RHEL packaging for routes setup (#549)
  * Fix RHEL packaging for routes scripts (#548)
  * Packaging changes to include routes script installation (#542)
  * Update CLI name in packaging (#543)
  * systemd should manage only the main process (#544)
- from version 20251030.01
  * Update agent_uninstall.ps1 (#558) (#580)
  * Update go version for stable branch to 1.25 (#571)
  * Add adapt script in stable branch as per #569 (#570)
  * Backport fix from #567 to stable branch (#568)
  * Revert compat behavior and call known binary directly (#560)
  * Revert compat behavior and call known binary directly (#559)
  * Build rollforward package to re-enable original agent and disable core plugin (#557)
- from version 20251030.00
  * Add Tyler, Saswat, Hank to OWNERS (#577)
  * Honor core plugin setting on windows package update (#576)
  * Restart agent if core plugin is disabled (#575)
  * Add extra debug logging around toggling OS Login (#572)
  * Update go version to 1.25 (#565)
  * Add compat adapt script to windows in agent sysprep (#569)
  * Fix adapt to use more portable shebang line (#567)
  * Remove routes script from packaging (#566)
  * Update adapt script to run on startup/shutdown both (#561)
  * Update agent_uninstall.ps1 (#558)
  * Stop core plugin before removing agent package (#554)
  * Startup scripts should start after agent manager instead (#553)
  * Update presets and install dependencies on systemd units (#552)
  * Ensure agent service is disabled (#551)
  * Disable legacy agent to enable core plugin (#550)
  * Final fix for RHEL packaging for routes setup (#549)
  * Fix RHEL packaging for routes scripts (#548)
  * Packaging changes to include routes script installation (#542)
  * Update CLI name in packaging (#543)
  * systemd should manage only the main process (#544)
- from version 20251011.00
  * Update go version for stable branch to 1.25 (#571)
  * Add adapt script in stable branch as per #569 (#570)
  * Backport fix from #567 to stable branch (#568)
  * Revert compat behavior and call known binary directly (#560)
  * Revert compat behavior and call known binary directly (#559)
  * Build rollforward package to re-enable original agent and disable core plugin (#557)
- from version 20251009.01
  * Add Tyler, Saswat, Hank to OWNERS (#577)
  * Honor core plugin setting on windows package update (#576)
  * Restart agent if core plugin is disabled (#575)
  * Add extra debug logging around toggling OS Login (#572)
  * Update go version to 1.25 (#565)
  * Add compat adapt script to windows in agent sysprep (#569)
  * Fix adapt to use more portable shebang line (#567)
  * Remove routes script from packaging (#566)
  * Update adapt script to run on startup/shutdown both (#561)
  * Update agent_uninstall.ps1 (#558)
  * Stop core plugin before removing agent package (#554)
  * Startup scripts should start after agent manager instead (#553)
  * Update presets and install dependencies on systemd units (#552)
  * Ensure agent service is disabled (#551)
  * Disable legacy agent to enable core plugin (#550)
  * Final fix for RHEL packaging for routes setup (#549)
  * Fix RHEL packaging for routes scripts (#548)
  * Packaging changes to include routes script installation (#542)
  * Update CLI name in packaging (#543)
  * systemd should manage only the main process (#544)
- from version 20251009.00
  * Update go version for stable branch to 1.25 (#571)
  * Add adapt script in stable branch as per #569 (#570)
  * Backport fix from #567 to stable branch (#568)
  * Revert compat behavior and call known binary directly (#560)
  * Revert compat behavior and call known binary directly (#559)
  * Build rollforward package to re-enable original agent and disable core plugin (#557)
- Drop disable_google_guest_agent_manager.patch, fixed upstream

- Update to version 20251007.00
  * Add Tyler, Saswat, Hank to OWNERS (#577)
  * Honor core plugin setting on windows package update (#576)
  * Restart agent if core plugin is disabled (#575)
  * Add extra debug logging around toggling OS Login (#572)
  * Update go version to 1.25 (#565)
  * Add compat adapt script to windows in agent sysprep (#569)
  * Fix adapt to use more portable shebang line (#567)
  * Remove routes script from packaging (#566)
  * Update adapt script to run on startup/shutdown both (#561)
  * Update agent_uninstall.ps1 (#558)
  * Stop core plugin before removing agent package (#554)
  * Startup scripts should start after agent manager instead (#553)
  * Update presets and install dependencies on systemd units (#552)
  * Ensure agent service is disabled (#551)
  * Disable legacy agent to enable core plugin (#550)
  * Final fix for RHEL packaging for routes setup (#549)
  * Fix RHEL packaging for routes scripts (#548)
  * Packaging changes to include routes script installation (#542)
  * Update CLI name in packaging (#543)
  * systemd should manage only the main process (#544)
- from version 20251006.01
  * Update go version for stable branch to 1.25 (#571)
  * Add adapt script in stable branch as per #569 (#570)
  * Backport fix from #567 to stable branch (#568)
  * Revert compat behavior and call known binary directly (#560)
  * Revert compat behavior and call known binary directly (#559)
  * Build rollforward package to re-enable original agent and
    disable core plugin (#557)
- from version 20251006.00
  * Honor core plugin setting on windows package update (#576)
  * Restart agent if core plugin is disabled (#575)
  * Add extra debug logging around toggling OS Login (#572)
  * Update go version to 1.25 (#565)
  * Add compat adapt script to windows in agent sysprep (#569)
  * Fix adapt to use more portable shebang line (#567)
  * Remove routes script from packaging (#566)
  * Update adapt script to run on startup/shutdown both (#561)
  * Update agent_uninstall.ps1 (#558)
  * Stop core plugin before removing agent package (#554)
  * Startup scripts should start after agent manager instead (#553)
  * Update presets and install dependencies on systemd units (#552)
  * Ensure agent service is disabled (#551)
  * Disable legacy agent to enable core plugin (#550)
  * Final fix for RHEL packaging for routes setup (#549)
  * Fix RHEL packaging for routes scripts (#548)
  * Packaging changes to include routes script installation (#542)
  * Update CLI name in packaging (#543)
  * systemd should manage only the main process (#544)
- from version 20251005.00
  * Update go version for stable branch to 1.25 (#571)
  * Add adapt script in stable branch as per #569 (#570)
  * Backport fix from #567 to stable branch (#568)
  * Revert compat behavior and call known binary directly (#560)
  * Revert compat behavior and call known binary directly (#559)
  * Build rollforward package to re-enable original agent and
    disable core plugin (#557)
- from version 20250930.01
  * Honor core plugin setting on windows package update (#576)
- from version 20250929.01
  * Restart agent if core plugin is disabled (#575)
  * Add extra debug logging around toggling OS Login (#572)
  * Update go version to 1.25 (#565)
  * Add compat adapt script to windows in agent sysprep (#569)
  * Fix adapt to use more portable shebang line (#567)
  * Remove routes script from packaging (#566)
  * Update adapt script to run on startup/shutdown both (#561)
  * Update agent_uninstall.ps1 (#558)
  * Stop core plugin before removing agent package (#554)
  * Startup scripts should start after agent manager instead (#553)
  * Update presets and install dependencies on systemd units (#552)
  * Ensure agent service is disabled (#551)
  * Disable legacy agent to enable core plugin (#550)
  * Final fix for RHEL packaging for routes setup (#549)
  * Fix RHEL packaging for routes scripts (#548)
  * Packaging changes to include routes script installation (#542)
  * Update CLI name in packaging (#543)
  * systemd should manage only the main process (#544)
- from version 20250929.00
  * Update go version for stable branch to 1.25 (#571)
  * Add adapt script in stable branch as per #569 (#570)
  * Backport fix from #567 to stable branch (#568)
  * Revert compat behavior and call known binary directly (#560)
  * Revert compat behavior and call known binary directly (#559)
  * Build rollforward package to re-enable original agent and
    disable core plugin (#557)
- from version 20250926.00
  * Add extra debug logging around toggling OS Login (#572)
  * Update go version to 1.25 (#565)
  * Add compat adapt script to windows in agent sysprep (#569)
  * Fix adapt to use more portable shebang line (#567)
  * Remove routes script from packaging (#566)
  * Update adapt script to run on startup/shutdown both (#561)
  * Update agent_uninstall.ps1 (#558)
  * Stop core plugin before removing agent package (#554)
  * Startup scripts should start after agent manager instead (#553)
  * Update presets and install dependencies on systemd units (#552)
  * Ensure agent service is disabled (#551)
  * Disable legacy agent to enable core plugin (#550)
  * Final fix for RHEL packaging for routes setup (#549)
  * Fix RHEL packaging for routes scripts (#548)
  * Packaging changes to include routes script installation (#542)
  * Update CLI name in packaging (#543)
  * systemd should manage only the main process (#544)
- from version 20250924.02
  * Update go version for stable branch to 1.25 (#571)
  * Add adapt script in stable branch as per #569 (#570)
  * Backport fix from #567 to stable branch (#568)
  * Revert compat behavior and call known binary directly (#560)
  * Revert compat behavior and call known binary directly (#559)
  * Build rollforward package to re-enable original agent and
    disable core plugin (#557)
- from version 20250924.01
  * Add extra debug logging around toggling OS Login (#572)
  * Update go version to 1.25 (#565)
  * Add compat adapt script to windows in agent sysprep (#569)
  * Fix adapt to use more portable shebang line (#567)
  * Remove routes script from packaging (#566)
  * Update adapt script to run on startup/shutdown both (#561)
  * Update agent_uninstall.ps1 (#558)
  * Stop core plugin before removing agent package (#554)
  * Startup scripts should start after agent manager instead (#553)
  * Update presets and install dependencies on systemd units (#552)
  * Ensure agent service is disabled (#551)
  * Disable legacy agent to enable core plugin (#550)
  * Final fix for RHEL packaging for routes setup (#549)
  * Fix RHEL packaging for routes scripts (#548)
  * Packaging changes to include routes script installation (#542)
  * Update CLI name in packaging (#543)
  * systemd should manage only the main process (#544)
- from version 20250924.00
  * Update go version for stable branch to 1.25 (#571)
  * Add adapt script in stable branch as per #569 (#570)
  * Backport fix from #567 to stable branch (#568)
  * Revert compat behavior and call known binary directly (#560)
  * Revert compat behavior and call known binary directly (#559)
  * Build rollforward package to re-enable original agent and
    disable core plugin (#557)

- Update to version 20250923.01
  * Add extra debug logging around toggling OS Login (#572)
  * Update go version to 1.25 (#565)
  * Add compat adapt script to windows in agent sysprep (#569)
  * Fix adapt to use more portable shebang line (#567)
  * Remove routes script from packaging (#566)
  * Update adapt script to run on startup/shutdown both (#561)
  * Update agent_uninstall.ps1 (#558)
  * Stop core plugin before removing agent package (#554)
  * Startup scripts should start after agent manager instead (#553)
  * Update presets and install dependencies on systemd units (#552)
  * Ensure agent service is disabled (#551)
  * Disable legacy agent to enable core plugin (#550)
  * Final fix for RHEL packaging for routes setup (#549)
  * Fix RHEL packaging for routes scripts (#548)
  * Packaging changes to include routes script installation (#542)
  * Update CLI name in packaging (#543)
  * systemd should manage only the main process (#544)
- from version 20250923.00
  * Update go version for stable branch to 1.25 (#571)
  * Add adapt script in stable branch as per #569 (#570)
  * Backport fix from #567 to stable branch (#568)
  * Revert compat behavior and call known binary directly (#560)
  * Revert compat behavior and call known binary directly (#559)
  * Build rollforward package to re-enable original agent and disable core plugin (#557)
- from version 20250921.00
  * Add extra debug logging around toggling OS Login (#572)
- from version 20250920.01
  * Update go version to 1.25 (#565)
  * Add compat adapt script to windows in agent sysprep (#569)
  * Fix adapt to use more portable shebang line (#567)
  * Remove routes script from packaging (#566)
  * Update adapt script to run on startup/shutdown both (#561)
  * Update agent_uninstall.ps1 (#558)
  * Stop core plugin before removing agent package (#554)
  * Startup scripts should start after agent manager instead (#553)
  * Update presets and install dependencies on systemd units (#552)
  * Ensure agent service is disabled (#551)
  * Disable legacy agent to enable core plugin (#550)
  * Final fix for RHEL packaging for routes setup (#549)
  * Fix RHEL packaging for routes scripts (#548)
  * Packaging changes to include routes script installation (#542)
  * Update CLI name in packaging (#543)
  * systemd should manage only the main process (#544)
- from version 20250920.00
  * Update go version for stable branch to 1.25 (#571)
  * Add adapt script in stable branch as per #569 (#570)
  * Backport fix from #567 to stable branch (#568)
  * Revert compat behavior and call known binary directly (#560)
  * Revert compat behavior and call known binary directly (#559)
  * Build rollforward package to re-enable original agent and disable core plugin (#557)
- from version 20250918.01
  * Update go version to 1.25 (#565)
  * Add compat adapt script to windows in agent sysprep (#569)
  * Fix adapt to use more portable shebang line (#567)
  * Remove routes script from packaging (#566)
  * Update adapt script to run on startup/shutdown both (#561)
  * Update agent_uninstall.ps1 (#558)
  * Stop core plugin before removing agent package (#554)
  * Startup scripts should start after agent manager instead (#553)
  * Update presets and install dependencies on systemd units (#552)
  * Ensure agent service is disabled (#551)
  * Disable legacy agent to enable core plugin (#550)
  * Final fix for RHEL packaging for routes setup (#549)
  * Fix RHEL packaging for routes scripts (#548)
  * Packaging changes to include routes script installation (#542)
  * Update CLI name in packaging (#543)
  * systemd should manage only the main process (#544)
- from version 20250917.01
  * Update go version for stable branch to 1.25 (#571)
  * Add adapt script in stable branch as per #569 (#570)
  * Backport fix from #567 to stable branch (#568)
  * Revert compat behavior and call known binary directly (#560)
  * Revert compat behavior and call known binary directly (#559)
  * Build rollforward package to re-enable original agent and disable core plugin (#557)
- from version 20250917.00
  * Update go version to 1.25 (#565)
  * Add compat adapt script to windows in agent sysprep (#569)
  * Fix adapt to use more portable shebang line (#567)
  * Remove routes script from packaging (#566)
  * Update adapt script to run on startup/shutdown both (#561)
  * Update agent_uninstall.ps1 (#558)
  * Stop core plugin before removing agent package (#554)
  * Startup scripts should start after agent manager instead (#553)
  * Update presets and install dependencies on systemd units (#552)
  * Ensure agent service is disabled (#551)
  * Disable legacy agent to enable core plugin (#550)
  * Final fix for RHEL packaging for routes setup (#549)
  * Fix RHEL packaging for routes scripts (#548)
  * Packaging changes to include routes script installation (#542)
  * Update CLI name in packaging (#543)
  * systemd should manage only the main process (#544)
- from version 20250916.00
  * Update go version for stable branch to 1.25 (#571)
  * Add adapt script in stable branch as per #569 (#570)
  * Backport fix from #567 to stable branch (#568)
  * Revert compat behavior and call known binary directly (#560)
  * Revert compat behavior and call known binary directly (#559)
  * Build rollforward package to re-enable original agent and disable core plugin (#557)
- from version 20250915.00
  * Update go version to 1.25 (#565)
  * Add compat adapt script to windows in agent sysprep (#569)
  * Fix adapt to use more portable shebang line (#567)
  * Remove routes script from packaging (#566)
  * Update adapt script to run on startup/shutdown both (#561)
  * Update agent_uninstall.ps1 (#558)
  * Stop core plugin before removing agent package (#554)
  * Startup scripts should start after agent manager instead (#553)
  * Update presets and install dependencies on systemd units (#552)
  * Ensure agent service is disabled (#551)
  * Disable legacy agent to enable core plugin (#550)
  * Final fix for RHEL packaging for routes setup (#549)
  * Fix RHEL packaging for routes scripts (#548)
  * Packaging changes to include routes script installation (#542)
  * Update CLI name in packaging (#543)
  * systemd should manage only the main process (#544)
- Add disable_google_guest_agent_manager.patch to disable missing daemon
  google_guest_agent_manager referenced by google-startup-scripts.service

- Update to version 20250908.00
  * Update go version for stable branch to 1.25 (#571)
  * Add adapt script in stable branch as per #569 (#570)
  * Backport fix from #567 to stable branch (#568)
  * Revert compat behavior and call known binary directly (#560)
  * Revert compat behavior and call known binary directly (#559)
  * Build rollforward package to re-enable original agent and
    disable core plugin (#557)
- from version 20250907.00
  * Update go version to 1.25 (#565)
  * Add compat adapt script to windows in agent sysprep (#569)
  * Fix adapt to use more portable shebang line (#567)
  * Remove routes script from packaging (#566)
  * Update adapt script to run on startup/shutdown both (#561)
  * Update agent_uninstall.ps1 (#558)
  * Stop core plugin before removing agent package (#554)
  * Startup scripts should start after agent manager instead (#553)
  * Update presets and install dependencies on systemd units (#552)
  * Ensure agent service is disabled (#551)
  * Disable legacy agent to enable core plugin (#550)
  * Final fix for RHEL packaging for routes setup (#549)
  * Fix RHEL packaging for routes scripts (#548)
  * Packaging changes to include routes script installation (#542)
  * Update CLI name in packaging (#543)
  * systemd should manage only the main process (#544)
- from version 20250905.01
  * Update go version for stable branch to 1.25 (#571)
  * Add adapt script in stable branch as per #569 (#570)
  * Backport fix from #567 to stable branch (#568)
  * Revert compat behavior and call known binary directly (#560)
  * Revert compat behavior and call known binary directly (#559)
  * Build rollforward package to re-enable original agent and
    disable core plugin (#557)
- from version 20250905.00
  * Update go version to 1.25 (#565)
  * Add compat adapt script to windows in agent sysprep (#569)
  * Fix adapt to use more portable shebang line (#567)
  * Remove routes script from packaging (#566)
  * Update adapt script to run on startup/shutdown both (#561)
  * Update agent_uninstall.ps1 (#558)
  * Stop core plugin before removing agent package (#554)
  * Startup scripts should start after agent manager instead (#553)
  * Update presets and install dependencies on systemd units (#552)
  * Ensure agent service is disabled (#551)
  * Disable legacy agent to enable core plugin (#550)
  * Final fix for RHEL packaging for routes setup (#549)
  * Fix RHEL packaging for routes scripts (#548)
  * Packaging changes to include routes script installation (#542)
  * Update CLI name in packaging (#543)
  * systemd should manage only the main process (#544)
- from version 20250902.00
  * Update go version for stable branch to 1.25 (#571)
  * Add adapt script in stable branch as per #569 (#570)
  * Backport fix from #567 to stable branch (#568)
  * Revert compat behavior and call known binary directly (#560)
  * Revert compat behavior and call known binary directly (#559)
  * Build rollforward package to re-enable original agent and
    disable core plugin (#557)
- Build and install new gce_workload_cert_refresh binary
- Fix installation source of google_metadata_script_runner_adapt script
- Install new systemd service file
  * gce-workload-cert-refresh.service

- Update to version 20250901.00
  * Update go version to 1.25 (#565)
  * Add compat adapt script to windows in agent sysprep (#569)
  * Fix adapt to use more portable shebang line (#567)
  * Remove routes script from packaging (#566)
  * Update adapt script to run on startup/shutdown both (#561)
  * Update agent_uninstall.ps1 (#558)
  * Stop core plugin before removing agent package (#554)
  * Startup scripts should start after agent manager instead (#553)
  * Update presets and install dependencies on systemd units (#552)
  * Ensure agent service is disabled (#551)
  * Disable legacy agent to enable core plugin (#550)
  * Final fix for RHEL packaging for routes setup (#549)
  * Fix RHEL packaging for routes scripts (#548)
  * Packaging changes to include routes script installation (#542)
  * Update CLI name in packaging (#543)
  * systemd should manage only the main process (#544)
- from version 20250831.03
  * Update go version for stable branch to 1.25 (#571)
  * Add adapt script in stable branch as per #569 (#570)
  * Backport fix from #567 to stable branch (#568)
  * Revert compat behavior and call known binary directly (#560)
  * Revert compat behavior and call known binary directly (#559)
  * Build rollforward package to re-enable original agent and
    disable core plugin (#557)
- from version 20250831.02
  * Update go version to 1.25 (#565)
  * Add compat adapt script to windows in agent sysprep (#569)
  * Fix adapt to use more portable shebang line (#567)
  * Remove routes script from packaging (#566)
  * Update adapt script to run on startup/shutdown both (#561)
  * Update agent_uninstall.ps1 (#558)
  * Stop core plugin before removing agent package (#554)
  * Startup scripts should start after agent manager instead (#553)
  * Update presets and install dependencies on systemd units (#552)
  * Ensure agent service is disabled (#551)
  * Disable legacy agent to enable core plugin (#550)
  * Final fix for RHEL packaging for routes setup (#549)
  * Fix RHEL packaging for routes scripts (#548)
  * Packaging changes to include routes script installation (#542)
  * Update CLI name in packaging (#543)
  * systemd should manage only the main process (#544)
- from version 20250831.01
  * Update go version for stable branch to 1.25 (#571)
  * Add adapt script in stable branch as per #569 (#570)
  * Backport fix from #567 to stable branch (#568)
  * Revert compat behavior and call known binary directly (#560)
  * Revert compat behavior and call known binary directly (#559)
  * Build rollforward package to re-enable original agent
    and disable core plugin (#557)
- from version 20250831.00
  * Update go version to 1.25 (#565)
  * Add compat adapt script to windows in agent sysprep (#569)
  * Fix adapt to use more portable shebang line (#567)
  * Remove routes script from packaging (#566)
  * Update adapt script to run on startup/shutdown both (#561)
  * Update agent_uninstall.ps1 (#558)
  * Stop core plugin before removing agent package (#554)
  * Startup scripts should start after agent manager instead (#553)
  * Update presets and install dependencies on systemd units (#552)
  * Ensure agent service is disabled (#551)
  * Disable legacy agent to enable core plugin (#550)
  * Final fix for RHEL packaging for routes setup (#549)
  * Fix RHEL packaging for routes scripts (#548)
  * Packaging changes to include routes script installation (#542)
  * Update CLI name in packaging (#543)
  * systemd should manage only the main process (#544)
- from version 20250830.02
  * Update go version for stable branch to 1.25 (#571)
  * Add adapt script in stable branch as per #569 (#570)
  * Backport fix from #567 to stable branch (#568)
  * Revert compat behavior and call known binary directly (#560)
  * Revert compat behavior and call known binary directly (#559)
  * Build rollforward package to re-enable original agent
    and disable core plugin (#557)
- from version 20250830.01
  * Update go version to 1.25 (#565)
- from version 20250830.00
  * Add compat adapt script to windows in agent sysprep (#569)
  * Fix adapt to use more portable shebang line (#567)
  * Remove routes script from packaging (#566)
  * Update adapt script to run on startup/shutdown both (#561)
  * Update agent_uninstall.ps1 (#558)
  * Stop core plugin before removing agent package (#554)
  * Startup scripts should start after agent manager instead (#553)
  * Update presets and install dependencies on systemd units (#552)
  * Ensure agent service is disabled (#551)
  * Disable legacy agent to enable core plugin (#550)
  * Final fix for RHEL packaging for routes setup (#549)
  * Fix RHEL packaging for routes scripts (#548)
  * Packaging changes to include routes script installation (#542)
  * Update CLI name in packaging (#543)
  * systemd should manage only the main process (#544)
- from version 20250828.00
  * Add adapt script in stable branch as per #569 (#570)
  * Backport fix from #567 to stable branch (#568)
- from version 20250826.00
  * Revert compat behavior and call known binary directly (#560)
  * Revert compat behavior and call known binary directly (#559)
  * Build rollforward package to re-enable original agent and
    disable core plugin (#557)
- from version 20250821.01
  * Remove routes script from packaging (#566)
- Drop CVE-2025-22868.patch, merged upstream
- Update Go API version to 1.25

- Update to version 20250718.00
  * Update adapt script to run on startup/shutdown both (#561)
  * Update agent_uninstall.ps1 (#558)
  * Stop core plugin before removing agent package (#554)
  * Startup scripts should start after agent manager instead (#553)
  * Update presets and install dependencies on systemd units (#552)
  * Ensure agent service is disabled (#551)
  * Disable legacy agent to enable core plugin (#550)
  * Final fix for RHEL packaging for routes setup (#549)
  * Fix RHEL packaging for routes scripts (#548)
  * Packaging changes to include routes script installation (#542)
  * Update CLI name in packaging (#543)
  * systemd should manage only the main process (#544)

- Update to version 20250709.02
  * Revert compat behavior and call known binary directly (#560)
  * Revert compat behavior and call known binary directly (#559)
  * Build rollforward package to re-enable original agent and disable core plugin (#557)
- from version 20250709.01
  * Update adapt script to run on startup/shutdown both (#561)
  * Update agent_uninstall.ps1 (#558)
  * Stop core plugin before removing agent package (#554)
  * Startup scripts should start after agent manager instead (#553)
  * Update presets and install dependencies on systemd units (#552)
  * Ensure agent service is disabled (#551)
  * Disable legacy agent to enable core plugin (#550)
  * Final fix for RHEL packaging for routes setup (#549)
  * Fix RHEL packaging for routes scripts (#548)
  * Packaging changes to include routes script installation (#542)
  * Update CLI name in packaging (#543)
  * systemd should manage only the main process (#544)
- from version 20250709.00
  * Revert compat behavior and call known binary directly (#560)
  * Revert compat behavior and call known binary directly (#559)
  * Build rollforward package to re-enable original agent and disable core plugin (#557)
- from version 20250702.00
  * Update adapt script to run on startup/shutdown both (#561)
- from version 20250701.01
  * Update agent_uninstall.ps1 (#558)
- from version 20250701.00
  * Stop core plugin before removing agent package (#554)
- from version 20250628.00
  * Startup scripts should start after agent manager instead (#553)
  * Update presets and install dependencies on systemd units (#552)
  * Ensure agent service is disabled (#551)
- from version 20250626.00
  * Disable legacy agent to enable core plugin (#550)
  * Final fix for RHEL packaging for routes setup (#549)
  * Fix RHEL packaging for routes scripts (#548)
  * Packaging changes to include routes script installation (#542)
  * Update CLI name in packaging (#543)
  * systemd should manage only the main process (#544)
  * startup script: wrap compatibility decision into its own scripts (#538)
  * Reapply "oslogin: Correctly handle newlines at the end of modified files (#520)" (#523) (#540)
- from version 20250625.00
  * prepare stable release.
- Install google_metadata_script_runner_adapt script (bsc#1245759)

- Update to version 20250624.00
  * Final fix for RHEL packaging for routes setup (#549)
  * Fix RHEL packaging for routes scripts (#548)
  * Packaging changes to include routes script installation (#542)
  * Update CLI name in packaging (#543)
  * systemd should manage only the main process (#544)
  * startup script: wrap compatibility decision into its own scripts (#538)
  * Reapply "oslogin: Correctly handle newlines at the end of modified
    files (#520)" (#523) (#540)
- from version 20250611.01
  * prepare stable release.
- from version 20250611.00
  * startup script: wrap compatibility decision into its own scripts (#538)
  * Reapply "oslogin: Correctly handle newlines at the end of modified
    files (#520)" (#523) (#540)
- from version 20250609.00
  * prepare stable release.
- from version 20250605.00
  * startup script: wrap compatibility decision into its own scripts (#538)
  * Reapply "oslogin: Correctly handle newlines at the end of modified
    files (#520)" (#523) (#540)
  * Make sure agent added connections are activated by NM (#534)
  * wrap NSS cache refresh in a goroutine (#533)
  * Wicked: Only reload interfaces for which configurations are
    written or changed. (#524)
  * Add AuthorizedKeysCompat to windows packaging (#530)
  * Remove error messages from gce_workload_cert_refresh and metadata
    script runner (#527)
  * Update guest-logging-go dependency (#526)
  * Add 'created-by' metadata, and pass it as option to logging library (#508)
  * Revert "oslogin: Correctly handle newlines at the end of
    modified files (#520)" (#523)
  * Re-enable disabled services if the core plugin was enabled (#522)
  * Enable guest services on package upgrade (#519)
  * oslogin: Correctly handle newlines at the end of modified files (#520)
  * Fix core plugin path (#518)
  * Fix package build issues (#517)
  * Fix dependencies ran go mod tidy -v (#515)
  * Fix debian build path (#514)
  * Bundle compat metadata script runner binary in package (#513)
  * Bump golang.org/x/net from 0.27.0 to 0.36.0 (#512)
  * Update startup/shutdown services to launch compat manager (#503)
  * Bundle new gce metadata script runner binary in agent package (#502)
  * Revert "Revert bundling new binaries in the package (#509)" (#511)

- Update to version 20250604.00
  * Preparing stable build.
- from version 20250602.00
  * Make sure agent added connections are activated by NM (#534)
  * wrap NSS cache refresh in a goroutine (#533)
  * Wicked: Only reload interfaces for which configurations are written or changed. (#524)
  * Add AuthorizedKeysCompat to windows packaging (#530)
  * Remove error messages from gce_workload_cert_refresh and metadata script runner (#527)
  * Update guest-logging-go dependency (#526)
  * Add 'created-by' metadata, and pass it as option to logging library (#508)
  * Revert "oslogin: Correctly handle newlines at the end of modified files (#520)" (#523)
  * Re-enable disabled services if the core plugin was enabled (#522)
  * Enable guest services on package upgrade (#519)
  * oslogin: Correctly handle newlines at the end of modified files (#520)
  * Fix core plugin path (#518)
  * Fix package build issues (#517)
  * Fix dependencies ran go mod tidy -v (#515)
  * Fix debian build path (#514)
  * Bundle compat metadata script runner binary in package (#513)
  * Bump golang.org/x/net from 0.27.0 to 0.36.0 (#512)
  * Update startup/shutdown services to launch compat manager (#503)
  * Bundle new gce metadata script runner binary in agent package (#502)
  * Revert "Revert bundling new binaries in the package (#509)" (#511)
- from version 20250521.00
  * Preparing stable build.
- from version 20250515.00
  * Make sure agent added connections are activated by NM (#534)
  * wrap NSS cache refresh in a goroutine (#533)
  * Wicked: Only reload interfaces for which configurations are written or changed. (#524)
  * Add AuthorizedKeysCompat to windows packaging (#530)
  * Remove error messages from gce_workload_cert_refresh and metadata script runner (#527)
  * Update guest-logging-go dependency (#526)
  * Add 'created-by' metadata, and pass it as option to logging library (#508)
  * Revert "oslogin: Correctly handle newlines at the end of modified files (#520)" (#523)
  * Re-enable disabled services if the core plugin was enabled (#522)
  * Enable guest services on package upgrade (#519)
  * oslogin: Correctly handle newlines at the end of modified files (#520)
  * Fix core plugin path (#518)
  * Fix package build issues (#517)
  * Fix dependencies ran go mod tidy -v (#515)
  * Fix debian build path (#514)
  * Bundle compat metadata script runner binary in package (#513)
  * Bump golang.org/x/net from 0.27.0 to 0.36.0 (#512)
  * Update startup/shutdown services to launch compat manager (#503)
  * Bundle new gce metadata script runner binary in agent package (#502)
  * Revert "Revert bundling new binaries in the package (#509)" (#511)
google-osconfig-agent
- Packaging improvements:
  * Remove define github project name components no longer needed
  * Define shortname corresponding to binary name when different
    from package name. Use shortname where applicable to normalize
    common lines across Go app packages, similar to name macro.
  * Drop BuildRequires: golang-packaging. The original macros for
    file movements into GOPATH are obsolete with Go modules. Macro
    go_nostrip is no longer needed with current binutils and Go.
  * Remove go_nostrip macro which is no longer recommended
  * Re-enable binary stripping and debuginfo boo#1210938
  * Remove goprep macro which is no longer recommended
  * Build PIE with pattern that may become recommended procedure:
    %%ifnarch ppc64 GOFLAGS="-buildmode=pie" %%endif go build
    A go toolchain buildmode default config would be preferable
    but none exist at this time.
  * Drop export CGO_ENABLED="0". Use the default unless there is a
    defined requirement or benefit.
  * For this package, we were seeing the expected error
    "-buildmode=pie requires external (cgo) linking, but cgo is not
    enabled" when using buildmode=pie and CGO_ENABLED=0. The error
    manifested only on s390x and i586 architectures, which was not
    expected. Resolve by using default CGO_ENABLED.
  * Remove ldflags -s (Omit symbol table and debug info) and -w
    (Omit DWARF symbol table). This information is used to produce
    separate debuginfo packages and binaries are stripped for
    reduced size by GNU strip during RPM build.
  * Remove ldflags -X entry for embedding build version metadata.
    This information is embedded in binaries with go1.18+ and
    available via go version -m or runtime/debug.ReadBuildInfo().
  * Drop mod=vendor, go1.14+ will detect vendor dir and auto-enable
  * Raise minimum golang API version to 1.25.5 to match go.mod file
  * Use explicit upstream GitHub homepage in URL field
  * Use single invocation of %setup with -a1 to unpack both tarballs

- Update to version 20260615.01
  * Upgrade golang.org/x/crypto & golang.org/x/net (#1006)
    (bsc#1266171, CVE-2026-39827, CVE-2026-39834, CVE-2026-39828,
    CVE-2026-39829, CVE-2026-39831, CVE-2026-42508, CVE-2026-39833,
    CVE-2026-39830, CVE-2026-39832, CVE-2026-46597, CVE-2026-46598,
    CVE-2026-46595, CVE-2026-39835) (bsc#1266603, CVE-2026-39821)
- from version 20260615.00
  * Add unit tests for ospatch_apt_upgrade.go (#938)

- Update to version 20260611.00
  * Add unit tests for policies/policies.go PART 5 (#998)
- from version 20260610.00
  * Add unit tests for policies/policies.go PART 4 (#997)
- from version 20260609.02
  * squash commits (#936)
- from version 20260609.01
  * Add unit tests for policies/policies.go PART 3 (#996)
- from version 20260609.00
  * Add unit tests for policies/policies.go PART 2 (#991)
- from version 20260602.01
  * Align format of dates and timestamp collected across Windows packages (#973)
- from version 20260602.00
  * Add unit tests for config/config,go (#979)
- from version 20260528.00
  * Bump github.com/containerd/containerd (#990)
- from version 20260521.00
  * Cover agentconfig functionality by unit tests (#925)
- from version 20260520.04
  * Add unit tests for policies/googet.go (#961)
  * Bump github.com/go-git/go-git/v5 (#987)
- from version 20260520.02
  * Add unit tests for policies/yum.go (#952)
  * Add unit tests for policies/apt.go PART 3 (#951)
- from version 20260520.00
  * Add unit tests for policies/zypper.go (#953)
- from version 20260519.00
  * Add unit tests for policies/policies.go PART 1 (#949)
- from version 20260513.01
  * Bump github.com/go-git/go-git/v5 (#981), this also updates
    golang.org/x/net to v0.53.0 (bsc#1265762, CVE-2026-33814)
- from version 20260513.00
  * upgrade a few packages (#980)
- from version 20260512.02
  * Add/improve unit tests for agentendpoint/exec_task.go (#933)
- from version 20260512.01
  * Cover google_update.go by unit tests (#941)
- from version 20260512.00
  * Change zone for arm64 builds because of stockout (#978)

- Add CVE-2026-33186.patch to fix authorization bypass in grpc-go due to improper
  validation of the HTTP/2 :path pseudo-header (bsc#1260264, CVE-2026-33186)

- Update to version 20260511.00
  * switch to t2a-standard-2 on ARM package build (#977)
- from version 20260505.03
  * Cover zypper_patch by unit tests (#958)
- from version 20260505.02
  * Remove unused functions DisableAutoUpdates (#970)
- from version 20260505.01
  * Bump go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc (#966)
- from version 20260505.00
  * Upgrade a few dependencies across the repo (#968)
    + github.com/go-git/go-git/v5 5.16.2->5.18.0 (bsc#1264923, CVE-2026-41506)
    + github.com/go-jose/go-jose/v4 4.1.3->4.1.4 (bsc#1262926, CVE-2026-34986)
    + github.com/go-viper/mapstructure/v2 2.3.0->2.4.0
    + go.opentelemetry.io/otel 1.40.0->1.41.0
    + go.opentelemetry.io/otel/sdk 1.39.0->1.43.0
- from version 20260504.01
  * bump github.com/docker/cli to 29.2.0 (#962)
- from version 20260504.00
  * Bump github.com/opencontainers/selinux (#960)
- Add missing CVE reference to previous changelog entry
- Drop CVE-2026-34986.patch, merged upstream

- Update to version 20260428.00
  * Add/improve unit tests for agentendpoint/agentendpoint.go (#930)
- from version 20260427.03
  * Cover config/file.go by unit tests (#935)
- from version 20260422.01
  * Cover patch_linux.go by unit tests (#932)
- from version 20260422.00
  * upgrade grpc package in main package and e2e tests (#959)
    (bsc#1260264, CVE-2026-33186)
- from version 20260417.04
  * Bump OSV-Scalibr version to v0.4.3 (#956)
- from version 20260417.03
  * Add unit tests for updates_linux.go (#937)
- from version 20260417.02
  * Add zone to CreateDisk step (#955)
- from version 20260417.01
  * Change disk type for deb11 (#954)
- from version 20260417.00
  * Add unit tests for policies/apt.go PART 1 (#950)
- from version 20260410.02
  * Add unit tests for packages/pty_linux.go (#943)
- from version 20260410.01
  * fix disk type for arm workflows (#948)
- from version 20260410.00
  * Change machine type for arm based workflows (#946)
- Drop CVE-2026-33186.patch, merged upstream

- Add CVE-2026-34986.patch to fix crafted JWE input with a missing encrypted
  key can lead to a denial of service (bsc#1262926, CVE-2026-34986)

- Update to version 20260330.00
  * bump timeouts for all workflows (#940)
- from version 20260326.00
  * Cover exec_resource.go by unit tests (#934)
- from version 20260318.00
  * Integrate OSConfig agent with ReportVmInventory (#923)
- from version 20260313.02
  * remove cacheonly flag from yum upgrade (#924)
- from version 20260313.01
  * conditions python version override (#927)
- from version 20260313.00
  * Fix presubmits by explicitly set python version for rpm based systems (#926)
- from version 20260311.00
  * Bump osconfig version (#922)
- from version 20260309.02
  * Extend OSV scalibr extractor (#921)
- from version 20260309.01
  * upgrade golang.org/x/crypto and it's transitive deps (#918)
- from version 20260309.00
  * Add purl to pkg info (#920)
- from version 20260306.00
  * Add 'Type' field to PkgInfo (#919)
- from version 20260303.01
  * Upgrade go.opentelemetry.io/otel/sdk (#913)
- from version 20260303.00
  * Bump github.com/vbatts/tar-split from 0.11.5 to 0.12.2 (#908)
- from version 20260302.00
  * Bump github.com/spdx/tools-golang from 0.5.3 to 0.5.7 (#906)
- from version 20260126.00
  * Bump go.opentelemetry.io/otel/sdk from 1.38.0 to 1.39.0 (#905)
  * Bump github.com/sirupsen/logrus (#894)

- Update to version 20260119.00
  * Bump cloud.google.com/go/storage from 1.56.0 to 1.58.0 (#899)
- Add missing Bugzilla and CVE references for CVE-2023-45288
- Drop CVE-2025-47911.patch, fixed upstream
- Drop CVE-2025-58190.patch, fixed upstream

- Update to version 20251230.00
  * chore: Migrate gsutil usage to gcloud storage (#904)
- from version 20251223.00
  * fix e2e tests for report inventory (#903)
- from version 20251222.01
  * Revert "Bump cloud.google.com/go/longrunning from 0.6.3 to 0.7.0 (#882)" (#902)
- from version 20251222.00
  * Bump golang to the new version (#900)
- from version 20251218.00
  * add new CODEOWNERS (#901)
- from version 20251217.00
  * Bump cloud.google.com/go/longrunning from 0.6.3 to 0.7.0 (#882)
- Bump the golang compiler version to 1.24.5

- Update to version 20251202.00
  * Revert "Bump github.com/spdx/tools-golang from 0.5.3 to 0.5.5 (#887)" (#893)

- Update to version 20251201.00
  * Revert "Bump github.com/containerd/containerd (#890)" (#892)

- Update to version 20251126.00
  * Bump github.com/containerd/containerd (#890)
  * Bump github.com/spdx/tools-golang from 0.5.3 to 0.5.5 (#887)

- Update to version 20251028.00
  * Bump go.opentelemetry.io/otel/sdk/metric from 1.35.0 to 1.38.0 (#886)
  * Bump github.com/tidwall/pretty from 1.2.0 to 1.2.1 (#880)
- from version 20251023.02
  * Create multiple_os.yaml (#883)
- from version 20251023.00
  * Bump github.com/docker/go-connections from 0.4.0 to 0.6.0 (#877)
  * Add test runner for e2e tests (#876)
- Reword previous changelog entry so that the added patches are accepted

- Update to version 20250925.00
  * Bump cloud.google.com/go/auth/oauth2adapt from 0.2.7 to 0.2.8 (#870)
  * Bump google.golang.org/protobuf from 1.36.6 to 1.36.9 (#874)
  * Bump go.opentelemetry.io/otel from 1.35.0 to 1.38.0 (#872)
  * Bump github.com/golang/glog from 1.2.4 to 1.2.5 (#830)

- Add CVE-2025-47911.patch to fix an issue in the HTML parser where a large
  number of open elements can cause the parser to become extremely slow by
  limiting the stack size of open elements (bsc#1251453, CVE-2025-47911)
- Add CVE-2025-58190.patch to fix an issue in the HTML parser where a specific
  HTML document can cause the parser to enter an infinite loop when trying
  to parse a </tbody> and implied </tr> next to each other.
  (bsc#1251704, CVE-2025-58190)

- Update to version 20250902.01
  * Bump github.com/googleapis/enterprise-certificate-proxy (#829)
- from version 20250902.00
  * update github.com/go-jose/go-jose/v4 (#869)
  * Upgrade scalibr and other deps (#866)
- from version 20250901.00
  * Fix possibility of path traversal for zip and tar archival (#868)
- from version 20250825.00
  * set CODEOWNERS file as required by org (#863)
- from version 20250819.00
  * Fix/rhel10 build centos image (#860)
- from version 20250814.00
  * Fix/rhel10 build image (#859)
- from version 20250813.00
  * Fix: Add RHEL 10 support to RPM startup script (#858)
- from version 20250811.00
  * Remove old/sles-15-sp4-sap as image is deprecated (#857)

- Update to version 20250806.00
  * Fixed JSON identifier for the universe domain (#855)
- from version 20250729.00
  * Bump github.com/google/s2a-go from 0.1.8 to 0.1.9 (#828)
- from version 20250725.02
  * Update utils.go (#854)
  * Upgrade golang.org/x/oauth2 package to the latest. (#853)
  * Bump golang.org/x/time from 0.9.0 to 0.12.0 (#839)
- from version 20250725.01
  * Bump golang.org/x/oauth2 (#848)
  * Port fix for debian 11 to goo package manager. (#852)
- from version 20250725.00
  * Update Golang version in common.sh and skip backports
    repo for debian 11 (#850)
- from version 20250723.01
  * Add workflows to build package for el10 (#849)
- from version 20250721.00
  * Make OS Config agent TPC aware (#846)
- from version 20250718.00
  * Create workflows for new Debian 13. (#847)
- Drop CVE-2025-22868.patch, merged upstream

- Update to version 20250703.00
  * Fix sles images (#844)
- from version 20250702.00
  * Remove rhel-sap 8-4 add rhel-sap 8-10 (#843)
- from version 20250701.00
  * Bump the go_modules group across 1 directory with 2 updates (#840)

- Update to version 20250606.00
  * Change base docker images Google's official base images. (#838)
iproute2
- add CVE fix (CVE-2024-58251 bsc#1254324)
  * ss-escape-characters-in-command-name.patch

- support display of bound but unconnected sockets (bsc#1204562)
  * ss-Add-support-for-dumping-TCP-bound-inactive-socket.patch
kernel-default
- crypto: ccp: Don't attempt to copy ID to userspace if PSP
  command failed (bsc#1264116 CVE-2026-31697).
- crypto: ccp: Don't attempt to copy PDH cert to userspace if
  PSP command failed (bsc#1263880 CVE-2026-31698).
- crypto: ccp: Don't attempt to copy CSR to userspace if PSP
  command failed (bsc#1263879 CVE-2026-31699).
- commit d5c5a29

- io_uring/kbuf: check if target buffer list is still legacy on
  recycle (CVE-2026-43366 bsc#1265116).
- commit abdd276

- xfrm: defensively unhash xfrm_state lists in __xfrm_state_delete (CVE-2026-46116 bsc#1267369)
- commit 2de5e93

- crypto: algif_aead - Fix minimum RX size check for decryption
  (CVE-2026-43077 bsc#1264470).
- commit 3c6f0bc

- ibmveth: Disable GSO for packets with small MSS (CVE-2026-46273
  bsc#1267651 bsc#1265211).
- commit 7b8d62c

- netfilter: nf_tables: release flowtable after rcu grace period
  on error (CVE-2026-23392 bsc#1260531).
- commit a113750

- ip6_gre: Use cached t->net in ip6erspan_changelink() (CVE-2026-46120 bsc#1267640)
- commit 9355ea4

- sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (CVE-2026-46227 bsc#1267697)
- commit 9f23ae6

- Bluetooth: btintel: serialize btintel_hw_error() with
  hci_req_sync_lock (CVE-2026-31500 bsc#1262993).
- commit 3f9d46a

- kabi: revert kabi breaking changes from bsc#1264610 fix
  (CVE-2026-43198 bsc#1264610).
- tcp: fix potential race in tcp_v6_syn_recv_sock()
  (CVE-2026-43198 bsc#1264610).
- commit e76ef72

- Bluetooth: virtio_bt: clamp rx length before skb_put
  (CVE-2026-46123 bsc#1267621).
- commit cd81331

- media: mc, v4l2: serialize REINIT and REQBUFS with
  req_queue_mutex (CVE-2026-31473 bsc#1262663).
- commit 02e769f

- ipv4: icmp: validate reply type before using icmp_pointers
  (CVE-2026-46037 bsc#1267361).
- commit 1875083

- fanotify: fix false positive on permission events (bsc#1267387
  CVE-2026-46150).
- commit 06e4d33

- usb: ulpi: fix memory leak on ulpi_register() error paths
  (CVE-2026-31759 bsc#1264076).
- commit b80df76

- usb: ulpi: fix double free in ulpi_register_interface() error
  path (CVE-2026-31759 bsc#1264076).
- commit 45a646c

- arm64: errata: Mitigate TLBI errata on various Arm CPUs (bsc#1266290 CVE-2025-10263)
  Enable workaround for this CVE.
  Drop all new CPU models which where not existing at the time of v5.14.
- commit ec74444

- scsi: imm: Fix use-after-free bug caused by unfinished delayed
  work (CVE-2025-68324 bsc#1255416).
- commit 3b35bd6

- Update
  patches.suse/net-skbuff-propagate-shared-frag-marker-through-frag-trans.patch
  (CVE-2026-43503 bsc#1265960).
- commit 141f017

- packaging: Add nvidia kernel description
- commit 5f2699f

- bpf: Fix bpf_xdp_store_bytes proto for read-only arg
  (CVE-2026-45886 bsc#1266810).
- commit 8d2da5e

- btrfs: fix btrfs_ioctl_space_info() slot_count TOCTOU which
  can lead  to info-leak (bsc#1267652,CVE-2026-46159).
- commit 5b52ada

- gfs2: Fix use-after-free in iomap inline data write path
  (CVE-2026-45984 bsc#1267214).
- gfs2: Add metapath_dibh helper (CVE-2026-45984 bsc#1267214).
- gfs2: Move the inode glock locking to gfs2_file_buffered_write
  (CVE-2026-45984 bsc#1267214).
- commit 329df60

- rpm/mkspec: Conditionally set Rust BuildReqs (bsc#1258538)
  This is a further optimization of kernel packaging rust-enablement.
  Add the check of CONFIG_RUST at creating the spec for each kernel
  flavor, and set BuildRequires conditionally only for archs that have
  CONFIG_RUST.  This avoids the unnecessary dependency chains due to
  unused rust.
  The main knob ENABLE_RUST is still needed because otherwise we can't
  know whether to pass the dummy-tools or not at processing
  run_oldconfig.
- commit ccf4b93

- rpm/check-for-config-changes: ignore Rust-related configs (bsc#1258538)
  Those configs may be dynamically changed at the build time
- commit 5251980

- rpm: Add BuildRequires for Rust enablement (bsc#1258538)
  Update mkspec and template to generate the spec files with
  BuildRequires of Rust-related packages when ENABLE_RUST=Yes is set in
  rpm/config.sh.
- commit d0f276f

- bonding: alb: fix UAF in rlb_arp_recv during bond up/down
  (CVE-2026-45970 bsc#1267205).
- commit 99e9810

- thermal: core: Fix thermal zone governor cleanup issues
  (CVE-2026-46021 bsc#1267220).
- commit 8a0a43b

- arm64: tlb: Optimize ARM64_WORKAROUND_REPEAT_TLBI (git-fixes)
- commit 5565461

- arm64: tlb: Allow XZR argument to TLBI ops (git-fixes)
- commit b280f12

- KVM: x86: Fix shadow paging use-after-free due to unexpected
  GFN (CVE-2026-46113 bsc#1266969).
- commit ed60983

- KVM: x86/mmu: Add helper to convert SPTE value to its shadow
  page (CVE-2026-46113 bsc#1266969).
- commit f4850cb

- media: dvb-net: fix OOB access in ULE extension header tables (CVE-2026-31405 bsc#1261700)
- commit c1417e1

- usb: usbtmc: Flush anchored URBs in usbtmc_release (CVE-2026-31758 bsc#1264093)
- commit c03e48d
libarchive
- Fix CVE-2026-4424, 257-byte heap memory leak when processing a 170-byte RAR3
  (CVE-2026-4424, bsc#1259928)
  * CVE-2026-4424.patch
- Fix CVE-2026-4426, undefined behavior due to unvalidated operand in shift expression of the zisofs decompression code 3.8.1 in function apply_substitution in file tar/subst.c
  (CVE-2026-4426, bsc#1259931)
  * CVE-2026-4426.patch
- Fix CVE-2026-4111, logical deadlock the RAR5 filter subsystem and the half-window output limiter leads to infinite loop and DoS
  (CVE-2026-4111, bsc#1259635)
  * CVE-2026-4111.patch
- Fix CVE-2026-5121, missing validation check for pz_log2_bs can a heap buffer overflow write
  (CVE-2026-5121, bsc#1261186)
  * CVE-2026-5121.patch
- Fix CVE-2025-60753, An issue was discovered in libarchive bsdtar before version 3.8.1 in function apply_substitution in file tar/subst.c when processing crafted -s substitution rules
  (CVE-2025-60753, bsc#1253088)
  * CVE-2025-60753.patch
mozilla-nss
- update to NSS 3.112.5
  * bmo#2033783 - reject DTLS 1.3 Server Hello after HVR without capping ss->vrange.max.
  * bmo#2034185 - update to version 2.84 of builtins module.

- Added "Suggests: p11-kit-nss-trust" to favor over mozilla-nss-certs
    (Jira: PED-15633)
libsolv
- fix solv_chksum_free segfault when called with a NULL pointer
- bump version to 0.7.39

- made repo_add_solv more robust against corrupt files
  [bsc#1265935] [CVE-2026-9149]
- fix potential buffer overflow when verifying EdDSA signatures
  [bsc#1266039] [CVE-2026-48863]
- added limit checks in multiple places to catch overflows
- reduce the size of the language id cache
- fixed Debian canon selection
- fixed dbpath detection in repo_rpmdb_librpm
- reduced stack usage in repo page compression (needed for musl)
- bump version to 0.7.38

- fix parsing of sha512 checksums in debian repositories
  [bsc#1265938] [CVE-2026-9150]
- improve speed of dirpool_add_dir makeing parsing of filelists.xml
  twice as fast
- fix parsing of recommends in the old Mandriva synthesis format
- bump version to 0.7.37

- respect the "default" attribute in environment optionlist in
  the comps parser
- support suse namespace deps in boolean dependencies [bsc#1258193]
- support for the Elbrus2000 (e2k) architecture
- support language() suse namespace rewriting
- bump version to 0.7.36

- fixed rare crash in the handling of allowuninstall in combination
  with forcebest updates
- new pool_satisfieddep_map feature to test if a set of packages
  satisfies a dependency
- bump version to 0.7.35
sqlite3
- Sync version 3.53.2 from Factory:
  * bsc#1268013, CVE-2026-11824: heap-based buffer overflow
    vulnerability in the FTS5 full-text search extension.
  * bsc#1268012, CVE-2026-11822: memory corruption vulnerabilities
    in the FTS5 full-text search extension.
libzypp
- A .repo files "path=" entry must not refer to a location
  outside the repo (bsc#1267874, CVE-2026-44942)
  A "path=" entry may solely denote a sub-directory of the baseurl
  where the metadata are located. A relative path trying to access
  data outside the baseurl is reported and sanitized.
- version 17.38.13 (35)

- Repo "keyhint" must denote a filename, no path (bsc#1267426,
  CVE-2026-44941)
- version 17.38.12 (35)

- Fix potential crash on malformed or malicious repository
  metadata (fixes #740)
- version 17.38.11 (35)

- Repo metadata: discard entries referring to a location outside
  the repo (bsc#1259802, CVE-2026-25707)
  Mirroring those data locally would refer to a location outside
  the repo's local cache directory. Those data entries are reported
  and discarded.
- zypp.conf: Allow [env] section to add environment variables.
  This feature is designed to enable environment-specific settings
  or debugging options over an extended period. See zypp.conf(5).
- version 17.38.10 (35)

- Prevent configured scripts from escaping the sigcheck directory
  (bsc#1265223, CVE-2026-44933)
- StringV: guard hasPrefix/hasPrefixCI against reading past the
  view end (fixes #735)
- version 17.38.9 (35)

- Mandatory signature verification plugin support (PED#11922)
- version 17.38.8 (35)

- Fix purge-kernel -rc kernel handling (bsc#1239718)
- Explicitly_set_pool_DISTTYPE_RPM (fixes #726)
- version 17.38.7 (35)

- Check for trusted key updates when updating the general keyring
  (bsc#1259706)
- Support multiple MirroredOrigin authorities (bsc#1253193)
- Workaround doxygen bug: doxygen/doxygen#12057
- libzypp.spec: Add missing graphviz-gd BuildRequires (boo#1259842)
- version 17.38.6 (35)

- Fix preloader not caching packages from arch specific subrepos
  (bsc#1253740)
- Deprioritize invalid mirrors (fixes openSUSE/zypper#636)
- version 17.38.5 (35)

- Fix Product::referencePackage lookup (bsc#1259311)
  Use a provided autoproduct() as hint to the package name of the
  release package. It might be that not just multiple versions of
  the same release package provide the same product version, but
  also different release packages.
- version 17.38.4 (35)

- specfile: on fedora use %{_prefix}/share as zyppconfdir if
  %{_distconfdir} is undefined (fixes #693)
  This will set '-DZYPPCONFDIR=%{zyppconfdir}' for cmake.
- Fall back to a writable location when precaching packages
  without root (bsc#1247948)
- version 17.38.3 (35)

- Prepare a legacy /etc/zypp/zypp.conf to be installed on old distros.
  See the ZYPP.CONF(5) man page for details.
- Fix runtime check for broken rpm --runposttrans (bsc#1257068)
- version 17.38.2 (35)

- Avoid libcurl-mini4 when building as it does not support ftp
  protocol.
- Translation: updated .pot file.
- version 17.38.1 (35)

- zypp.conf: follow the UAPI configuration file specification
  (PED-14658)
  In short terms it means we will no longer ship an
  /etc/zypp/zypp.conf, but store our own defaults in
  /usr/etc/zypp/zypp.conf. The systems administrator may choose to
  keep a full copy in /etc/zypp/zypp.conf ignoring our config file
  settings completely, or - the preferred way - to overwrite
  specific settings via /etc/zypp/zypp.conf.d/*.conf overlay files.
  See the ZYPP.CONF(5) man page for details.
- cmake: correctly detect rpm6 (fixes #689)
- Use 'zypp.tmp' as temp directory component to ease setting up
  SELinux policies (bsc#1249435)
- zyppng: Update Provider to current MediaCurl2 download
  approach, drop Metalink ( fixes #682 )
- version 17.38.0 (35)
000release-packages:sle-module-basesystem-release
n/a
000release-packages:sle-module-containers-release
n/a
000release-packages:sle-module-desktop-applications-release
n/a
000release-packages:sle-module-development-tools-release
n/a
000release-packages:sle-module-public-cloud-release
n/a
000release-packages:sle-module-python3-release
n/a
000release-packages:sle-module-server-applications-release
n/a
000release-packages:sle-module-web-scripting-release
n/a
tar
- Fix CVE-2026-5704.patch causing errors when extracting certain archives
  generated by rpm2archive which contain hard links
- Refresh fix-dereference.patch

- Fix tar changing dir permissions temporarily even when using --no-overwrite-dir
  * no-overwrite-dir-fix.patch
- Fix CVE-2026-5704, crafted archives can be used to to hide file injection
  (bsc#1261900)
  * CVE-2026-5704.patch
- Fix --dereference/-h not working properly after CVE-2025-45582 fix (bsc#1265450)
  * fix-dereference.patch
- Fix extraction failure for paths like "a/./b" caused by the gnulib openat2
  implementation (bsc#1267189)
  * openat2-fix-dotlike-failure.patch
zypper
- Transactional systems: Delegate rw-commands to
  transactional-wrapper if available (jsc#PED-13680, jsc#PED-15607)
  On a transactional system where the root filesystem is mounted
  read-only, zypper commands that modify the system cannot be
  executed directly.
  If the system provides a transactional-wrapper utility, zypper
  will automatically attempt to invoke it. The wrapper
  transparently executes the zypper command within a new, writable
  snapshot and manages the lifecycle of that snapshot based on the
  command's exit status.
  On transactional systems lacking a transactional-wrapper, users
  must manually invoke specialized tools -such as
  transactional-update- to install, update, or remove software.
- version 1.14.98

- Add --filter-version-change to zypper lu.
  Adds filtering by version change significance to reduce noise in
  update listings. Supports levels: rebuild (hides rebuild-only
  changes) and package (hides all release-only changes).
- version 1.14.97

- Autorefresh ris-services the way as plugin-services (bsc#1246504)
  It's actually wrong to treat service refreshes different
  depending on the service type. For the purpose of a service it
  makes no difference how the data about the repos to use are
  acquired.
- version 1.14.96

- Report download progress for command line rpms (fixes #613)
- Hint to '-vv ref' to see the mirrors used to download the
  metadata (bsc#1257882)
- Service: Allow "zypper ls SERVICE ..." to test whether a
  service with this alias is defined (bsc#1252744)
  The command prints an abstract of all services passed on the
  command line. It returns 3-ZYPPER_EXIT_ERR_INVALID_ARGS if some
  argument does not name an existing service.
- Keep repo data when updating the service settings (bsc#1252744)
- info: Enhance pattern content table (bsc#1158038)
  Alternatives (multiple packages providing the same requirement)
  are now listed as a single entry in the content table. The entry
  shows either the installed package which satisfies the
  requirement or the requirement itself as type 'Provides'.
  Listing all potential alternatives was miss leading, especially
  if the alternatives were mutual exclusive. It looked like an
  installed pattern had not-installed requirements and it was not
  possible to install all requirements at the same time.
- version 1.14.95