X-Git-Url: https://ruderich.org/simon/gitweb/?p=blhc%2Fblhc.git;a=blobdiff_plain;f=NEWS;h=1c8247f11a5eb97bac4409c72896cf237155cc53;hp=f980c0780c784fd2f3e3d8da890d06ee91762ec8;hb=14b61d421e2479318cb2971acc1c94812f5a8ac1;hpb=290a8e3484c700ebb91c3460820310e03ca38cb2 diff --git a/NEWS b/NEWS index f980c07..1c8247f 100644 --- a/NEWS +++ b/NEWS @@ -4,6 +4,14 @@ NEWS Version 0.XX ------------ +- Detect restore of -D_FORTIFY_SOURCE=2 after it was overwritten by + -D_FORTIFY_SOURCE=0 or 1 or -U_FORTIFY_SOURCE; reported by Mike Hommey + (Debian bug #898332). + + +Version 0.08 +------------ + - Support new dpkg versions which replaced Dpkg::Arch's debarch_to_debtriplet with debarch_to_debtuple (Debian Bug #844393), reported by Johannes Schauer. - Support Open MPI mpicc/mpicxx compiler wrappers to prevent false positives @@ -12,6 +20,15 @@ Version 0.XX - Add better support for Fortran (c.f. Debian Bug #853265). - Don't report missing PIE flags in buildd mode if GCC defaults to PIE (c.f. Debian Bug 845339). +- Add new --debian option to handle PIE flags like buildd mode, thanks to + Eriberto Mota for the suggestion. This is not enabled per default to prevent + false negatives as the flags are missing from the build log and blhc can't + detect if the compiler applied PIE internally (c.f. Debian Bug 845339). +- Add --line-numbers command line option +- Sync architecture specific hardening support with dpkg 1.19.0.5. +- Use proper look back for non-verbose detection if DEB_BUILD_OPTIONS=parallel + is present. Previously it was too small causing false-positives if the + option was detected. Version 0.07