libopenscap25-1.3.6-150400.11.5.1<>,ĉf|.p9|tl勚pZ;HQj _'P྄= hHTӄE-W]- U x~G?15l^9ZxɚOwt$f-uvX3,#<$E9JPzmLˠy?qQ?{=2\0eN|EbR9UZl eMTd^*8>y&`f<QZC|\&;2\ETk^PfE~̬})3mJ >@|?ld $ 7pt  ( , 0 8 z  ; ; ;( 8 59 5:5>~@~F~G~H~I~X~Y~\] ^4b@cdleqftlvuvw$x,y46z  &hClibopenscap251.3.6150400.11.5.1OpenSCAP C LibraryThe OpenSCAP C Library for easy integration with SCAP.f|.s390zp35SUSE Linux Enterprise 15SUSE LLC LGPL-2.1-or-laterhttps://www.suse.com/System/Librarieshttps://www.open-scap.org/linuxs390xf|f|147c16850efc1ce6a1b640f4de0f5507db51bd54809bebb00be45e6af00d2d91libopenscap.so.25.5.0rootrootrootrootopenscap-1.3.6-150400.11.5.1.src.rpmlibopenscap.so.25()(64bit)libopenscap25libopenscap25(s390-64)@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@    /sbin/ldconfig/sbin/ldconfiglibacl.so.1()(64bit)libacl.so.1(ACL_1.0)(64bit)libblkid.so.1()(64bit)libblkid.so.1(BLKID_1.0)(64bit)libbz2.so.1()(64bit)libc.so.6()(64bit)libc.so.6(GLIBC_2.2)(64bit)libc.so.6(GLIBC_2.2.3)(64bit)libc.so.6(GLIBC_2.3)(64bit)libc.so.6(GLIBC_2.3.3)(64bit)libc.so.6(GLIBC_2.3.4)(64bit)libc.so.6(GLIBC_2.4)(64bit)libc.so.6(GLIBC_2.7)(64bit)libcap.so.2()(64bit)libcurl.so.4()(64bit)libdbus-1.so.3()(64bit)libdbus-1.so.3(LIBDBUS_1_3)(64bit)libexslt.so.0()(64bit)libgcrypt.so.20()(64bit)libgcrypt.so.20(GCRYPT_1.6)(64bit)libpcre.so.1()(64bit)libprocps.so.8()(64bit)libprocps.so.8(LIBPROCPS_0)(64bit)libpthread.so.0()(64bit)libpthread.so.0(GLIBC_2.12)(64bit)libpthread.so.0(GLIBC_2.2)(64bit)libpthread.so.0(GLIBC_2.3.2)(64bit)libpthread.so.0(GLIBC_2.3.3)(64bit)librpm.so.8()(64bit)librpmio.so.8()(64bit)libselinux.so.1()(64bit)libselinux.so.1(LIBSELINUX_1.0)(64bit)libxml2.so.2()(64bit)libxml2.so.2(LIBXML2_2.4.30)(64bit)libxml2.so.2(LIBXML2_2.5.0)(64bit)libxml2.so.2(LIBXML2_2.5.7)(64bit)libxml2.so.2(LIBXML2_2.5.8)(64bit)libxml2.so.2(LIBXML2_2.6.0)(64bit)libxml2.so.2(LIBXML2_2.6.17)(64bit)libxml2.so.2(LIBXML2_2.6.20)(64bit)libxml2.so.2(LIBXML2_2.6.21)(64bit)libxml2.so.2(LIBXML2_2.6.23)(64bit)libxml2.so.2(LIBXML2_2.6.24)(64bit)libxml2.so.2(LIBXML2_2.6.3)(64bit)libxml2.so.2(LIBXML2_2.6.5)(64bit)libxml2.so.2(LIBXML2_2.9.1)(64bit)libxmlsec1-openssl.so.1()(64bit)libxmlsec1.so.1()(64bit)libxslt.so.1()(64bit)libxslt.so.1(LIBXML2_1.0.11)(64bit)libxslt.so.1(LIBXML2_1.0.18)(64bit)libxslt.so.1(LIBXML2_1.0.22)(64bit)libxslt.so.1(LIBXML2_1.1.18)(64bit)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)3.0.4-14.6.0-14.0-15.2-14.14.3c*c#aNaaLaZaG``r`__/@_Q_w@^^{G^@^^]:\@\[@[[@[ @Z@Z1@Z1@ZZ@Z Z Y@X@XXoX2XW@V@V%@V`.V@Vf@UmUUF U#T@T}T|X@Ty@dmueller@suse.commeissner@suse.comrfrohl@suse.comdcermak@suse.commeissner@suse.commeissner@suse.comsteven.kowalik@suse.comrfrohl@suse.comrfrohl@suse.comrfrohl@suse.commeissner@suse.commeissner@suse.commeissner@suse.comrfrohl@suse.commeissner@suse.comchristophe@krop.frmeissner@suse.commeissner@suse.commeissner@suse.comrfrohl@suse.comrfrohl@suse.combjorn.lie@gmail.comrfrohl@suse.commeissner@suse.commeissner@suse.commeissner@suse.commeissner@suse.comjengelh@inai.demeissner@suse.commeissner@suse.comrbrown@suse.commeissner@suse.commeissner@suse.commeissner@suse.comjengelh@inai.demeissner@suse.commeissner@suse.commeissner@suse.commeissner@suse.commeissner@suse.commeissner@suse.commeissner@suse.commeissner@suse.commeissner@suse.commeissner@suse.commeissner@suse.commeissner@suse.commeissner@suse.commeissner@suse.commeissner@suse.commeissner@suse.commeissner@suse.comledest@gmail.com- require shared library in the same version or newer- added Leap 15.4 and 15.5 dictionary entries. (bsc#1203408)- openscap 1.3.6 * New features - Select and exclude groups of rules on the command line - The boot-time remediation service for systemd's Offline Update mode - Memory limit control using OSCAP_PROBE_MEMORY_USAGE_RATIO environment variable - Allow disablement of SHA-1 and MD5 - Allow providing pre-downloaded components - Introduce OSBuild Blueprint fix type * Maintenance, bug fix - Fix coverity issues - Patch the `segfault` in dpkginfo_fini() - Add an alternative source of hostname - Fail download on HTTP errors - Compile "environmentvariable_probe" on Windows - FreeBSD build and test fixes - Add offline mode for password probe - Initialize crypto API only once - Fix UBI 9 scan - oval/yamlfilecontent: Add 'null' values handling - Do not set Rpath - Do not split `XCCDF:requires` with multiple `idrefs` - Allow empty /proc in offline mode - oscap-remediate is shipped via /usr/bin Added oscap-remediate.service.in.patch- Rename oscap-docker to oscap-containers and provide oscap-podman as well (Relates to jsc#SLE-12852)- openscap-docker-add-suse.patch: add SLES support oscap-docker (bsc#1179314)- ship python3 docker module always- Since upstream has moved to Python 3, switch the BuildRequires from python-devel to python3-devel.- Add definition for tumbleweed to openscap-opensuse-cpe.patch (boo#1186735)- add old patches - slightly renamed; cpe are needed (boo#1186735) * openscap-opensuse-cpe.patch * openscap-suse-cpe.patch- openscap 1.3.5 * New features - Made schematron-based validation enabled by default for validate command of oval and xccdf modules - Added SCAP 1.3 source data stream Schematron - Added XML Signature Validation - Added --enforce-signature option for eval, guide, and fix modules - Added entity support (OVAL/yamlfilecontent) - Allowed to clamp mtime to SOURCE_DATE_EPOCH - Added severity and role attributes - Added support for requires/conflicts elements of the Rule and Group (XCCDF) - Added Kubernetes remediation to HTML report * Maintenance, bug fix - Fixed CMake warnings - Made 'gpfs', 'proc' and 'sysfs' filesystems non-local - Fixed handling of '--arg=val'-styled common options - Documented used environment variables - Updated man page and help texts - Added --skip-validation option synonym for --skip-valid - Fixed behavior of StateType operator - Fixed some of the coverity warnings - Ignoring namespace in XPath expressions - Fixed how oval_probe_ext_eval checks absence of the response from the probe (obtrusive data warning) - Described SWID tags detection - Improved documentation about --stig-viewer option - File probe behaviour fixed (symlink traversal now behaves as defined by OVAL) - Fixed multiple segfaults and broken test in --stig-viewer feature - Added dpkg version comparison algorithm - Pluged some memory leaks - Fixed TestResult/benchmark/@href attribute - Fixed memory allocation - Fixed field names for cases where key selection section is followed by a set section (probes/yamfilecontent) - Changing hard coded libperl path in favor of FindPerlLibs method - Check local filesystems when using 'filepath' element - dropped, because not needed anymore: * 0001-Fix-memory-allocation.patch * openscap-new-suse.patch * openscap-leap-cpe-15.12.patch- 0001-Fix-memory-allocation.patch: fixed a crash during oscap oval eval- openscap-leap-cpe-15.12.patch: add CPE dict entries for openSUSE Leap 15.1 and 15.2- add dbus-1-devel buildrequires to enable systemd tests (bsc#1178301)- openscap 1.3.4 * New features - Add support for FreeBSD - Make use of HTTP header content-encoding: gzip if available - Improved yamlfilecontent: updated yaml-filter, extend the schema and probe to be able to work with a set of values in maps * Maintenance, bug fixes - A lot of memory leaks have been plugged - Refactored rpmverifyfile probe and fixed memory leak - Fixed SEGFAULT caused by recursive and circular dependencies between OVAL definitions - Fixed DOM representation of the profile platform - Test suit: better portability, more granularity in results, inclusion of memory-related tests - Compatibility with uClibc - Local and remote file system detection method was improved - Make the report a valid HTML5 document- openscap 1.3.3. Notable improvements in this release: - a Python script that can be used for CLI tailoring (autotailor) (thank you, Matěj Týč); - timezone for XCCDF TestResult start and end time (thank you, Jan Černý); - new yamlfilecontent independent probe (draft implementation), see the proposal https://github.com/OVAL-Community/OVAL/issues/91 for additional information. There are other changes as well, here is the list: - Introduced `urn:xccdf:fix:script:kubernetes` fix type in XCCDF; - Added ability to generate `machineconfig` fix; - Detect ambiguous scan target (utils/oscap-podman); - Fixed #170: The rpmverifyfile probe can't verify files from '/bin' directory; - The data system_info probe return for offline and online modes is consistent and actual; - Prevent crashes when complicated regexes are executed in textfilecontent58 probe; - Fixed #1512: Severity refinement lost in generated guide; - Fixed #1453: Pointer lost in Swig API; - Evaluation Characteristics of the XCCDF report are now consistent with OVAL entities; from system_info probe; - Fixed filepath pattern matching in offline mode in textfilecontent58 probe; - Fixed infinite recursion in systemdunitdependency probe; - Fixed the case when CMake couldn't find libacl or xattr.h. - dropped 0001-Do-not-use-C-keyword-operator-as-a-function-paramete.patch: upstream- Add upstream patch to fix the scap-workbench build: * 0001-Do-not-use-C-keyword-operator-as-a-function-paramete.patch- switch back to official release - openscap 1.3.2 - the test suite and build scripts were improved to support Debian 10 - offline mode has received some love with a set of dedicated tests and various fixes in OVAL probes; - the oscap-docker wrapper is no longer dependent on Atomic - Python binding are now more robust - HTML reports and guides, generated by the scanner, are now more accessible for non-visual rendering agents - Support of multi-check rules has been improved across the whole workflow There are other changes as well, here is the list: * New features - Offline mode support for environmentvariable58 probe - The oscap-docker wrapper is available without Atomic + Maintenance, bug fixes - Improved support of multi-check rules (report, remediations, console output) - Improved HTML report look and feel, including printed version - Less clutter in verbose mode output; some warnings and errors demoted to verbose mode levels - Probe rpmverifyfile uses and returns canonical paths - Improved a11y of HTML reports and guides - Fixes and improvements for SWIG Python bindings - #1403 fixed: Scanner would not apply remediation for multicheck rules (verbosity) - Fixed URL link mechanism for Red Hat Errata - New STIG Viewer URI: public.cyber.mil - Probe selinuxsecuritycontext would not check if SELinux is enabled - Scanner would provide information about unsupported OVAL objects - Added more tests for offline mode (probes, remediation) - #528 fixed: Eval SCE script when /tmp is in mode noexec - #1173, RHBZ#1603347 fixed: Double chdir/chroot in probe rpmverifypackage- temporary openscap 1.3.1 git snapshot - make it build with new RPM (bsc#1160720)- use distribution-release instead of dummy-release- openscap 1.3.1 - New features - Support for SCAP 1.3 Source Datastreams (evaluating, XML schemas, validation) - Introduced `oscap-podman` -- a tool for SCAP evaluation of Podman images and containers - Tailoring files are included in ARF result files - OVAL details are always shown in HTML report, users do not have to provide `--oval-results` on command line - HTML report displays OVAL test details also for OVAL tests included from other OVAL definitions using `extend_definition` - OVAL test IDs are shown in HTML report - Rule IDs are shown in HTML guide - Added `block_size` in Linux `partition_state` defined in OVAL 5.11.2 - Added `oscap_wrapper` that can be used to comfortably execute custom compiled oscap tool - Maintenance and bug fixes for a complete list please see https://github.com/OpenSCAP/openscap/releases/tag/1.3.1 - removed patches accepted upstream: rpmverifyfile_unittest.patch rpmverify_unittest.patch sysctl_unittest.patch test_probes_rpmverifypackage-disable-epoch-test.patch xinetd_probe.patch- obsolete removed packages: openscap-engine-sce and openscap-extra-probes- Drop gconf2-devel BuildRequires: It is not mandatory, so lets build without this obsolete package. - Add pkgconfig(glib-2.0) and pkgconfig(gobject-2.0) BuildRequires: They are also optional, but not obsolete, and previously pulled in via gconf2-devel dependency, so lets build support for them.- openscap-1.3.0 - New features - Introduced a virtual '(all)' profile selecting all rules - Verbose mode is a global option in all modules - Added Microsoft Windows CPEs - oscap-ssh can supply SSH options into an environment variable - Maintenance - Removed SEXP parser - Added Fedora 30 CPE - Fixed many Coverity defects (memory leaks etc.) - SCE builds are enabled by default - Moved many low-level functions out of public API - Removed unused and dead code - Updated manual pages - Numerous small fixes - xinetd_probe.patch: fix trailing whitespace in config - test_probes_rpmverifypackage-disable-epoch-test.patch: fix rpmverifypackage unit test - sysctl_unittest.patch: fix sysctl unit test - rpmverifyfile_unittest.patch: fix rpmverifyfile unit test - rpmverify_unittest.patch: fix rpmverify unit test - openscap-xattr.patch: removed, included by upstream- openscap-xattr.patch: build against new libattr- scap-yast2sec-xccdf.xml: remove platform cpe match, as it is impossible to match both opensuse and sles or official suse_linux_enterprise_server names at once. (bsc#1091040)- openscap-1.2.17 - New features - HTML Guide user experience improvements - New options in HTML report "Group By" menu - oscap-ssh supports --oval-results (issue #863) - Maintenance - Support comparing state record elements with item - Updated Bash completion - Make Bash role headers consistent with --help output - Fixed problems reported by Coverity (issue #909) - Fixed CVE schema to support 4 to 7 digits CVEs - Fix output of generated bash role missing fix message - Fix oscap-docker to clean up temporary image (RHBZ #1454637) - Fix Ansible remediations generation - Add a newline between ids in xccdf info (issue #968) - Fix unknown subtype handling in oval_subtype_parse (issue #986) - Outsourced the pthreads feature check and setup - Speed up in debug mode - Refactored the Python handling in build scripts - Prevent reading from host in offline mode (issue #1001) - Many probes use OWN offline mode - Improve offline mode logic in OVAL probes - Do not use chroot in system_info probe - Prevent a segfault in oscap_seterr on Solaris - Out of tree build is possible - Use chroot for RPM probes in offline mode - PEP8 accepts lines up to 99 characters - New configure parameter --with-oscap-temp-dir (issue #1016) - Fixed OVAL record elements namespace and SEXP conversion - Removed '\r' characters from help output (issue #1023) - Full Python 3 compatibility - Removed basic Python implementation of oval_probes.c - Added support for Travis CI and Sonar Cloud - Minor fixes inspired by Sonar Cloud - Added Fedora 29 CPE - New tests in upstream test suite (offline mode, Ansible, etc.)- openscap-new-suse.patch: handle SLE15 and openSUSE Leap 42.3 and 15.0 (bsc#1091040)- Replace old $RPM_* shell vars.- replace oscap-scan.init by oscap-scan.service, add a /usr/bin/oscap-scan helper tool for this. (bsc#1083115)- disable scap-as-rpm binary to avoid python2 dependency. (bsc#1082135)- Replace references to /var/adm/fillup-templates with new %_fillupdir macro (boo#1069468)- openscap-productid-cvrf.patch: add a --productid selector for "oscap cvrf" as upstream does not detect the system yet. (might go away)- openscap-1.2.16 - New features - oscap can generate output that is compatible with STIG Viewer. - CVRF parsing and export has been implemented. - oscap info command has been expanded. - The AIX platform is supported. - Many documentation improvements. - Numerous other improvements of existing features. - Maintenance - Huge cross-platform improvements. - Memory leaks fixed (RHBZ#1485876). - SELinux fixes. - Many coverity fixes. - Numerous other bugfixes. - buildrequire procps-devel- openscap-1.2.15 / 25-08-2017 - New features - short profile names can be used instead of long IDs - new option --rule allows to evaluate only a single rule - new option --fix-type in "oscap xccdf generate fix" allows choosing remediation script type without typing long URL - "oscap info" shows profile titles - OVAL details in HTML report are easier to read - HTML report is smaller because unselected rules are removed - HTML report supports NIST 800-171 and CJIS - remediation scripts contain headers with useful information - remediation scripts report progress when they run - basic support for Oracle Linux (CPEs, runlevels) - remediation scripts can be generated from datastreams that contain multiple XCCDF benchmarks (issue #772) - basic support for OVAL 5.11.2 (only schemas, no features) - enabled offline RPM database in rpminfo probe (issue #778) - added Fedora 28 CPE - Maintenance - fixed oscap-docker with Docker >= 2.0 (issue #794) - fixed behavior of sysctl probe to be consistent with sysctl tool - fixed generating remediation scripts (issue #723, #773) - severity of tailored rules is not discarded (issue #739) - fixed errors in RPM probes initialization - oscap-docker shows all warnings reported by oscap (issue #713) - small improvements in verbose mode - standard C operations are used instead of custom OpenSCAP operations - fixed compiler warnings - fixed missing header files - fixed resource leaks (issue #715) - fixed pkgconfig file (RHBZ #1414777) - refactoring - documentation fixes and improvements- Remove line-trailing whitespace from last changelog entry. - Rename %soname to %sover to better reflect its use. - Replace unnecessary %__-type macro indirections.- openscap-1.2.14 / 21-03-2017 - New features - Detailed information about ARF files in 'oscap info' (issue #664) - XSLT template creating XCCDF files from OVAL files - Generating remediation scripts from ARF - Significant improvements of User Manual (issue #249, #513) - HTML report UX improvements (issue #601, #620, #622, #655) - Warnings are shown by default - Verbose mode is available in 'xccdf remediate' module (issue #520) - Added Fedora 26, Fedora 27 and OpenSUSE 42.2 CPEs (issue #698) - Support for Anaconda remediation in HTML report - Maintenance - Fixed CPE dictionary to identify RHEVH as RHEL7 (RHBZ #1420038) - Fixed systemd probes crashes inside containers (RHBZ #1431186, issue #700) - Added a warning on non-existing XCCDF Benchmarks (issue #614) - Fixed output on terminals with white background (RHBZ #1365911, issue #512) - Error handling in oscap-vm (RHBZ #1391754) - Fixed SCE stderr stalling (RHBZ #1420811) - Fixed Android OVAL schema (issue #279) - Fixed absolute filepath parsing in OVAL (RHBZ #1312831, #1312824) - Fixes based on Coverity scan report (issue #581, #634, #681) - Fixed duplicated error messages (issue #707) - Fixed XCCDF score calculation (issue #617) - Fixed segmentation faults in RPM probes (RHBZ #1414303, #1414312) - Fixed failing DataStream build if "@" is in filepath - Fixed missing header in result-oriented Ansible remediations - Memory leak and resource leak fixes (issue #635, #636) - New upstream tests - Many minor fixes and improvements- openscap-1.2.13 / 05-01-2017 - Maintenance - we always build system_info OVAL probe, fixed configure output accordingly - warn when the user requests to generate an ARF from XCCDF 1.1 - fixed a segfault when loading an OVAL file with invalid family attribute - added --thin-results CLI override to oscap xccdf eval - added --without-syschar CLI override to oscap xccdf eval - fixed a segfault when freeing xccdf_policy of the default profile - removed ARF schematron workaround when there are no applicable checks - fixed verbose output in oscap xccdf generate fix - do not filter fix by applicability when generating remediations from results - fixed memory leaks, resource leaks and other minor issues- openscap-1.2.12 / 21-11-2016 - New features - separated stdout and stderr in SCE results and HTML report - HTML reports contain [ref] links for rules and groups - Maintenance - fixed ARF errors reported by the SCAPval tool - fixed CVE parsing (issue #550) - fixed namespace of ARF vocabulary according to NIST SP800-126 errata - fixed exporting OVAL Windows namespaces - fixed injecting xccdf:check-content-ref references in ARF results - fixed oscap-docker incompliance reporting (issue #475, RHBZ #1387248) - fixed oscap-docker man page (RHBZ #1387166) - fixed memory leaks and resource leaks - small fixes and refactoring, test suite fixes- openscap-1.2.11 / 14-10-2016 - New features - huge speed-up of generating HTML reports and guides - support remote datastream components (issue #526) - support tailoring of external datastreams - various attributes of remediation scripts are now shown in HTML report (issue #541) - new option generating OVAL results without system characteristics - remediation scripts in HTML report are now collapsed - support for extracting Ansible playbooks - enabled fetching remote resources in OVAL module - added Wind River Linux CPE - Maintenance - updated jQuery and bootstrap libraries in HTML reports - extended, improved and updated user manual - fixed issues with proxy in oscap-docker (RHBZ #1351952) - fixed a bug in OVAL arithmetic function - fixed a segmentation fault (issue #529) - fixed results of XCCDF rules with @role="unscored" (issue #525) - fixed invalid characters in OVAL results (issue #468) - fixed a segmentation fault in tailoring (RHBZ #1367896) - updated SUSE 11 CPE - fixed many memory issues - large refactoring of datastream module - new tests in upstream test suite - various small fixes and improvements - openscap-1.2.10 / 29-06-2016 - New features - support --benchmark-id when running `oscap xccdf generate guide` - added CPE support for OpenSUSE 42.1 - Maintenance - oscap-docker fixed to be source compatible with both Python 2 and 3 - fixed offline mode in rpmverifypackage probe - fixed scanning of non-RHEL containers in oscap-docker (issue #427) - fixed regression in loading a datastream session (RHBZ #1250072) - fixed missing SCE results in XCCDF reports (issue #394) - fixed a segmentation fault (issue #370) - fix error message when OVAL generator element is missing (issue #345) - fixed failing rpminfo probe - fixed compilation on RHEL5 (issue #393) - new tests in upstream test suite - test suite is able to run on Fedora 24 - fixed remediation scripts appearance in HTML guides (issue #460) - fixed autoconf build - small fixes, refactoring, small documentation improvements- openscap 1.2.9 release - New features - oscap-chroot - a tool for offline scanning of filesystems mounted at arbitrary paths - enabled offline scanning in many probes - support for SCE in data streams - many improvements of verbose mode - verbose messages can be written on stderr - runlevel probe supports SUSE systems - new upstream tests - Maintenance - a lot of refactoring - fixes in various tests - OCILs are correctly placed in datastreams (issue #364) - oscap-vm can work with fusermount when guestunmount is not available - fixed oscap-docker HTTP communication issues (issue #304) - fixed oscap-docker tracebacks (issue #303, #317) - fixed container mounting in oscap-docker (issue #329) - added Fedora 25 CPE - only non-empty profiles are built (rhbz#1256879, rhbz#1302230) - fixed compiler errors on RHEL5 and SLES11 - fixed sorting of groups in HTML report (issue #342) - fixed version/@time and version/@update in XCCDF Benchmark - fixed CPE definitions to work also in offline mode - fixed sysctl probe (issue #258) - fixed manual page for oscap-ssh (rhbz#1299969) - updated user manuals and manual pages - updated .gitignore - dropped fix-missing-include.dif, not needed anymore- enable the SCE (script checking engine) packaged in "openscap-engine-sce" subpackage. - enable the CCE (Common Configuration Enumeration)- openscap 1.2.8 release - Maintenance - textfilecontent54_probe does not produce false positives on non-UTF files (rhbz #1285757) - fixed oscap-docker - small improvements in verbose mode - oscap info module shows information about tailoring files - fixed build with CCE (issue #264) - fixed XCCDF score computation (issue #272) - fixed segmentation fault in variable probe (issue #277) - fixed broken support for OVAL directives - fixed bash completion - plugged memory leaks - fixed fresh static analysis (coverity) findings - fixed shellcheck warnings - new tests - refactoring in datastream module - many small bugfixes and typo fixes- openscap 1.2.7 release - New features - OVAL 5.11.1 fully supported - oscap-vm - tool for offline scanning of virtual machines - verbose mode - added SLED, SLES and OpenSUSE CPE names - show profile description in HTML report and guide - group rules by PCI DSS identifier in HTML report - preliminary support for Ansible Playbooks within xccdf:fix - added "How to contribute" and "Versioning" documents - Maintenance - using bziped RHSA documents in oscap-docker - fixed errors of sysctl probe - fixed skip-valid option (issue #203) - fixed segmentation faults in SCE content reporting (issue #231) - fixed tracebacks of scap-as-rpm - fixed invalid memory reads in rpmverifyfile probe (issue #212) - updated README and user manual - many small bugfixes and new tests - openscap-new-inventory.patch: upstreamed - fix-missing-include.dif: refreshed, 1 hunk upstream- openscap-new-inventory.patch: find out the CPE ids of SUSE Linux Enterprise and openSUSE versions.- openscap 1.2.6 release - New features - introduced OpenSCAP user manual - improved OVAL 5.11.1 support - added OVAL 5.11.1 XSD schemas and schematrons - support for core/platform schema versions - support for check_existence attribute in state entities - support for CIM datetime format - amended behavior of mask attribute - added support for remote .xml.bz2 files (use with --fetch-remote-resources) - rewrote oscap-docker to python, deeper integration with Atomic Host - introduced CPE name for Fedora 24 to the internal dictionary - HTML report & guide - results can be grouped by according to various aspects - printing supported (interactive elements are now hidden when printing) - table of content now shows only selected items (rule & groups) - references to RHSA are presented as links to website (rhbz#1243808) - Maintenance - scap-as-rpm can now build source rpm packages (srpms) (trac#469) - scap-as-rpm now supports python3 - refactored oval processing into oval_session structure - many smaller bugfixes and new tests - new openscap-docker subpackage- openscap-1.2.5 update - maintenance - smaller bugfixes - plugged memory leaks - fixed fresh static analysis (coverity) findings - fixed shellcheck warnings - fixes for Solaris platform- openscap-1.2.4 update - new features - OVAL 5.11 support 99.8% completed! - new symlink probe introduced - new process58 test capabilities - added possible_value support for external variables - added possible_restriction support for external variables - improved IP address comparisons - Added Scientific Linux CPEs - Added oscap-docker tool - Created man-page for oscap-ssh - HTML changes - improved visibility of selected XCCDF profile in guides and reports - render rule-result/message contents in reports - maintenance - Tests now pass on ppc64 little endian arch (rhbz#1215220) - partition probe now supports remount, bind and move mount options - Patched NIST OVAL-5.11 schemas to be backward compatible with OVAL-5.10 (rhbz#1220262) - fixed scap-as-rpm to work with vintage python (2.6) - better error reporting when a probe dies (i.e. due to OOM killer) - dropped selinux policy from upstream (rhbz#1209969) - fix segfault on invalid selectors (rhbz#1220944) - solaris support patches: file-system zones, systeminfo improvements - many smaller fixes and new tests- openscap-1.2.3 update - new features - oscap-ssh -- handy utility to run remote scan over ssh - glob_to_regexp OVAL function added - HTML changes - show rationale elements - show fixtext elements - show Benchmark's front-matter, description and notices - show warnings for Groups and Rules - improved handling of multiple fixes within a single Rule - scroll evaluation characteristic if they overflow - maintenance - OVAL 5.11 schema fixes - Coverity and memory leak fixes - skip transient files when traversing /proc (trac#457)- openscap-1.2.2 update - new features - OVAL 5.11 support turned on by default - included OVAL 5.11 schematron rules - DataStream can now contain OVAL 5.11 - `oscap ds sds-compose` now supports --skip-valid parameter - HTML report changes - Notably increased level of OVAL details - Table of contents is now generated for HTML guides - maitenance - rhbz#1182242, rhbz#1159289 - @var_check & @var_ref exporting - solaris build fixes - xccdf:fix/instance processing fixes - improved (none) epoch processing in rpm probe - environmentvariable58 now emits warning messages when appropriate - offline mode improvements - other bugfixes- openscap-1.2.1 update - API changes - 5.11 schemas updated (from RC1 to gold) - oscap_source_new_from_memory can take bzip2ed content - HTML report changes - severity bar is now reversed (left-to-right) - maintenance - rhbz#1165139 - fix probe cancelation - dozen of bugfixes- openscap-1.2.0 update - new features - native support of bzip2ed SCAP files (file extension needs to be '.xml.bz2') - improved performance on huge XML documents, especially DataStreams - minimized use of temp files to absolute minimum - added OVAL-5.11 release candidate schemas - API changes - overall 50 new symbols added to public API - introduced oscap_source abstraction for input files - further info: http://isimluk.livejournal.com/4859.html - all the parsers converted to use oscap_source abstraction - introduced ds_sds_session, high level API for playing with Source DataStreams - introduced cpe_session, abstraction to approach multiple CPE resources - introduced ds_rds_session, high level API for playing with Result DataStreams (ARF files) - deprecated dozens of API calls dependent on filepath - introduced API for waivers (xccdf:override) and modification of ARF - initial support for waivers in HTML Report - dozens of small improvements - maintenance - dozens of small fixes - dozens of memory leaks (whole test suite is now leak free) - updated gnulib - openscap-1.1.0-fix-bashisms.patch: upstreamed- openscap-1.1.1 update - Hint towards `oscap info` when profile is not found in oscap tool - HTML report changes: - Source OVAL results from ARF if available - Highlight notchecked rules, treat them as rules that need attention - HTML guide changes: - Variable Substitution improvements - Show benchmark title - Show info about selected profile - Avoid cdf12:notice, show only its contents - bugfixes: - improved handling of fqdn in XCCDF - memory leaks - static analysis fixes- fix bashism in oscap-scan.cron script - add patches: * openscap-1.1.0-fix-bashisms.patch/sbin/ldconfig/sbin/ldconfigs390zp35 17194094541.3.6-150400.11.5.11.3.6-150400.11.5.1libopenscap.so.25libopenscap.so.25.5.0/usr/lib64/-fmessage-length=0 -grecord-gcc-switches -O2 -Wall -D_FORTIFY_SOURCE=2 -fstack-protector-strong -funwind-tables -fasynchronous-unwind-tables -fstack-clash-protection -gobs://build.suse.de/SUSE:Maintenance:34486/SUSE_SLE-15-SP4_Update/f409e49276c156675c5887317de897cd-openscap.SUSE_SLE-15-SP4_Updatedrpmxz5s390x-suse-linuxELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=6fe6d4348ec74af8a9cc516903846e6a5b10f6da, stripped6PRRRR!RR RR R R R RR4R5R3R6R(R.R+R,R%R/R)R&R-R*R$R#R'RRRRRR"R2R1R0RRRRRRRRR RRRRRR7͏*Y hutf-8c2ef902bd816d9913489c656cd5b7d39ecbbf301622e6190b44ec8033f6e4e80?7zXZ !t/}]]"k%4"tz-q3"~р1]t m f¸bVU CmhTBAB̃5Kբ~<d`1}OʸY $^-/S0kƴ\~AŌ_ap:=,B;^ w O *M`#kNQ;t^?qFjV=JvU2g%3FT)E'{CU_k$fMݼr/v]4eiFozqdNy}Nh^4(Q ~tx⇆{p &Z¨., 9q^Ag4bbCYF3疎_hGbf]WvIybȕSppc 1B(N+U)/3(4 4Fn7KD}wRJ2x5(g(8VFלAE!W:O-XĄi[=m ZPc2][^̸ 27^H{#a`d4]["0>Ё\0cpޞLV#1< 8NtJ+su,|`k;2ySst݂%Q >*#\ο ]$i(% ^RҏAX,~rq!A6u'-[C;퍽7pͼrOɎMsbLqBkBB`oQ=08(4⁅S_Hu%r#QR'/P$Pag"!Jsml\pVfh0?vV_ܭ(?J}gd#dB f+#m6Ϸ9Kr 8|}>l0F5FG!Oi HZ-Sq|ZZ'օ@yZF8^(FRb|<6ešq\e^vb(EXxS)rBMܶU xhL׿ BBO#eZnSQ'h:65\J|Rǝ :HSؖy4J(\f n̤ W#ݜM\ L.LXW;;O^OL^IYgRP5=힜Rk?NkT-IwhtYJ6c$,ŊD+._ARRvm!QxwJ Y+@{ifq\_w2RWSvWjjfw߃՜ mW}m$ZGk8^͗18Dz1]k}=\M@(Xem=8҃%gFA)aj1S 5gg*A&:9bⲉj VA᲍]$g}z<75:o`W&]&wrZ8$q=ݞ.##uI7$WTtUhǚWCI!)l$S%oH94#z?b1=xɓinZy}.vL`4Ξ 2,Ng#\]-j~fvbPҴԦ]1;N)a wܚ%-שSXD8O(nLUx2tM IOq;Gq-8ߎL@T03KNhy-g˯'g4~M3Oi2,ZX}!|Qtkr)l$g(tؔ&(ONU8@#)0ҟ=m~*OSk[?#9=i6nM*$#ӭ|5Z jV,BЌJv_k"H)ZpzDmֺ!fLv@/%Q LQ@]W/LϹʙ8FZaȒ]p $DzA*W.~^S?Q$ ɹps Pm Q^@ֿu^PVOWM`C1wq՘@N=GyQAR2H#?zR%_M[ ρ?l1%D"-l^UO.jn"k*Rk7%"Rztpn O{Rb!j|k6rr7$V:Zx\$5LGڗA|!bDz@'U#u/qLb0[6gg!==/RZgn-p`AUUY4Y]R"dJ3Vl!f;nakWQYd_~é|BX P&Uʝ:]\c7qx3-2*ͳPwu.W?e*/Ǐwݔk\Y΍fj8BNgJ;͵qޮdƳf̓@;OsQmu(eFd9ZeN'(%[{XgJ9^G+0G=C}T6OHV]yԯY닷(PN+l9 `z}_x:fM<,'jSCtUQ֜Ou. %ŀMYBխW!נ Sk_Tx3{`y {pͺRzvV>07osc Bc41Xh$ $ E,4r >BM1CQ.2']|U%b[HP,OTuiݏ+j=޸ؙ~%n%~|t8t΀R=?xCqP˝oyI{g鐗 P40NJMHځ"Zj|}0rF}Gbn|h TIP3sbSl|> L~L mG5rUBѫL/u HxA̯|Q+ڜF*M.]Gz3֡RNQyZәO"g8̈!RH2G:P.JH<m?-MEw1IP6-6|+lܬw/(Z%)Ys#}#G*:屿rK!]Dh@ (xI!ȑUݬ_E $*?/7xorƄUfO7%̵dlsDY89r{1MLZ bk@̛h^$/CIv|35Z$wRV#|Ϩ^,W?z'Jw;#ϸ:%E?b-'`,V{=At1LO+bRt]|iv3!Ztlm1 =[ 1F뫪L Q]9( &@iSNE#Co!1Dt69?4rl4+JSkfzX_xch OFi[ OB}F]1ty7Bhbk2S0˨mEXI!':~| 5G?Lٝy"y a&#.˨Zi$q66QUeɎPKKi -^HgsfRc?v}fY#~@M1meD'Z +FnҠ\1o6:^F/2h)؎fz?qEH߬$Myz5.G~-RIH[BjAb'QCHJ*;@i]'eUB罘mt"Θou92''ϋ$;竭<6/IxޅROiplh48׺X_uaE2a\lzWu/ 5 37db#B 6:c肮v)U-W=Us.Xqy ݼ~Ѽ6]GgLFg5fzO; ,1UioplAHgcKLwW7,Xد#"Mnz uؐR4,o@p2>D˃M(^BýB#f􁐭%BsVSD+7GniNz _`vŨB=ʌv.aho&PpGoL\P(CbTh4A mΙaŲ 5Wa_"i{K BJQp>$w4v<Zn x9r 7TAZuhޓS"ALؖ@' 20j<-_P&l1 3JKm{ Hu'>59 hXXUxabJf1RFGp1p~Ob Hq0˖'rdewQ yj//"Np]m[Qi)!!_Y&#QL5z/jύ6c294깥g;KT`P-sc n8w' GE Ayϩk$%D%eLeP4#r(j9;Q~5ܬڲXpgO4MڿSFMT.:{7/A~2 @=[Q ʰLnҘdv. Z&8kB1ELlGlu1IO9B]?cwf}syW?w7zqL)n^ui&(oUEɦz [ Z<]2i'D}VIq56FGp]Dv_u;Hi9a$OZNZC54D.*Dm!Ǽ*%v.rVw?yȵ5c2r%b~RԱ] b4xhT#3oh'w tre WX*) ̱0CFE`PM,>m'B"lDH-K-K 6\҅,]C0 PP̠yyđ{gQ6Icvk㳷#yf(*NcY0crzjY=3;`$Ĥψl[1aی́1tC'8ʀ]f#ջ(} A%9vnk N<32_?Ƒb1 FK“UN⠖YO{ɀV R*hC< :#qzf)y&qk`Sd8Ы СW.VN$A[gcuj4#QT$I-[*_JCJR}"R &W5'NU:;7y׿,V<ȃĐ?8`k̮=OYU!arˆ!νyքJR=jC?[*6xvҧS(CZlEI%k4ZnKh'_}ħ#%,g>Moe<)|vQB r3Wq(x@0~X7 j= ?}$?&zx+{`h7Y:{pbo:f2r\x7Z88 9uEC;Mz*` eKܑkk$>.;Og}:$ >cMmS7 Y5AUk(1?ho8ʓaeLnJG^ݝfx>>x* ޅxH%p/ 5Y, l Dndž.ʴY:GAZƹʤQ9-bLbuG0/l{Wm]gF)Y~-_u--\ITa㣅5 p.`VIWgBkNP ~XwDsS%/ydQuI XW"ΎXJ[&f6  7oj:#;e~B4{?>x@fcR9m~A/i Qhg"Cn#gitD_PA ~%d^m'a>djb+XSY4G+_?#8{+ŘhiLk鳳9,^;ۻK5X^ŋi /\@G{Rak{݌?u^&2sdw P Pގk23%J`b$M{VPHE_@9hr1ȗ'\9糳5e}2ʯFϑmQRV%[oi"=`_5Q$7J0Ow16=۸vQBIApA)\NlXR{eu) g)K s<D=Bo]Sr;S&}HƲDY}O-ҺЏR,Gi3KR2 .$m%{QS]:M7%^ M{֗-Qx&Y0p wԈU=(vcJrjF柜FMGmGZhO~=-:}rÚ_~1(%=[JI͞( bfvg RyKg ED 4$ɍ%򛍜 t)ɳT"lN@׭2k+>fm(nȍ#qG:>,&6\|lsٰ02ISk|ǭ\[ :$f La!Q^; o 6s- 8_ 8veHmMn`r0җB ϣќw;ne?4G͊o6\?g %Qq!&__;jj<dv6]qyT|FZbRus{Wi؈"> :y'+|7F"3hEC`DmcpyU E [ĕ!n#ܷP -&IK{, SHם[aC4gYi@fd#9|LoK/j veJ5(|6d2#X:jg L]k) \" e&(V˼XeZm d:8[iϚ{$X{,G;YBzftT }.Z"#m6{ f?Hi_pl^<+X eO(("?r#"RX0={EL2:e^-ȍ$4cSI,2IdY^.!ʀw%wzZ9JPKTYAev^r3e>ja;_COLo萑9<씿 IMqlZ̟l)]CsX@jfh,.UF2k*M>cYl P`l!Ʃpf壱kTjDMJkp*d<_ߎ*a DZ`g)P2#U:?6Y0˿Ig%cJHy$փ`+&(rAu]]>&+Xޮ:vE^K2u:WZns UB̏A{ߜOU& CF}M1(tD: L%U>+ 76Vea sGMP_MKҾPHkM,l=rW#}t-gG L-`'`~iȨD h&Q,</MCA޷QpHPIϺ' >SJ_Țw;6p3NT +ʋ0_;|ω3n~,bXtxJ`)Z9cR]K?*Ky⌵MX,6J&1&eK[OȠU Ss\w!=?;p|B;FfmW/ }6j#qL!Focc:!zN.Ym9`dw Y=LH!8j=GM K?Ƈ4'yo qs9VLHP!'U2&]@h׉_Y37-nYaj fQF 2-Ⱥ9Wp{qBU6G'/o0̞=?93B AybDYyjcE^bOho*&I}\rL Kmub7\䡾"ؿ$e 1[,'xŽ%6 Qlvȫt$8̼-iK43+Ӡᵿ M*פֿe&X0q wab42<Zd.xBcWq*eԘNۙvz39왵xjZm ֛ EƍKma+F6IIde`Y_[WRRKICN<3D2|WwX"#[;F_@jyR̰$=xo,(Vdm60?{QPZR f B@Ip `ǘ vABTR7T5PFtJ=ɭ&:R{\Z[۽ta "2[;V' j޶0b.$rp<}qgfZ^`2'P{z>tR } ʀTjTBᒝIŔ?s.QQ  |[we>2oIc^L7D}},j˥m $I!1J9]qg:##d NdR+A :6R9yqLЋX I5$mMz܄vxRM^6nH܍&[&e*a5lJ CĴ\YQ| YsB!,Tj7!؝޽$E^BDavGQ! /^$ 0yruV*Y~O%V b]Op\@_UUCuTdn3IϘGM[wpyb5fb rh0( 1ozP9r:B$0sv㯡qB-ޝtAgn8C+I=@>k^_(fi5ANq87sҼT2)ڵI,dɮaI vEBb%citE#/]UG<;uS!\6מm)RsYNM -uۋvM[N3ɣ>>}l|eӝmO9[}yO+HY[ UsjN*Y7V]SdJx[x38yRP FFGO ˍ!2)F5|Yt;rW.L}t+|P!5]K tt oOD+"_n]u|ټWGj:3\p8f768ﺸ(؜ = Ů1Ŧ [r2;D&A#ҭM) qu }xp.nG\z2۫0PM˞s+`Ñ GAIcG>d( p{Rg"U gZ|@1^rKupVKK,J 1,{T5xIKUDs!k7uɄqX KN$r!c6 6,_Vxfp/$'=f #͓3@?HDHփQ:!)xU4QP.}QePg,<M74G*v v@/6EYq.L)ChF6\%8k{£E4?*A 8ƌ'wdx3HᵷB&NY7ٹbYҍtlM-^qY^CZHD"vUZ"|ҙ1H,t Q5kY꿻y LeLjR(H HϷ:ߣcV|\;„4n/A#W04-kq\ɚ^~_zall7F ;,I8dv_]ٴj|m>%U\W[6utoͳ@(qDd[k1:*I7g1sDSDSwnR LMW}nkW!LFA+7Y˖H[Nj-=&yzeբI2?J qGB(?x||c=0co@01w9vYL2 wಣQ+" P2Nzu㭗A5ʌ7Ķu $U7Иyt-1'\akҰ =^%}&+󓭃3~r7&0Y0 !8PJ5Nag賈AAӧt)q]5bmAKm;*y%d)(%{Ba1t5A![OƂ.]RGp +ҏ \'_n*O 0)O_= zz*cCfu%iːhu'7r4O=Ks@Em=f6^K"KĞj bf`D :4yV~b4L ڌJ*b3f/Vam_pLAcԏ)LNư sӝ얥"Fo(Ն=[3"%_~nmGub$:wK؊cuܠYPeXb 4Oٲ.XpZ>QyK2O\>cJMWЗ=i+5I?ya X&wcN^ES |mVx\*jBN[B&gá)nfRum#C],.⅌n:0),$_7{dTִ=hv aF * ġlq|X6tt ||^~-Xc)C6f tL#]~[3DBI4Ibπү4>Ex$Uh"j5%yў8\<QA%Վ69ǎ* a› X VA6mxzMp/A)+$X"sS3°F=_=I&#a+`?24 -`MQ \\R =ɻA/{@'h/ck4l-Qc'Q D̠$My; 'O$A2<58ӗH|E]N{88:H1|5n0aj[Hky6]:kժҦ۫W\d&^ t)& ኹ{(p)l{YO08W<Ѐa&9аe@A0q/e)d =d9NN4^KAn, w;*H&m_i".I E8)3MiejX/GUDMP&8׮;02I{ P\޲ Btu=g4]?jrS㺃a6qgFUKla`2 fWe^,񙠀ו)gs d̂ͼTT[(=(.^ K*ULV~JnkjugF[K3p9?oaڠDɶE߯,I9I]'qr h5]{tU<#] Hf~ Tr(x ٧ed$Zʿ]c4oyt^c\y|D3=V2[,)~ۡV_u}q ̠'RLyqW1qli+w}S{I컾i뛍;-׏#" ŖJ' SdiNWyK /Eѓ*Il 3O \Io)ͼ'o$dRQ | i@yǔ0:ÇDfsM_WQG3!lxcx{k:4:XpÄ=dks3-cEs k₤>.F幤&f9^ }exVFXDY1u ŃF!Sש,TÙWxLE+TMw$,wns3<-+-XȄ@לϏ*k, 5=!XHL?;Y(/0/gB1s>7 ,@]}"t!OS$EBdj df#n2Ņ15_C9KW,<ӄ.t. 8t)Or6ru** T=}7M\ <Ȇi=~]^KE(DZ50=P&B+K.%TN9 ޑ:]ֺTPჁ -0 o_T3sw1U?cu`[U5 UA :ܻbbus'Sc~rp=l[L67t'_Ч]z5LiHnԡw֎+"$}坥- 㞮xN ɐزq5zc'S+3(lC?N,/Dya,e '#P.KJa٠O."^p}b۞}p9k jաI܉E6C!• )qCD| Z;K̈n~8H)-"RָP^tuÙfj之3%/W%}C  2s{SnCJEqx1trD)"o, / G9''wo̍=5Kqr(W!&+꽓7CgVRtji)#S?W M"T<+kT65%zjzuM;-C>/pOF|~ޜې紙 p~V@{2L4m5^Y[./q9 Hs::$eWRPOmt0m攇lpVڼB3F@b'}ǔ>R-3nxWމ.[ʪKz6_+G󻐋恻l!/M!o exM;Sv`ۖk[b֢xqgvR2 "8;^/xk?+=l*p Vwg iBp~Mdv%W99][z,A'\wSNԮ'W)N'zW}ӎ|%A,K_]ָ(ܷ I- Y8_0?Q4Cj|uX'Z 7xXi]Zd2>T˖W-puW> x?E'fZ1[8 T M $i˼؞$D2DG*`=ID)-ω 4drxPMY% k AbRPԯh: pW#Cu&# R9qU b1Na!ўz_떎i2CޱV/z_XybLC+َg<2_iSja1DxM7E4=o/4l FiCS7k>Jm1;TMp<"I7H>7E~mF>+Yx=<_)]=ԅ.C ýz&T0'%W+VLeCpUs,x9:G!uTuJ|}c7de^-\U/CǴ1C ZI);aCwTQ:Nna-"( v*a}Ç蜂$?K>DetqC ސ8'*IP*:Q+-w$w̪TNd+:V+sG6N/)l4VuF ` o!S5l3{؈2ۮ}'̃<$\?O‰6IV[0b}67I)Z1R!3ыO9بX,G2Qpɸ@S6=_q;&Nݽ.^!`8ר39@,Ҏ(6fIKr0o;'y'B5.3mJ[NUbQH"h)T)tAL1>p,˫E| o9)%RWKFRO/x?к~K8%Y>i ="cs˼l[ ˡ- 1 &4m|LA /M:_ ΙЃXܖɋs\6הr~It)ڙ)WN6{{cqnpg$s 'SQk{44+KKW^VT>0Yٵi]G]Biyјe$Nt)MUAnE5B#3$b$JґKj0lyrIX;(dswO> ee҇ uxb<1q2f׿wSPhiX1J^73]i [Iw!m4-" -/0:-xBZ /rCM,澲:_^CWg u,[ E͠)ؙ"V,4aԧEh<~f k4wFdIuFcƨ<#U iQvJ^X Ӊ{h& &1>-MdN8Ȅ E{BI34id%eE*Q#to$y-7THy7 #4S9M{;%[]ݽ~7F-s#NIЊ:4n&\Ͳ$`0~? x*K2#@Ǔ#wc7PHi5&>grWN"o-F+V`sU1E nZ4(_106FoZw0R CU'~wlk4 a܃0;!|5|S>[` >ȅJ;6St0JcKMõuD@4Pa)~՜C-aր&Q Yoa+33Da!Ţ|3zT#˭ՎG"ٽ1sN=J!.?=E>v#7T i얁cgw?)^Fkr$ U'I(h]CoJ=>DD(,,֩r=C2FKSI/K>PF/y=+1NU׶< ճ5L.!2qɅF ;o7p]~O\ͻx7:a5i+%tqڢ,T#ﯥ/W?PF5_E<\yKԖ| kʹJzw41G$cQ.kp>\)O&#c{Q<3R"1AABѦzBN.kvwPʹR%\tVOakS"EI\m%9Ϣ\Y*S*w#n@sh@OeԌYt J-?G9:7HNܢ; $ZFzmB9z8(Oz6@;}7pxl4KH_vK 8a[tۻQ"5 ne-A 7{]\\e&<(~y~Ym$T6Vjֹb}\!L_4|>h`?0~Qؘ81 l@;T(*/ RU6M^w2=$oXx]9޺lP9NWy[95lz6 As*9cT}lHᄕQdj^nIFS$)w,V`?@FIpxu|Lɞ~ڕ++y~-вL :W&I4ͫ(%vw@o%u%c!"f;ʾ1#~32gkM.D#2X3Xi)&PK1[h7m؟E6zs^*T&;K-lWN\a: nk{Q;^Iu踾3Z-wZ,~l Q*lJԠ"blgS} OߛlMu%SQKOCNFꅦ/c8rHf9op_TGI:w<_ZWj|)jFJ6;N;kp9=OkofL&@ȗ Wl]:yAdYFS_a#""#2L0G`ї ;:U@;uc:@4LE6uF <;"!Y9Tde[Aj;~p0›)a]k=)~WDhX`(([,bҙ(<@67@p|OTe~̷WΕU ZI f0Wv8&siPN9!#^"xa/0 Doe40A3r\LUxn^D$H$ًN3ؘXlOY0 /TAcu XVd(*8N:[,AQII֦BeKMx%P<1ȸ,J,3髳'3>߂Hr%T&Y.[:Fs=TLďz rSVM89' :1W"ss[񝒓gU{+qn;B Et7z. R S~iH|)ҽL}: !1RqA>o5#,*nX0tf &GЉi .&t֜ $ƛ5ZfTb(m.v"8!U+Tcy[Fd>iwV+.L {E<{d3KLvUq;G\&CIVm]'_ԜHO,pik$]+Nkө*i9Lt:p`D8t8 YZ