[Lvfs-announce] LVFS 1.3.2

Richard Hughes <[email protected]> Tue, 22 Jun 2021 10:09:37 +0100
Newsgroups dev.linux.lists.lvfs-announce
Message-ID <CAD2FfiEokh7GjgB6LkWUjrhPHaxonCkGX0_5PhRvrT2Tv4xo6A@mail.gmail.com>
Hi all,

As usual, most of these changes have been "live" for some time, but I
thought it would be good to recap on some of the new things that you
might have noticed. One highlight is the new "soft-requirement"
feature which allows vendors to recommend that requirements are
followed, but allowing users to ignore that suggestion if required
with --force on the command line. It's only available on the
as-yet-unreleased fwupd 1.6.2 so think twice before you start using
the new feature. In general, hard requirements the user cannot ignore
are preferred in almost all cases.

1.3.2 (2021-06-22)
==================

This release adds the following features:

 * Add an optional PSIRT URL for each vendor
 * Add a plugin which uses uefi_r2 to add shard attributes
 * Add support for component soft-requirements
 * Allow exporting the embargoed firmware using PULP_MANIFEST
 * Allow searching for files by checksum on the internal dashboard
 * Allow vendor managers to purge firmware without asking an admin
 * Do not overwrite when resigning and use unique filenames for each revision

This release fixes the following bugs:

 * Be more helpful when failing to load invalid XML
 * Dedupe the component requirements where allowed
 * Do not allow the update description to contain the firmware name
 * Do not autodecode content when mirroring using sync-pulp.py
 * Explicitly set the CDN Cache-Control to be 4 hours by default
 * Ask vendors to provide 10 useful release description words
 * Include the update images in the PULP_MANIFEST file
 * Resign any files that do not include the PKCS#7 certificate

Comments and questions welcomed off-list.

Richard.