SUSE-SU-2019:2562-1: moderate: Security update for ansible1, ardana-ansible, ardana-cluster, ardana-db, ardana-extensions-nsx, ardana-glance, ardana-input-model, ardana-installer-ui, ardana-manila, ardana-monasca, ardana-neutron, ardana-nova, ardana-octavia, ardana-opsconsole-ui, ardana-osconfig, ardana-service, ardana-tls, crowbar-core, crowbar-ha, crowbar-openstack, crowbar-ui, grafana, novnc, openstack-cinder, openstack-dashboard, openstack-designate, openstack-glance, openstack-heat, openstack-horizon-plugin-heat-ui, openstack-horizon-plugin-monasca-ui, openstack-ironic, openstack-ironic-python-agent, openstack-keystone, openstack-manila, openstack-neutron, openstack-neutron-gbp, openstack-nova, openstack-octavia, openstack-sahara, openstack-tempest, openstack-watcher, python-ardana-configurationprocessor, python-cinder-tempest-plugin, python-urllib3, rubygem-easy_diff

sle-security-updates at lists.suse.com sle-security-updates at lists.suse.com
Fri Oct 4 10:16:34 MDT 2019


   SUSE Security Update: Security update for ansible1, ardana-ansible, ardana-cluster, ardana-db, ardana-extensions-nsx, ardana-glance, ardana-input-model, ardana-installer-ui, ardana-manila, ardana-monasca, ardana-neutron, ardana-nova, ardana-octavia, ardana-opsconsole-ui, ardana-osconfig, ardana-service, ardana-tls, crowbar-core, crowbar-ha, crowbar-openstack, crowbar-ui, grafana, novnc, openstack-cinder, openstack-dashboard, openstack-designate, openstack-glance, openstack-heat, openstack-horizon-plugin-heat-ui, openstack-horizon-plugin-monasca-ui, openstack-ironic, openstack-ironic-python-agent, openstack-keystone, openstack-manila, openstack-neutron, openstack-neutron-gbp, openstack-nova, openstack-octavia, openstack-sahara, openstack-tempest, openstack-watcher, python-ardana-configurationprocessor, python-cinder-tempest-plugin, python-urllib3, rubygem-easy_diff
______________________________________________________________________________

Announcement ID:    SUSE-SU-2019:2562-1
Rating:             moderate
References:         #1118900 #1119737 #1120657 #1140267 #1145967 
                    #1147144 #1148158 #1150895 #1152032 
Affected Products:
                    SUSE OpenStack Cloud Crowbar 9
                    SUSE OpenStack Cloud 9
______________________________________________________________________________

   An update that contains security fixes can now be installed.

Description:

   This update for ansible1, ardana-ansible, ardana-cluster, ardana-db,
   ardana-extensions-nsx, ardana-glance, ardana-input-model,
   ardana-installer-ui, ardana-manila, ardana-monasca, ardana-neutron,
   ardana-nova, ardana-octavia, ardana-opsconsole-ui, ardana-osconfig,
   ardana-service, ardana-tls, crowbar-core, crowbar-ha, crowbar-openstack,
   crowbar-ui, grafana, novnc, openstack-cinder, openstack-dashboard,
   openstack-designate, openstack-glance, openstack-heat,
   openstack-horizon-plugin-heat-ui, openstack-horizon-plugin-monasca-ui,
   openstack-ironic, openstack-ironic-python-agent, openstack-keystone,
   openstack-manila, openstack-neutron, openstack-neutron-gbp,
   openstack-nova, openstack-octavia, openstack-sahara, openstack-tempest,
   openstack-watcher, python-ardana-configurationprocessor,
   python-cinder-tempest-plugin, python-urllib3, rubygem-easy_diff contains
   the following fixes:

   - 0004-add_ipv6_support_to_synchronize_action_plugin.patch fixes:
     bsc#1145967

     IPv6 addreses need to be wrapped when used in scp command in the form
   scp user@[ipv6address]:port SOC-10117

   - Update to version 9.0+git.1568385829.54601ac:
     * Enable Cloud9 parallelised upgrade workflow (SOC-10484)

   - Update to version 9.0+git.1568379640.07c5144:
     * Enable DB upgrade in ardana-update.yml (SOC-10094)

   - Update to version 9.0+git.1567617871.4426809:
     * Ensure tls-upgrade.yml called by ardana-update.yml (SOC-9942)

   - Update to version 9.0+git.1566486136.e2f6b0f:
     * Add deprecations cleanup support (SOC-10275)

   - Update to version 9.0+git.1568150980.027f167:
     * Enable auth_openidc Apache2 module (SOC-10509)

   - Update to version 9.0+git.1568382922.6f2cea4:
     * Use galera-upgrade.yml for update/upgrade workflow (SOC-10521)

   - Update to version 9.0+git.1568830037.2eea267:
     * Add missing DHCP options for NSX-T (SOC-5838)

   - Update to version 9.0+git.1568307751.d68a198:
     * Add NSX-T QoS service definition (SOC-10479)

   - Update to version 9.0+git.1567606893.85b4d54:
     * Add NSX-T LBaaS service definition (SOC-9900)

   - Update to version 9.0+git.1567416354.e45fd54:
     * Add missing policies for NSX-T (SOC-5831)

   - Update to version 9.0+git.1567196895.2e056b5:
     * Add NSX-T VPNaaS service definition (SOC-9935)
     * Add NSX-T FWaaS service definition (SOC-9935)

   - Update to version 9.0+git.1567196861.0ca4cc9:
     * Add the NSX-T DNS service definition (SOC-9912)

   - Update to version 9.0+git.1567196262.39a7dd0:
     * Improvements over initial NSX-T support (SOC-5831)

   - Update to version 9.0+git.1566918834.1b7a49a:
     * Update policy json templates for vmware-nsx (SOC-10254)

   - Update to version 9.0+git.1567000146.4569d10:
     * Cloud 8to9 upgrade enhancements for glance (SOC-10043)

   - Update to version 9.0+git.1566409257.eec6360:
     * Add neutron-fwaas.json when neutron-l3-agent is deployed (SOC-10280)

   - Update to version 9.0+git.1569535129.ca87ef0:
     * Add support for running in Docker container (SOC-8524) (#350)

   - Update to version 9.0+git.1567797529.273abf2:
     * Use IPv6 validator on baremetal (SOC-10251)

   - Update to version 9.0+git.1568835830.10c9689:
     * Ensure Manila services don't auto start on reboot (SOC-10641)

   - Update to version 9.0+git.1567695427.5974ab2:
     * Stop existing mon-api services during upgrade (SOC-10470)

   - Update to version 9.0+git.1568817582.a4813e2:
     * Fix neutron-ovsvapp-agent status (SOC-10637)

   - Update to version 9.0+git.1567606982.697a2bf:
     * Let SDNs configure LB service provider (SOC-9900)

   - Update to version 9.0+git.1567606981.c612be8:
     * API extension paths separated by colon (SOC-10447)

   - Update to version 9.0+git.1567000278.309171b:
     * Neutron 8to9 upgrade workflow (SOC-10080)

   - Update to version 9.0+git.1566503987.df6961f:
     * Add policy.d/neutron-fwaas.json.j2 (SOC-10280)

   - Update to version 9.0+git.1567630824.aa6dc2d:
     * api_db sync needed before db_expand.yml (SOC-10023)

   - Update to version 9.0+git.1567125466.9b151d6:
     * Enable tls channel for vnc on compute VM (SOC-9942)

   - Update to version 9.0+git.1566826931.741980f:
     * Install libosinfo package (SOC-10295)

   - Update to version 9.0+git.1568362662.7fba216:
     * Make octavia heartbeat frequency options configurable (SOC-9285)

   - Update to version 9.0+git.1566374458.f58d2bb:
     * Include SES variables when configuring image (SOC-9285)

   - Update to version 9.0+git.1566593422.813e56c:
     * Update ip address validator (SOC-9679)

   - Update to version 9.0+git.1567630791.5ca70a6:
     * Revert Ansible 2.x compatibility change (SOC-10452)

   - Update to version 9.0+git.1567553292.5991a87:
     * Configured openvswitch logrotate user based on system settings
       (SOC-10282)

   - Update to version 9.0+git.1569439941.6800991:
     * Re-enable streaming of playbook logs (SOC-10720)

   - Update to version 9.0+git.1569257240.456c4fc:
     * Add condition to avoid case with no compute (SOC-10692)

   - Update to version 9.0+git.1568075665.a627f71:
     * Fix missing key error for c9 update (SOC-10476)

   - Update to version 9.0+git.1567640139.61bbe4e:
     * Add support for redhat compute (SOC-9942)

   - Update to version 9.0+git.1567530252.4b0dc66:
     * Generate vnc server cert on compute host (SOC-9942)

   - Update to version 6.0+git.1569587091.3f083d63c:
     * barclamp_lib: Sync timeout with other barclamps (SOC-10513, SOC-10011)
     * Revert "batch: Use easy_merge for merging (SOC-10505)"
     * batch: Use easy_merge for merging (SOC-10505)

   - Update to version 6.0+git.1569357869.75e2690cc:
     * Update input group to be more specific (SOC-10644)

   - Update to version 6.0+git.1569231374.0fa522d5d:
     * Revert "batch: Use easy_merge for merging (SOC-10505)"

   - Update to version 6.0+git.1568968829.f21efcf5e:
     * batch: Use easy_merge for merging (SOC-10505)

   - Update to version 6.0+git.1568744770.09e7a1fe1:
     * upgrade: Fix pie chart colors on dashboard (SOC-10619)

   - Update to version 6.0+git.1568201547.4dfc6ffec:
     * gems: Update easy_diff to 1.0.0 (SOC-10505)

   - Update to version 6.0+git.1567846948.0f169d133:
     * upgrade: Reload nova services early (SOC-10273)
     * upgrade: Update release name (trivial)
     * upgrade: Upgrade compute services early (SOC-10273)

   - Update to version 6.0+git.1567731275.6019e8f62:
     * IPV6:Expose methods in chef NetworkHelper to crowbar_framework
       (SOC-6397)

   - Update to version 6.0+git.1567694723.1a9df112d:
     * Allow designate rndc for all nodes (SOC-10339)

   - Update to version 6.0+git.1567599465.9b1ea2814:
     * upgrade: dump Monasca, Grafana databases (SOC-9772)

   - Update to version 6.0+git.1567195728.44b7cf1d0:
     * Public ips for dns nodes when designate integration is in use
       (SOC-9635)

   - Update to version 6.0+git.1567161357.ba5de8885:
     * network: Check existing upper layers before bond setup  (bsc#1120657)
     * network: never plug two interface into the same ovs bridge
       (bsc#1120657)
     * network: Avoid plugging the same interface to two ovs bridges
       (bsc#1120657)
     * nic library: some helper for identifying base interface (bsc#1120657)
     * network: Rework the vlan port replugging code (bsc#1120657)
     * network: DRY out "kill_nic_files" (noref)
     * network: override sysctl netfilter param(SOC-6229)

   - Update to version 6.0+git.1567094352.24e2a710d:
     * upgrade: Re-run upgrade on non-compute nodes (SOC-10072)

   - Update to version 6.0+git.1566808212.3e1e65b69:
     * allow user to ask for FQDN as public hostname (SOC-9616)

   - Update to version 6.0+git.1567673476.1342c3d:
     * Fix typo in error message

   - Update to version 6.0+git.1569805311.a94583476:
     * Designate: Add dns_domain_ports config (SOC-10740)

   - Update to version 6.0+git.1569429613.2b29fd9d6:
     * horizon: add back horizon service reload (SOC-10191)
     * helper:move config_for_role_exists from horizon to
       crowbar-openstack(SOC-10191)
     * tempest: don't rely on service catalogue (SOC-10633)

   - Update to version 6.0+git.1569343076.e8ca90fd9:
     * enable LDAP chase_referrals configuration (SOC-7364)

   - Update to version 6.0+git.1569255523.d14bb0d9d:
     * nova: Don't autoselect nodes for Xen (continued) (bsc#1147144)

   - Update to version 6.0+git.1569053948.d0e638900:
     * Add pci passthrough filter (SOC-10624)
     * glance: don't reuse sync mark names (SOC-10348)
     * nova: Don't autoselect nodes for Xen (bsc#1147144)
     * database: fix no-op migration 302 (SOC-10623)
     * Fix Cloud 8 no-op migrations (SOC-10623)

   - Update to version 6.0+git.1568986202.bae13ce05:
     * designate: Fix the keys syntax error on migrations (SOC-10660)

   - Update to version 6.0+git.1568968817.8df296f0c:
     * upgrade: restore Monasca/Grafana DB (SOC-9772)

   - Update to version 6.0+git.1568904766.a7e023933:
     * Revert "designate: Mark as user managed (SOC-10233)"
     * nova: set default attribute for max_threads_per_process
     * Add tempest filter for designate (SOC-10288)
     * Allow setting ElasticSearch path.repo from Crowbar (SOC-10440,
       bsc#1148158)

   - Update to version 6.0+git.1568735102.940794f57:
     * Use source load balancing for OpenID Connect (SOC-10551)

   - Update to version 6.0+git.1568676694.b4ebc087b:
     * designate: Mark as user managed (SOC-10233)
     * Octavia: Hide UI until complete (SOC-10550)

   - Update to version 6.0+git.1568650755.8399d83e9:
     * IPV6: Barclamp horizon make IPV6 compliant (SOC-6397)

   - Update to version 6.0+git.1568325876.a82d6c3c6:
     * designate: Correct missing variable (SOC-10549)

   - Update to version 6.0+git.1568242913.38fe0574a:
     * designate: cleanup producer HA deployment (SOC-9766)

   - Update to version 6.0+git.1568130776.de1686df9:
     * designate: No longer care about master/slave (SOC-10456)
     * tempest: remove manila test from blacklist (SOC-9298)
     * nova: raise neutron client timeout to 5 minutes
     * neutron: Small cleanup to neutron_lbaas.conf template
     * neutron-lbaas: remove loadbalancer/pool limit

   - Update to version 6.0+git.1568004341.35d132726:
     * Designate default Bind9 pool config (SOC-10339)

   - Update to version 6.0+git.1567626408.bd1a24326:
     * nova: Don't put nova-compute roles on monasca node (SOC-10373)

   - Update to version 6.0+git.1567522813.05041a6eb:
     * Fix OpenID migration (SOC-9616)

   - Update to version 6.0+git.1567383972.eeae4cf86:
     * designate: Update ns_records with all nameservers (SOC-9636)

   - Update to version 6.0+git.1567095011.0d080dce4:
     * support OpenID Connect WebSSO (SOC-9616)

   - Update to version 6.0+git.1566925661.1e127bf66:
     * designate: Deploy producer on a server node (SOC-9766)

   - Update to version 6.0+git.1566851961.bda2f922c:
     * database: Hardcode ruby version for package installation (SOC-10010)

   - Update to version 6.0+git.1566629500.bbc0dd82f:
     * rabbitmq: Turn off hipe compile
     * designate: initialize email in default designate proposal

   - Update to version 6.0+git.1566553393.e01147258:
     * memcache: lookup memcached servers port only on local node (SOC-10173)

   - Update to version 1.3.0+git.1568396400.0344a727:
     * upgrade: Add missing precheck titles

   - spec file change:
     * alter permissions of /etc/grafana and /var/lib/grafana to 755
     * alter owner of /etc/grafana/provisioning/dashboards tree to root:root
     * this allows installing dashboards via rpms without these rpms
       depending on this rpm

   - Update to version 6.2.5:
     * release 6.2.5
     * Panel: Fully escape html in drilldown links (was only sanitized
       before)  (#17731)
     * Grafana-CLI: Wrapper for `grafana-cli` within RPM/DEB packages and
       config/homepath are now global flags (#17695)
     * config: fix connstr for remote_cache (#17675)
     * TablePanel: fix annotations display (#17646)
     * middleware: fix Strict-Transport-Security header (#17644)
     * Elasticsearch: Fix empty query request to send properly (#17488)
     * release 6.2.4
     * grafana-cli: Fix receiving flags via command line (#17617)
     * HTTPServer: Fix X-XSS-Protection header formatting (#17620)
     * release 6.2.3
     * cli: grafana-cli should receive flags from the command line (#17606)
     * AuthProxy: Optimistic lock pattern for remote cache Set (#17485)
     * OAuth: Fix for wrong user token updated on OAuth refresh in DS proxy
       (#17541)
     *  middleware: add security related HTTP(S) response headers (#17522)
     * remote_cache: Fix redis (#17483)
     * auth_proxy: non-negative cache TTL (#17495)

   - Update to version 6.2.2:
     * Security Fix: Prevent csv formula injection attack
     * PluginConfig: Fixed plugin config page navigation when using subpath
     * Explore: Update time range before running queries
     * Perf: Fix slow dashboards ACL query
     * Database: Initialize xorm with an empty schema for postgres
     * CloudWatch: Avoid exception while accessing results

   - Remove phantomjs dependency
     * Modified: Makefile
   - Update to version 6.2.1
     * Bug Fixes
       + Auth Proxy: Resolve database is locked errors.
       + Database: Retry transaction if sqlite returns database is locked
         error.
       + Explore: Fixes so clicking in a Prometheus Table the query is
         filtered by clicked value.
       + Singlestat: Fixes issue with value placement and line wraps.
       + Tech: Update jQuery to 3.4.1 to fix issue on iOS 10 based browers as
         well as Chrome 53.x.
     * Features / Enhancements
       + CLI: Add command to migrate all datasources to use encrypted
         password fields.
       + Gauge/BarGauge: Improvements to auto value font size.
     * Modified: README
   - Update to version 6.2.0
     * Bug Fixes
       + BarGauge: Fix for negative min values.
       + Gauge/BarGauge: Fix for issues editing min & max options.
       + Search: Make only folder name only open search with current folder
         filter.
       + AzureMonitor: Revert to clearing chained dropdowns.
       + Dashboard: Fixes blank dashboard after window resize with panel
         without title.
       + Dashboard: Fixes lazy loading & expanding collapsed rows on mobile.
       + Dashboard: Fixes scrolling issues for Edge browser.
       + Dashboard: Show refresh button in first kiosk(tv) mode.
       + Explore: Fix empty result from datasource should render logs
         container.
       + Explore: Fixes so clicking in a Prometheus Table the query is
         filtered by clicked value.
       + Explore: Makes it possible to zoom in Explore/Loki/Graph without
         exception.
       + Gauge: Fixes orientation issue after switching from BarGauge to
         Gauge.
       + GettingStarted: Fixes layout issues in getting started panel.
       + InfluxDB: Fix HTTP method should default to GET.
       + Panels: Fixed alert icon position in panel header.
       + Panels: Fixes panel error tooltip not showing.
       + Plugins: Fix how datemath utils are exposed to plugins.
       + Singlestat: fixed centering issue for very small panels.
       + Search: Scroll issue in dashboard search in latest Chrome.
       + Docker: Prevent a permission denied error when writing files to the
         default provisioning directory.
       + Gauge: Adds background shade to gauge track and improves height
         usage.
       + RemoteCache: Avoid race condition in Set causing error on insert. .
       + Build: Fix bug where grafana didn't start after mysql on rpm
         packages.
       + CloudWatch: Fixes query order not affecting series ordering & color.
       + CloudWatch: Use default alias if there is no alias for metrics.
       + Config: Fixes bug where timeouts for alerting was not parsed
         correctly.
       + Elasticsearch: Fix view percentiles metric in table without date
         histogram.
       + Explore: Prevents histogram loading from killing Prometheus instance.
       + Graph: Allow override decimals to fully override.
       + Mixed Datasource: Fix error when one query is disabled.
       + Search: Fixes search limits and adds a page parameter.
       + Security: Responses from backend should not be cached.
     * Breaking Changes
       + Plugins: Data source plugins that process hidden queries need to add
         a "hiddenQueries: true" attribute in plugin.json.
       + Gauge Panel: The suffix / prefix options have been removed from the
         new Gauge Panel (introduced in v6.0). #16870.
     * Features / Enhancements
       + Plugins: Support templated urls in plugin routes.
       + Packaging: New MSI windows installer package**.
       + Admin: Add more stats about roles.
       + Alert list panel: Support variables in filters.
       + Alerting: Adjust label for send on all alerts to default .
       + Alerting: Makes timeouts and retries configurable.
       + Alerting: No notification when going from no data to pending.
       + Alerting: Pushover alert, support for different sound for OK.
       + Auth: Enable retries and transaction for some db calls for auth
         tokens .
       + AzureMonitor: Adds support for multiple subscriptions per datasource.
       + Bar Gauge: New multi series enabled gauge like panel with horizontal
         and vertical layouts and 3 display modes.
       + Build: Upgrades to golang 1.12.4.
       + CloudWatch: Update AWS/IoT metric and dimensions.
       + Config: Show user-friendly error message instead of stack trace.
       + Dashboard: Enable filtering dashboards in search by current folder.
       + Dashboard: Lazy load out of view panels .
       + DataProxy: Restore Set-Cookie header after proxy request.
       + Datasources: Add pattern validation for time input on datasource
         config pages.
       + Elasticsearch: Add 7.x version support.
       + Explore: Adds reconnect for failing datasource.
       + Explore: Support user timezone.
       + InfluxDB: Add support for POST HTTP verb.
       + Loki: Search is now case insensitive.
       + OAuth: Update jwt regexp to include =.
       + Panels: No title will no longer make panel header take up space.
       + Prometheus: Adds tracing headers for Prometheus datasource.
       + Provisioning: Add API endpoint to reload provisioning configs.
       + Provisioning: Do not allow deletion of provisioned dashboards.
       + Provisioning: Interpolate env vars in provisioning files.
       + Security: Add new setting allow_embedding.
       + Security: Store datasource passwords encrypted in secureJsonData.
       + UX: Improve Grafana usage for smaller screens.
       + Units: Add angle units, Arc Minutes and Seconds.

   - Update to version 6.1.6
     * Security: Bump jQuery to 3.4.0
     * Playlist: Fix loading dashboards by tag.
   - Update to version 6.0.2:
     * Fixed issue with alert links in alert list panel causing panel not
       found errors, fixes #15680
     * Improved error handling when rendering dashboard panels, fixes #15913
     * fix allow anonymous server bind for ldap search
     * add nil/length check when delete old login attempts
     * fix discord notifier so it doesn't crash when there are no image
       generated
     * fix only users that can edit a dashboard should be able to update
       panel json
     * move to new component to handle focus
     * added state to not set focus on search every render
     * Snapshots update
     * Use app config directly in ButtonRow instead of passing datasources
       page URL via prop
     * Update snapshots
     * Fixed url of back button in datasource edit page, when root_url
       configured
     * release: Bumped version
   - Update to version 6.0.1:
     * Bug Fixes:
       + utils: show string errors
       + Viewers with viewers_can_edit should be able to access /explore
       +  log phantomjs output even if it timeout and include orgId when
   render alert
   - Update to version 6.0.0:
     * Breaking Changes:
       + Text Panel: The text panel does no longer by default allow
         unsantizied HTML. This means that if you have text panels with
         scripts tags they will no longer work as before. To enable unsafe
         javascript execution in text panels enable the settings
         disable_sanitize_html under the section [panels] in your Grafana ini
         file, or set env variable GF_PANELS_ABLE_SANITIZE_HTML=true.
       + Dashboard: Panel property minSpan replaced by maxPerRow. Dashboard
         migration will automatically migrate all dashboard panels using the
         minSpan property to the new maxPerRow property
       + Internal Metrics Edition has been added to the build_info metric.
         This will break any Graphite queries using this metric. Edition will
         be a new label for the Prometheus metric.
     * New Features:
       + Alerting: Adds support for Google Hangouts Chat notifications
       + Elasticsearch: Support bucket script pipeline aggregations
       + Influxdb: Add support for time zone (tz) clause
       + Snapshots: Enable deletion of public snapshot
       + Provisioning: Provisioning support for alert notifiers
       + Explore: A whole new way to do ad-hoc metric queries and
         exploration. Split view in half and compare metrics & logs and much
         much more. Read more here
       + Auth: Replace remember me cookie solution for Grafana's builtin,
         LDAP and OAuth authentication with a solution based on short-lived
         tokens
       + AzureMonitor: Enable alerting by converting Azure Monitor API to Go
       + Explore A new query focused workflow for ad-hoc data exploration and
         troubleshooting.
       + Grafana Loki Integration with the new open source log aggregation
         system from Grafana Labs.
       + Gauge Panel A new standalone panel for gauges.
       + New Panel Editor UX improves panel editing and enables easy
         switching between different visualizations.
       + Google Stackdriver Datasource is out of beta and is officially
         released.
       + React Plugin support enables an easier way to build plugins.
       + Named Colors in our new improved color picker.
       + Removal of user session storage makes Grafana easier to deploy &
         improves security.
     * Bug Fixes:
       + Metrics: Fixes broken usagestats metrics for /metrics
       + Dashboard: Fixes kiosk mode should have &kiosk appended to the url
       + Dashboard: Fixes kiosk=tv mode with autofitpanels should respect
         header
       + Image rendering: Fixed image rendering issue for dashboards with
         auto refresh,
       + Dashboard: Fix only users that can edit a dashboard should be able
         to update panel json.
       + LDAP: fix allow anonymous initial bind for ldap search.
       + UX: Fixed scrollbar not visible initially (only after manual scroll).
       + Datasource admin TestData
       + Dashboard: Fixed scrolling issue that caused scroll to be locked to
         bottom.
       + Explore: Viewers with viewers_can_edit should be able to access
         /explore.
       + Security fix: limit access to org admin and alerting pages.
       + Panel Edit minInterval changes did not persist
       + Teams: Fixed bug when getting teams for user.
       + Stackdriver: fix for float64 bounds for distribution metrics
       + Stackdriver: no reducers available for distribution type
       + Influxdb: Add support for alerting on InfluxDB queries that use the
         non_negative_difference function
       + Alerting: Fix percent_diff calculation when points are nulls
       + Alerting: Fixed handling of alert urls with true flags
       + Gauge: Fix issue with gauge requests being cancelled
       + Gauge: Accept decimal inputs for thresholds
       + UI: Fix error caused by named colors that are not part of named
         colors palette
       + Search: Bug pressing special regexp chars in input fields
       + Permissions: No need to have edit permissions to be able to "Save as"
       + Search: Fix for issue with scrolling the "tags filter" dropdown
       + Prometheus: Query for annotation always uses 60s step regardless of
         dashboard range
       + Annotations: Fix creating annotation when graph panel has ata points
         position the popup outside viewport
       + Piechart/Flot: Fixes multiple piechart instances with donut bug
       + plus many minor changes and fixes
   - Update to version 5.4.3:
     * Fixes:
       + Alerting Invalid frequency causes division by zero in alert scheduler
       + Dashboard Dashboard links do not update when time range changes
       + Limits Support more than 1000 datasources per org
       + Backend fix signed in user for orgId=0 result should return active
         org id
       + Provisioning Adds orgId to user dto for provisioned dashboards
   - Update to version 5.4.2:
     * Fixes:
       + Datasource admin: Fix for issue creating new data source when same
         name exists
       + OAuth: Fix for oauth auto login setting, can now be set using env
         variable
       + Dashboard search: Fix for searching tags in tags filter dropdown.
   - Update to version 5.4.1:
     * Fixes:
       + Stackdriver: Fixes issue with data proxy and Authorization header
       + Units: fixedUnit for Flow:l/min and mL/min
       + Logging: Fix for issue where data proxy logged a secret when debug
         logging was enabled, now redacted.
       + InfluxDB: Add support for alerting on InfluxDB queries that use the
         cumulative_sum function.
       + Plugins: Panel plugins should no receive the panel-initialized event
         again as usual.
       + Embedded Graphs: Iframe graph panels should now work as usual.
       + Postgres: Improve PostgreSQL Query Editor if using different Schemas,
       + Quotas: Fixed for updating org & user quotas.
       + Cloudwatch: Add the AWS/SES Cloudwatch metrics of BounceRate and
         ComplaintRate to auto complete list.
       + Dashboard Search: Fixed filtering by tag issues.
       + Graph: Fixed time region issues,
       + Graph: Fixed issue with series color picker popover being placed
         outside window.
   - Update to version 5.4.0:
     * Breaking Changes:
       + Postgres/MySQL/MSSQL datasources now per default uses max open
         connections = unlimited (earlier 10), max idle connections = 2
         (earlier 10) and connection max lifetime = 4 hours (earlier
         unlimited).
     * Features:
       + Alerting: Introduce alert debouncing with the FOR setting.
       + Alerting: Option to disable OK alert notifications
       + Postgres/MySQL/MSSQL: Adds support for configuration of max
         open/idle connections and connection max lifetime. Also, panels with
         multiple SQL queries will now be executed concurrently
       + MySQL: Graphical query builder
       + MySQL: Support connecting thru Unix socket for MySQL datasource
       + MSSQL: Add encrypt setting to allow configuration of how data sent
         between client and server are encrypted
       + Stackdriver: Not possible to authenticate using GCE metadata server
       + Teams: Team preferences (theme, home dashboard, timezone) support
       + Graph: Time regions support enabling highlight of weekdays and/or
         certain timespans
       + OAuth: Automatic redirect to sign-in with OAuth
       + Stackdriver: Template query editor
     * Fixes:
       + Cloudwatch: Fix invalid time range causes segmentation fault
       + Cloudwatch: AWS/CodeBuild metrics and dimensions
       + MySQL: Fix $__timeFrom() and $__timeTo() should respect local time
         zone
       + Graph: Fix legend always visible even if configured to be hidden
       + Elasticsearch: Fix regression when using datasource version 6.0+ and
         alerting
   - Update to version 5.3.4:
     * minor bug fixes

   - Fix patch novnc-1.0.0-fix-interpreter.patch
     * Renamed to patch novnc-1.1.0-fix-interpreter.patch
   - Update to 1.1.0: Application:
       * New translations for Russian, Korean, Czech and Chinese
         (traditional) languages
       * Fixed an issue where you didn't get scrollbn your browser on Windows
         if you had a touch screen.
       * Added the Super/Windows key to the toolbar.
       * Added an option to show a dot when there otherwise wouldn't be a
         visible cursor.
       * View drag is no longer available when in scaling mode. Library:
       * A large number of coding style changes has been made to make the
         code easier to read and better to work with.
       * Many keyboard issues has been fixed.
       * Local cursor is now available on all platforms.
       * Fixed a number of crashes related to clipboard.
       * Fixed issues that occurred if data from the server was being
         received slowly.
       * A problem has been fixed where the display module would incorrectly
         handle high DPI systems causing scrollbars to show when they
         shouldn't.

   - require python3-websockify for recent distros (bsc#1119737)

   - Update to version cinder-13.0.7.dev16:
     * Dell EMC SC: Handle the mappings of multiattached volume

   - Update to version cinder-13.0.7.dev14:
     * 3PAR: Add config for NSP single path attach

   - Update to version cinder-13.0.7.dev12:
     * Fix VolumeAttachment is not bound to a Session
     * Fix ceph: only close rbd image after snapshot iteration is finished

   - Update to version cinder-13.0.7.dev8:
     * Fix NFS volume retype with migrate

   - Update to version cinder-13.0.7.dev7:
     * Remove experimental openSUSE 42.3 job

   - Update to version cinder-13.0.7.dev5:
     * Fixing 404's and broken links

   - Update to version cinder-13.0.7.dev16:
     * Dell EMC SC: Handle the mappings of multiattached volume

   - Update to version cinder-13.0.7.dev14:
     * 3PAR: Add config for NSP single path attach

   - Update to version cinder-13.0.7.dev12:
     * Fix VolumeAttachment is not bound to a Session
     * Fix ceph: only close rbd image after snapshot iteration is finished

   - Update to version cinder-13.0.7.dev8:
     * Fix NFS volume retype with migrate

   - Update to version cinder-13.0.7.dev7:
     * Remove experimental openSUSE 42.3 job

   - Update to version cinder-13.0.7.dev5:
     * Fixing 404's and broken links

   - Update to version horizon-14.0.4.dev11:
     * Fix listing security groups when no rules

   - Update to version horizon-14.0.4.dev9:
     * Fix quoting in zuul for tempest plugins
     * Allow creating ICMPV6 rules

   - Update to version horizon-14.0.4.dev6:
     * Ensure to call patch\_middleware\_get\_user() in api.test\_base

   - Update to version horizon-14.0.4.dev5:
     * Fixing broken links

   - Update to version designate-7.0.1.dev22:
     * Fixing 404 link

   - Update to version designate-7.0.1.dev22:
     * Fixing 404 link

   - Update to version glance-17.0.1.dev30:
     * Fix manpage building and remove glance-cache-manage

   - Update to version glance-17.0.1.dev28:
     * Fix doc build after removal of glance-cache-manage man page

   - Update to version glance-17.0.1.dev26:
     * Updating Ceph 404 URLs

   - Update to version glance-17.0.1.dev24:
     * Remove experimental openSUSE 42.3 job
     * OpenDev Migration Patch

   - Update to version glance-17.0.1.dev22:
     * Failure in web-dowload kept image in importing state
     * Replace openstack.org git:// URLs with https://
     * Data remains in staging area if 'file' store is not enabled
     * Removed glancecachemanage.rst and updated header.txt

   - Update to version glance-17.0.1.dev30:
     * Fix manpage building and remove glance-cache-manage

   - Rebased patches:
     + 0001-Fix-manpage-building-and-remove-glance-cache-manage.patch dropped
       (merged upstream)

   - Update to version glance-17.0.1.dev28:
     * Fix doc build after removal of glance-cache-manage man page

   - Update to version glance-17.0.v26:
     * Updating Ceph 404 URLs

   - Update to version glance-17.0.1.dev24:
     * Remove experimental openSUSE 42.3 job
     * OpenDev Migration Patch

   - Add 0001-Drop-glance-cache-manage-entrypoint-from-setup.cfg.patch
     (SOC-6366) This removes the broken entrypoint for
     /usr/bin/glance-cache-manage The code behind the executable was already
     removed upstream so the executable was not usable

   - Update to version glance-17.0.1.dev22:
     * Failure in web-dowload kept image in importing state
     * Replace openstack.org git:// URLs with https://
     * Data remains in staging area if 'file' store is not enabled
     * Removed glancecachemanage.rst and updated header.txt
   - Add 0001-Fix-manpage-building-and-remove-glance-cache-manage.patch This
     fixes the manpage build which is needed after the removal
     of glancecachemanage.rst by upstream

   - Update to version openstack-heat-11.0.3.dev23:
     * Add retries when loading keystone data and fetching endpoints

   - Update to version openstack-heat-11.0.3.dev22:
     * Use connect\_retries when creating clients

   - Update to version openstack-heat-11.0.3.dev20:
     * Add retry for sync\_point\_update\_input\_data

   - Update to version openstack-heat-11.0.3.dev23:
     * Add retries when loading keystone data and fetching endpoints

   - Update to version openstack-heat-11.0.3.dev22:
     * Use connect\_retries when creating clients

   - Update to version openstack-heat-11.0.3.dev20:
     * Add retry for sync\_point\_update\_input\_data

   - Include heat_policy.json (bsc#1152032)
     * Fixed the unexpected error in Horizon when Heat dashboard is enabed

   - update to version 1.14.1~dev9
     - Hide Graph Metric action of alarm when Grafana is not available
     - OpenDev Migration Patch

   - Update to version ironic-11.1.4.dev15:
     * Fix typo in handling of exception FailedToGetIPAddressOnPort

   - Update to version ironic-11.1.4.dev14:
     * DRAC: Fix OOB introspection to use pxe\_enabled flag in idrac driver
     * iLO firmware update fails with 'update\_firmware\_sum' clean step

   - Update to version ironic-11.1.4.dev10:
     * CI: remove quotation marks from TEMPEST\_PLUGINS variable

   - Update to version ironic-11.1.4.dev15:
     * Fix typo in handling of exception FailedToGetIPAddressOnPort

   - Update to version ironic-11.1.4.dev14:
     * DRAC: Fix OOB introspection to use pxe\_enabled flag in idrac driver
     * iLO firmware update fails with 'update\_firmware\_sum' clean step

   - Update to version ironic-11.1.4.dev10:
     * CI: remove quotation marks from TEMPEST\_PLUGINS variable

   - Update to version ironic-python-agent-3.3.3.dev5:
     * Fix compatibility with Pint 0.5

   - Update to version keystone-14.1.1.dev16:
     * Fixing 404 URLs for Rocky

   - Update to version keystone-14.1.1.dev15:
     * Updating mapping rule link

   - Update to version keystone-14.1.1.dev13:
     * Fix python3 compatibility on LDAP search DN from id
     * Fixing dn\_to\_id function for cases were id is not in the DN

   - Update to version keystone-14.1.1.dev9:
     * Remove experimental openSUSE 42.3 job

   - Update to version keystone-14.1.1.dev16:
     * Fixing 404 URLs for Rocky

   - Update to version keystone-14.1.1.dev15:
     * Updating mapping rule link

   - Update to version keystone-14.1.1.dev13:
     * Fix python3 compatibility on LDAP search DN from id
     * Fixing dn\_to\_id function for cases were id is not in the DN

   - Update to version keystone-14.1.1.dev9:
     * Remove experimental openSUSE 42.3 job

   - Update to version manila-7.3.1.dev6:
     * Unmount NetApp active share after replica promote

   - Update to version manila-7.3.1.dev4:
     * Fixing broken links

   - Updateon manila-7.3.1.dev6:
     * Unmount NetApp active share after replica promote

   - Update to version manila-7.3.1.dev4:
     * Fixing broken links

   - Update to version neutron-13.0.5.dev50:
     * DVR: Cleanup ml2 dvr portbindings on migration

   - Update to version neutron-13.0.5.dev49:
     * Avoid unnecessary operation of ovsdb and flows

   - Update to version neutron-13.0.5.dev48:
     * Increase timeouts for OVSDB in functional tests

   - Update to version neutron-13.0.5.dev46:
     * Fix creation of vlan network with segmentation\_id set to 0
     * Add info log about ready DHCP config for ports

   - Update to version neutron-13.0.5.dev42:
     * Check the namespace is ready in test\_mtu\_update tests
     * Create \_mech\_context before delete to avoid race

   - Update to version neutron-13.0.5.dev39:
     * ML2 plugin: extract and postpone limit in port query
     * Increase TestDhcpAgentHA.agent\_down\_time to 30 seconds

   - Update to version neutron-13.0.5.dev35:
     * Use created subnet in port generator in
       "test\_port\_ip\_update\_revises"

   - Update to version neutron-13.0.5.dev34:
     * Increase number of retries in \_process\_trunk\_subport\_bindings

   - Update to version neutron-13.0.5.dev33:
     * Filter placement API endpoint by type too

   - Update to version neutron-13.0.5.dev31:
     * Remove experimental openSUSE 42.3 job
     * Initialize phys bridges before setup\_rpc
     * Populate binding levels when concurrent ops fail
     * Make sure the port still in port map when prepare\_port\_filter
     * [DVR] Add lock during creation of FIP agent gateway port

   - Update to version neutron-13.0.5.dev50:
     * DVR: Cleanup ml2 dvr portbindings on migration

   - Update to version neutron-13.0.5.dev49:
     * Avoid unnecessary operation of ovsdb and flows

   - Update to version neutron-13.0.5.dev48:
     * Increase timeouts for OVSDB in functional tests

   - Update to version neutron-13.0.5.dev46:
     * Fix creation of vlan network with segmentation\_id set to 0
     * Add info log about ready DHCP config for ports

   - Update to version neutron-13.0.5.dev42:
     * Check the namespace is ready in test\_mtu\_update tests
     * Create \_mech\_context before delete to avoid race

   - Update to version neutron-13.0.5.dev39:
     * ML2 plugin: extract and postpone limit in port query
     * Increase TestDhcpAgentHA.agent\_down\_time to 30 seconds

   - Update to version neutron-13.0.5.dev35:
     * Use created subnet in port generator in
       "test\_port\_ip\_update\_revises"

   - Update to version neutron-13.0.5.dev34:
     * Increase number of retries in \_process\_trunk\_subport\_bindings

   - Update to version neutron-13.0.5.dev33:
     * Filter placement API endpoint by type too

   - Update to version neutron-13.0.5.dev31:
     * Remove experimental openSUSE 42.3 job
     * Initialize phys bridges before setup\_rpc
     * Populate binding levels when concurrent ops fail
     * Make sure the port still in port map when prepare\_port\_filter
     * [DVR] Add lock during creation of FIP agent gateway port

   - Update to version group-based-policy-5.0.1.dev472:
     * [AIM] Fix HAIP RPC query

   - Update to version group-based-policy-5.0.1.dev471:
     * Fix implicit ICMPv6 Security Group Rules

   - Update to version group-based-policy-5.0.1.dev470:
     * Fixed snat port status to be ACTIVE and UP

   - Update to version group-based-policy-5.0.1.dev468:
     * Revert "Make DHCP provisioning blocks conditional"
     * Some refactoring regarding merge aim statuses

   - Update to version group-based-policy-5.0.1.dev464:
     * Verify aim\_epg exists before proceeding

   - Update to version group-based-policy-5.0.1.dev462:
     * Bulk extension support for

   - Update to version group-based-policy-5.0.1.dev461:
     * [AIM] Eliminate redundant router extension content

   - Update to version group-based-policy-5.0.1.dev460:
     * Fix for Commit 564905e49a0d418bc891f12b560e291a9fdc4acb 1. The method
       \_track\_connectivity returns nothing,    so, self.track\_success is
       updated in the method itself

   - Update to version nova-18.2.3.dev22:
     * lxc: make use of filter python3 compatible
     * Fix rebuild of baremetal instance when vm\_state is ERROR
     * Fix wrong assertions in unit tests
     * Fix 'has\_calls' method calls in unit tests
     * Fix non-existent method of Mock
     * Retrun 400 if invalid query parameters are specified

   - Update to version nova-18.2.3.dev10:
     * doc: Fix a broken reference link

   - Update to version nova-18.2.3.dev9:
     * Restore soft-deleted compute node with same uuid
     * Add functional regression recreate test for bug 1839560
     * rt: only map compute node if we created it

   - Update to version nova-18.2.3.dev3:
     * Remove experimental job on openSUSE 42.3

   - Update to version nova-18.2.3.dev2:
     * Fix misuse of nova.objects.base.obj\_equal\_prims 18.2.2
     * Don't generate service UUID for deleted services
     * Add 'path' query parameter to console access url
     * Replace non-nova server fault message
     * Avoid logging traceback when detach device not found
     * Fix python3 compatibility of rbd get\_fsid
     * Add functional regression test for bug 1778305
     * Add functional recreate test for bug 1764556
     * Cleanup when hitting MaxRetriesExceeded from no host\_available
     * Add functional regression test for bug 1837955
     * Revert "[libvirt] Filter hypervisor\_type by virt\_type"
     * Avoid crashing while getting libvirt capabilities with unknown arch
       names
     * libvirt: move checking CONF.my\_ip to init\_host()
     * Revert resize: wait for events according to hybrid plug
     * docs: Correct issues with 'openstack quota set' commands
     * doc: Fix a parameter of NotificationPublisher
     * Perf: Use dicts for ProviderTree roots
     * Fix type error on call to mount device
     * Drop source node allocations if finish\_resize fails
     * Add functional recreate test for regression bug 1825537
     * Stabilize unshelve notification sample tests
     * Ignore hw\_vif\_type for direct, direct-physical vNIC types
     * Fix double word hacking test
     * Disable limit if affinity(anti)/same(different)host is requested
     * Delete resource providers for all nodes when deleting compute service

   - Update to version nova-18.2.3.dev22:
     * lxc: make use of filter python3 compatible
     * Fix rebuild of baremetal instance when vm\_state is ERROR
     * Fix wrong assertions in unit tests
     * Fix 'has\_calls' method calls in unit tests
     * Fix non-existent method of Mock
     * Retrun 400 if invalid query parameters are specified

   - Update to version nova-18.2.3.dev10:
     * doc: Fix a broken reference link

   - Allow to attach more than 26 volumes (bsc#1118900)
     * This is a forward port from SOC7
     * Add 0001-Add-method-to-generate-device-names-universally.patch
     * Add 0002-Raise-403-instead-of-500-error-from-attach-volume-AP.patch
     * Add 0003-Add-configuration-of-maximum-disk-devices-to-attach.patch

   - Update to version nova-18.2.3.dev9:
     * Restore soft-deleted compute node with same uuid
     * Add functional regression recreate test for bug 1839560
     * rt: only map compute node if we created it

   - Update to version nova-18.2.3.dev3:
     * Remove experimental job on openSUSE 42.3

   - Update to version nova-18.2.3.dev2:
     * Fix misuse of nova.objects.base.obj\_equal\_prims
     * Don't generate service UUID fed services
     * Add 'path' query parameter to console access url
     * Replace non-nova server fault message
     * Avoid logging traceback when detach device not found
     * Fix python3 compatibility of rbd get\_fsid
     * Add functional regression test for bug 1778305
     * Add functional recreate test for bug 1764556
     * Cleanup when hitting MaxRetriesExceeded from no host\_available
     * Add functional regression test for bug 1837955
     * Revert "[libvirt] Filter hypervisor\_type by virt\_type"
     * Avoid crashing while getting libvirt capabilities with unknown arch
       names
     * libvirt: move checking CONF.my\_ip to init\_host()
     * Revert resize: wait for events according to hybrid plug
     * docs: Correct issues with 'openstack quota set' commands
     * doc: Fix a parameter of NotificationPublisher
     * Perf: Use dicts for ProviderTree roots
     * Fix type error on call to mount device
     * Drop source node allocations if finish\_resize fails
     * Add functional recreate test for regression bug 1825537
     * Stabilize unshelve notification sample tests
     * Ignore hw\_vif\_type for direct, direct-physical vNIC types
     * Fix double word hacking test
     * Disable limit if affinity(anti)/same(different)host is requested
     * Delete resource providers for all nodes when deleting compute service
   - remove 0001-Skip-to-remove-resource-provider-if-compute-node-not.patch:
     was only for an internal problem that we solved otherwise, and didn't go
     upstream.

   - Update to version octavia-3.1.2.dev45:
     * Fix member API handling of None/null updates

   - Update to version octavia-3.1.2.dev43:
     * Validate server\_certs\_key\_passphrase is 32 chars
     * Work around strptime threading issue
     * Fix base (VRRP) port abandoned on revert

   - Update to version octavia-3.1.2.dev38:
     * Do not run non-voting jobs in gate
     * Fix l7rule API handling of None updates
     * Fix template that generates vrrp check script
     * elements: add arch property for \`\`open-vm-tools\`\`

   - Update to version octavia-3.1.2.dev30:
     * Prevent UDP LBs to use different IP protocol versions in amphora driver
     * Fixed down server issue after reloading keepalived
     * Fixed pool and members status with UDP loadbalancers
     * Add support for monitor\_{address,port} in UDP members
     * Fix auto setup Barbican's ACL in the legacy driver

   - Update to version octavia-3.1.2.dev20:
     * Fix L7 repository create methods

   - Update to version octavia-3.1.2.dev18:
     * Add warning log if auth\_strategy is not keystone

   - Update to version octavia-3.1.2.dev16:
     * Add failover logging to show the amphora details

   - Update to version octavia-3.1.2.dev14:
     * Revert "Use the infra pypi mirror for DIB"

   - Update to version octavia-3.1.2.dev12:
     * Use the infra pypi mirror for DIB

   - Update to version octavia-3.1.2.dev10:
     * only rollback DB when we have a connection to the DB

   - Update to version octavia-3.1.2.dev9:
     * worker: Re-add FailoverPreparationForAmphora

   - Update to version sahara-9.0.2.dev12:
     * Fixing broken links and removing outdated driver
     * Fix requirements (bandit, sphinx)
     * OpenDev Migration Patch

   - Update to version sahara-9.0.2.dev12:
     * Fixing broken links and removing outdated driver
     * Fix requirements (bandit, sphinx)
     * OpenDev Migration Patch

   - Add 0001-Handle-path-query-parameter-for-test_novnc.patch

   - update to version 1.12.1~dev19
     - fix test failure with ironic client
     - OpenDev Migration Patch
     - pass default_config_dirs variable for config initialization.
   - Update Dependencies. There are number of client packages that are
     required by watcher ino function correctly. (SOC-4183)

   - update to version 1.12.1~dev15
     - Provide two arguments to exception's message
     - Replace openstack.org git:// URLs with https://
     - set watcherclient no voting
     - Access to action's uuid by key
     - make ceilometer client import optional
   - add the systemd unit files for openstack-watcher-api,
     openstack-watcher-applier, and openstack-watcher-decision-engine

   - Update to version 9.0+git.1568955483.5f039e4:
     * subnet/netmaks OR cidr are acceptable in baremetal input model
       (SOC-10615)

   - added 0001-Remove-redundant-cleanups-in-test_volume_backup.patch and
     0001-GET-backup-before-asserting-volume_id-and-snapshot_id.patch

   - Add missing dependency on python-six (bsc#1150895)

   rubygem-easy_diff:
   - updated to version 1.0.0
     - Unmerge Arrays containing Hashes
     - Handle duplicate values in arrays correctly

   - updated to version 0.0.6
     - Fix merging arrays of hashes


Patch Instructions:

   To install this SUSE Security Update use the SUSE recommended installation methods
   like YaST online_update or "zypper patch".

   Alternatively you can run the command listed for your product:

   - SUSE OpenStack Cloud Crowbar 9:

      zypper in -t patch SUSE-OpenStack-Cloud-Crowbar-9-2019-2562=1

   - SUSE OpenStack Cloud 9:

      zypper in -t patch SUSE-OpenStack-Cloud-9-2019-2562=1



Package List:

   - SUSE OpenStack Cloud Crowbar 9 (noarch):

      crowbar-ha-6.0+git.1567673476.1342c3d-3.10.1
      crowbar-openstack-6.0+git.1569805311.a94583476-3.10.1
      crowbar-ui-1.3.0+git.1568396400.0344a727-11.1
      grafana-monasca-ui-drilldown-1.14.1~dev9-3.6.1
      novnc-1.1.0-3.3.1
      openstack-cinder-13.0.7~dev16-3.10.2
      openstack-cinder-api-13.0.7~dev16-3.10.2
      openstack-cinder-backup-13.0.7~dev16-3.10.2
      openstack-cinder-scheduler-13.0.7~dev16-3.10.2
      openstack-cinder-volume-13.0.7~dev16-3.10.2
      openstack-dashboard-14.0.4~dev11-3.6.2
      openstack-designate-7.0.1~dev22-3.10.2
      openstack-designate-agent-7.0.1~dev22-3.10.2
      openstack-designate-api-7.0.1~dev22-3.10.2
      openstack-designate-central-7.0.1~dev22-3.10.2
      openstack-designate-producer-7.0.1~dev22-3.10.2
      openstack-designate-sink-7.0.1~dev22-3.10.2
      openstack-designate-worker-7.0.1~dev22-3.10.2
      openstack-glance-17.0.1~dev30-3.3.2
      openstack-glance-api-17.0.1~dev30-3.3.2
      openstack-heat-11.0.3~dev23-3.10.2
      openstack-heat-api-11.0.3~dev23-3.10.2
      openstack-heat-api-cfn-11.0.3~dev23-3.10.2
      openstack-heat-engine-11.0.3~dev23-3.10.2
      openstack-heat-plugin-heat_docker-11.0.3~dev23-3.10.2
      openstack-horizon-plugin-heat-ui-1.4.1~dev4-4.6.1
      openstack-horizon-plugin-monasca-ui-1.14.1~dev9-3.6.1
      openstack-ironic-11.1.4~dev15-3.10.2
      openstack-ironic-api-11.1.4~dev15-3.10.2
      openstack-ironic-conductor-11.1.4~dev15-3.10.2
      openstack-ironic-python-agent-3.3.3~dev5-3.10.2
      openstack-keystone-14.1.1~dev16-3.10.2
      openstack-manila-7.3.1~dev6-4.10.2
      openstack-manila-api-7.3.1~dev6-4.10.2
      openstack-manila-data-7.3.1~dev6-4.10.2
      openstack-manila-scheduler-7.3.1~dev6-4.10.2
      openstack-manila-share-7.3.1~dev6-4.10.2
      openstack-neutron-13.0.5~dev50-3.10.2
      openstack-neutron-dhcp-agent-13.0.5~dev50-3.10.2
      openstack-neutron-gbp-5.0.1~dev472-3.10.2
      openstack-neutron-ha-tool-13.0.5~dev50-3.10.2
      openstack-neutron-l3-agent-13.0.5~dev50-3.10.2
      openstack-neutron-linuxbridge-agent-13.0.5~dev50-3.10.2
      openstack-neutron-macvtap-agent-13.0.5~dev50-3.10.2
      openstack-neutron-metadata-agent-13.0.5~dev50-3.10.2
      openstack-neutron-metering-agent-13.0.5~dev50-3.10.2
      openstack-neutron-openvswitch-agent-13.0.5~dev50-3.10.2
      openstack-neutron-server-13.0.5~dev50-3.10.2
      openstack-nova-18.2.3~dev22-3.10.2
      openstack-nova-api-18.2.3~dev22-3.10.2
      openstack-nova-cells-18.2.3~dev22-3.10.2
      openstack-nova-compute-18.2.3~dev22-3.10.2
      openstack-nova-conductor-18.2.3~dev22-3.10.2
      openstack-nova-console-18.2.3~dev22-3.10.2
      openstack-nova-novncproxy-18.2.3~dev22-3.10.2
      openstack-nova-placement-api-18.2.3~dev22-3.10.2
      openstack-nova-scheduler-18.2.3~dev22-3.10.2
      openstack-nova-serialproxy-18.2.3~dev22-3.10.2
      openstack-nova-vncproxy-18.2.3~dev22-3.10.2
      openstack-octavia-3.1.2~dev45-3.10.2
      openstack-octavia-amphora-agent-3.1.2~dev45-3.10.2
      openstack-octavia-api-3.1.2~dev45-3.10.2
      openstack-octavia-health-manager-3.1.2~dev45-3.10.2
      openstack-octavia-housekeeping-3.1.2~dev45-3.10.2
      openstack-octavia-worker-3.1.2~dev45-3.10.2
      openstack-sahara-9.0.2~dev12-3.3.2
      openstack-sahara-api-9.0.2~dev12-3.3.2
      openstack-sahara-engine-9.0.2~dev12-3.3.2
      openstack-tempest-19.0.0-15.2
      openstack-tempest-test-19.0.0-15.2
      openstack-watcher-1.12.1~dev19-4.3.2
      openstack-watcher-doc-1.12.1~dev19-4.3.2
      python-cinder-13.0.7~dev16-3.10.2
      python-cinder-tempest-plugin-0.1.0-11.1
      python-designate-7.0.1~dev22-3.10.2
      python-glance-17.0.1~dev30-3.3.2
      python-heat-11.0.3~dev23-3.10.2
      python-horizon-14.0.4~dev11-3.6.2
      python-horizon-plugin-heat-ui-1.4.1~dev4-4.6.1
      python-horizon-plugin-monasca-ui-1.14.1~dev9-3.6.1
      python-ironic-11.1.4~dev15-3.10.2
      python-keystone-14.1.1~dev16-3.10.2
      python-manila-7.3.1~dev6-4.10.2
      python-neutron-13.0.5~dev50-3.10.2
      python-neutron-gbp-5.0.1~dev472-3.10.2
      python-nova-18.2.3~dev22-3.10.2
      python-octavia-3.1.2~dev45-3.10.2
      python-openstack_auth-14.0.4~dev11-3.6.2
      python-sahara-9.0.2~dev12-3.3.2
      python-tempest-19.0.0-15.2
      python-urllib3-1.23-3.9.1
      python-watcher-1.12.1~dev19-4.3.2

   - SUSE OpenStack Cloud Crowbar 9 (x86_64):

      crowbar-core-6.0+git.1569587091.3f083d63c-3.10.1
      crowbar-core-branding-upstream-6.0+git.1569587091.3f083d63c-3.10.1
      grafana-6.2.5-3.6.1
      grafana-debuginfo-6.2.5-3.6.1
      ruby2.1-rubygem-easy_diff-1.0.0-4.3.2

   - SUSE OpenStack Cloud 9 (noarch):

      ansible1-1.9.6-9.3.1
      ardana-ansible-9.0+git.1568385829.54601ac-3.10.1
      ardana-cluster-9.0+git.1568150980.027f167-3.10.1
      ardana-db-9.0+git.1568382922.6f2cea4-3.10.1
      ardana-extensions-nsx-9.0+git.1568830037.2eea267-11.1
      ardana-glance-9.0+git.1567000146.4569d10-3.10.1
      ardana-input-model-9.0+git.1566409257.eec6360-3.10.1
      ardana-installer-ui-9.0+git.1569535129.ca87ef0-3.10.1
      ardana-installer-ui-debugsource-9.0+git.1569535129.ca87ef0-3.10.1
      ardana-manila-9.0+git.1568835830.10c9689-3.6.1
      ardana-monasca-9.0+git.1567695427.5974ab2-3.10.1
      ardana-neutron-9.0+git.1568817582.a4813e2-3.10.1
      ardana-nova-9.0+git.1567630824.aa6dc2d-3.10.1
      ardana-octavia-9.0+git.1568362662.7fba216-3.10.1
      ardana-opsconsole-ui-9.0+git.1566593422.813e56c-4.10.1
      ardana-osconfig-9.0+git.1567630791.5ca70a6-3.10.1
      ardana-service-9.0+git.1569439941.6800991-3.10.1
      ardana-tls-9.0+git.1569257240.456c4fc-3.6.1
      grafana-monasca-ui-drilldown-1.14.1~dev9-3.6.1
      novnc-1.1.0-3.3.1
      openstack-cinder-13.0.7~dev16-3.10.2
      openstack-cinder-api-13.0.7~dev16-3.10.2
      openstack-cinder-backup-13.0.7~dev16-3.10.2
      openstack-cinder-scheduler-13.0.7~dev16-3.10.2
      openstack-cinder-volume-13.0.7~dev16-3.10.2
      openstack-dashboard-14.0.4~dev11-3.6.2
      openstack-designate-7.0.1~dev22-3.10.2
      openstack-designate-agent-7.0.1~dev22-3.10.2
      openstack-designate-api-7.0.1~dev22-3.10.2
      openstack-designate-central-7.0.1~dev22-3.10.2
      openstack-designate-producer-7.0.1~dev22-3.10.2
      openstack-designate-sink-7.0.1~dev22-3.10.2
      openstack-designate-worker-7.0.1~dev22-3.10.2
      openstack-glance-17.0.1~dev30-3.3.2
      openstack-glance-api-17.0.1~dev30-3.3.2
      openstack-heat-11.0.3~dev23-3.10.2
      openstack-heat-api-11.0.3~dev23-3.10.2
      openstack-heat-api-cfn-11.0.3~dev23-3.10.2
      openstack-heat-engine-11.0.3~dev23-3.10.2
      openstack-heat-plugin-heat_docker-11.0.3~dev23-3.10.2
      openstack-horizon-plugin-heat-ui-1.4.1~dev4-4.6.1
      openstack-horizon-plugin-monasca-ui-1.14.1~dev9-3.6.1
      openstack-ironic-11.1.4~dev15-3.10.2
      openstack-ironic-api-11.1.4~dev15-3.10.2
      openstack-ironic-conductor-11.1.4~dev15-3.10.2
      openstack-ironic-python-agent-3.3.3~dev5-3.10.2
      openstack-keystone-14.1.1~dev16-3.10.2
      openstack-manila-7.3.1~dev6-4.10.2
      openstack-manila-api-7.3.1~dev6-4.10.2
      openstack-manila-data-7.3.1~dev6-4.10.2
      openstack-manila-scheduler-7.3.1~dev6-4.10.2
      openstack-manila-share-7.3.1~dev6-4.10.2
      openstack-neutron-13.0.5~dev50-3.10.2
      openstack-neutron-dhcp-agent-13.0.5~dev50-3.10.2
      openstack-neutron-gbp-5.0.1~dev472-3.10.2
      openstack-neutron-ha-tool-13.0.5~dev50-3.10.2
      openstack-neutron-l3-agent-13.0.5~dev50-3.10.2
      openstack-neutron-linuxbridge-agent-13.0.5~dev50-3.10.2
      openstack-neutron-macvtap-agent-13.0.5~dev50-3.10.2
      openstack-neutron-metadata-agent-13.0.5~dev50-3.10.2
      openstack-neutron-metering-agent-13.0.5~dev50-3.10.2
      openstack-neutron-openvswitch-agent-13.0.5~dev50-3.10.2
      openstack-neutron-server-13.0.5~dev50-3.10.2
      openstack-nova-18.2.3~dev22-3.10.2
      openstack-nova-api-18.2.3~dev22-3.10.2
      openstack-nova-cells-18.2.3~dev22-3.10.2
      openstack-nova-compute-18.2.3~dev22-3.10.2
      openstack-nova-conductor-18.2.3~dev22-3.10.2
      openstack-nova-console-18.2.3~dev22-3.10.2
      openstack-nova-novncproxy-18.2.3~dev22-3.10.2
      openstack-nova-placement-api-18.2.3~dev22-3.10.2
      openstack-nova-scheduler-18.2.3~dev22-3.10.2
      openstack-nova-serialproxy-18.2.3~dev22-3.10.2
      openstack-nova-vncproxy-18.2.3~dev22-3.10.2
      openstack-octavia-3.1.2~dev45-3.10.2
      openstack-octavia-amphora-agent-3.1.2~dev45-3.10.2
      openstack-octavia-api-3.1.2~dev45-3.10.2
      openstack-octavia-health-manager-3.1.2~dev45-3.10.2
      openstack-octavia-housekeeping-3.1.2~dev45-3.10.2
      openstack-octavia-worker-3.1.2~dev45-3.10.2
      openstack-sahara-9.0.2~dev12-3.3.2
      openstack-sahara-api-9.0.2~dev12-3.3.2
      openstack-sahara-engine-9.0.2~dev12-3.3.2
      openstack-tempest-19.0.0-15.2
      openstack-tempest-test-19.0.0-15.2
      openstack-watcher-1.12.1~dev19-4.3.2
      openstack-watcher-doc-1.12.1~dev19-4.3.2
      python-ardana-configurationprocessor-9.0+git.1568955483.5f039e4-3.11.1
      python-cinder-13.0.7~dev16-3.10.2
      python-cinder-tempest-plugin-0.1.0-11.1
      python-designate-7.0.1~dev22-3.10.2
      python-glance-17.0.1~dev30-3.3.2
      python-heat-11.0.3~dev23-3.10.2
      python-horizon-14.0.4~dev11-3.6.2
      python-horizon-plugin-heat-ui-1.4.1~dev4-4.6.1
      python-horizon-plugin-monasca-ui-1.14.1~dev9-3.6.1
      python-ironic-11.1.4~dev15-3.10.2
      python-keystone-14.1.1~dev16-3.10.2
      python-manila-7.3.1~dev6-4.10.2
      python-neutron-13.0.5~dev50-3.10.2
      python-neutron-gbp-5.0.1~dev472-3.10.2
      python-nova-18.2.3~dev22-3.10.2
      python-octavia-3.1.2~dev45-3.10.2
      python-openstack_auth-14.0.4~dev11-3.6.2
      python-sahara-9.0.2~dev12-3.3.2
      python-tempest-19.0.0-15.2
      python-urllib3-1.23-3.9.1
      python-watcher-1.12.1~dev19-4.3.2
      venv-openstack-barbican-x86_64-7.0.1~dev18-3.9.1
      venv-openstack-cinder-x86_64-13.0.7~dev16-3.9.1
      venv-openstack-designate-x86_64-7.0.1~dev22-3.9.1
      venv-openstack-glance-x86_64-17.0.1~dev30-3.9.1
      venv-openstack-heat-x86_64-11.0.3~dev23-3.9.1
      venv-openstack-horizon-x86_64-14.0.4~dev11-4.9.1
      venv-openstack-ironic-x86_64-11.1.4~dev15-4.9.1
      venv-openstack-keystone-x86_64-14.1.1~dev16-3.9.1
      venv-openstack-magnum-x86_64-7.1.1~dev28-4.9.1
      venv-openstack-manila-x86_64-7.3.1~dev6-3.9.1
      venv-openstack-monasca-ceilometer-x86_64-1.8.2~dev3-3.9.1
      venv-openstack-monasca-x86_64-2.7.1~dev10-3.9.1
      venv-openstack-neutron-x86_64-13.0.5~dev50-6.9.1
      venv-openstack-nova-x86_64-18.2.3~dev22-3.9.1
      venv-openstack-octavia-x86_64-3.1.2~dev45-4.9.1
      venv-openstack-sahara-x86_64-9.0.2~dev12-3.9.1
      venv-openstack-swift-x86_64-2.19.2~dev1-2.6.1

   - SUSE OpenStack Cloud 9 (x86_64):

      grafana-6.2.5-3.6.1
      grafana-debuginfo-6.2.5-3.6.1


References:

   https://bugzilla.suse.com/1118900
   https://bugzilla.suse.com/1119737
   https://bugzilla.suse.com/1120657
   https://bugzilla.suse.com/1140267
   https://bugzilla.suse.com/1145967
   https://bugzilla.suse.com/1147144
   https://bugzilla.suse.com/1148158
   https://bugzilla.suse.com/1150895
   https://bugzilla.suse.com/1152032



More information about the sle-security-updates mailing list