X-Git-Url: https://ruderich.org/simon/gitweb/?p=blhc%2Fblhc.git;a=blobdiff_plain;f=NEWS;h=c1bd2b6ebbf2d4bf638d322f9b6cfa7082e7890d;hp=62dd83b9292d8d481cbf4b941e65b44221e26764;hb=5a6704713eef81b462bea15707af8e941c355bc4;hpb=a232d32f22387fdaf393ee3fa51c0ae9922cf824 diff --git a/NEWS b/NEWS index 62dd83b..c1bd2b6 100644 --- a/NEWS +++ b/NEWS @@ -4,6 +4,24 @@ NEWS Version 0.XX ------------ +- Sync architecture specific hardening support with dpkg 1.19.5. + + +Version 0.09 +------------ + +- Detect restore of -D_FORTIFY_SOURCE=2 after it was overwritten by + -D_FORTIFY_SOURCE=0 or 1 or -U_FORTIFY_SOURCE; reported by Mike Hommey + (Debian bug #898332). +- Detect overwrite of -fstack-protector options with -fno-stack-protector + (same for -fstack-protector-all and -fstack-protector-strong). +- Don't treat hexdumps which contain "cc" as compiler lines; reported by Kurt + Roeckx (Debian bug #899137). + + +Version 0.08 +------------ + - Support new dpkg versions which replaced Dpkg::Arch's debarch_to_debtriplet with debarch_to_debtuple (Debian Bug #844393), reported by Johannes Schauer. - Support Open MPI mpicc/mpicxx compiler wrappers to prevent false positives @@ -16,6 +34,11 @@ Version 0.XX Eriberto Mota for the suggestion. This is not enabled per default to prevent false negatives as the flags are missing from the build log and blhc can't detect if the compiler applied PIE internally (c.f. Debian Bug 845339). +- Add --line-numbers command line option +- Sync architecture specific hardening support with dpkg 1.19.0.5. +- Use proper look back for non-verbose detection if DEB_BUILD_OPTIONS=parallel + is present. Previously it was too small causing false-positives if the + option was detected. Version 0.07