=== release 1.28.8 ===

2026-10-08 17:20:32 +0200  Tim-Philipp Müller <tim@centricular.com>

	* gst-plugins-good.doap:
	* meson.build:
	  Release 1.28.8

2026-10-02 16:12:33 +0300  Sebastian Dröge <sebastian@centricular.com>

	* gst/rtpmanager/rtpsession.c:
	* tests/check/elements/rtpsession.c:
	  rtpsession: Ignore SDES priv RTCP packets with invalid lengths
	  Fixes https://gitlab.freedesktop.org/gstreamer/gstreamer/-/work_items/5307
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12659>

2026-09-24 13:19:05 +0100  Tim-Philipp Müller <tim@centricular.com>

	* gst/matroska/matroska-ids.c:
	  matroskademux: fix crash caused by bogus xiph codec data packet sizes
	  Fixes https://gitlab.freedesktop.org/gstreamer/gstreamer/-/work_items/5311
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12658>

2026-09-24 11:59:50 +0100  Tim-Philipp Müller <tim@centricular.com>

	* gst/rtp/gstrtpL16depay.c:
	* gst/rtp/gstrtpL24depay.c:
	* gst/rtp/gstrtpL8depay.c:
	* gst/rtp/gstrtpchannels.c:
	* gst/rtp/gstrtpchannels.h:
	  rtpL8depay, rtpL16depay, rtpL24depay: fix out of bounds write for high channel count
	  The positions array is only 64 entries large, but if a high channel count
	  is signalled in the SDP we might try to initialise more entries than are
	  available and write beyond the end of the array.
	  Fixes https://gitlab.freedesktop.org/gstreamer/gstreamer/-/work_items/5271
	  Fixes https://gitlab.freedesktop.org/gstreamer/gstreamer/-/work_items/5306
	  Fixes ZDI-CAN-31143
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12657>

2026-09-23 09:37:22 +0300  Sebastian Dröge <sebastian@centricular.com>

	* gst/rtp/gstrtph265depay.c:
	  rtph265depay: Check for short packets before processing them
	  Fixes https://gitlab.freedesktop.org/gstreamer/gstreamer/-/work_items/5258
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12655>

2026-10-01 17:30:59 +0200  David Lincoln <dave_exile@hotmail.com>

	* gst/isomp4/gstqtmux.c:
	* gst/isomp4/gstqtmux.h:
	  qtmux: preserve earliest reordered presentation time
	  Track the earliest presentation timestamp independently from the first buffer
	  timestamp. Use it for global timeline and edit-list calculations so reordered
	  streams retain leading presentation frames.
	  This makes sure that correct edit lists and ctts are created for streams where
	  the earliest PTS is not the first PTS, e.g. when the first frame is a B-frame.
	  The Rust MP4 muxer uses the same approach.
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12635>

2026-10-04 20:58:08 +0530  Sanchayan Maity <sanchayan@centricular.com>

	* gst/audiofx/audiofxbasefirfilter.c:
	* tests/check/elements/audiofirfilter.c:
	  audiofxbasefirfilter: Account for channels in FFT mode for push_residue
	  This resulted in corruption of the final EoS tail in FFT mode for channels > 1.
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12615>

2026-10-04 20:52:32 +0530  Sanchayan Maity <sanchayan@centricular.com>

	* gst/audiofx/audiofxbasefirfilter.c:
	  audiofxbasefirfilter: Make sure we are not left with a dangling pointer
	  When the frequency response is not re-built after being freed, we can be
	  left with a dangling pointer resulting in a double free in finalize().
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12615>

2026-10-04 20:49:15 +0530  Sanchayan Maity <sanchayan@centricular.com>

	* gst/audiofx/audiofirfilter.c:
	  audiofirfilter: Fix minor typo in latency
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12615>

2026-09-28 19:46:40 +0300  Sebastian Dröge <sebastian@centricular.com>

	* gst/audioparsers/gstflacparse.c:
	  flacparse: Fix resyncing after a seek
	  1d913768 introduced a regression in flacparse where seeking to a previously
	  unindexed position (i.e. requiring resyncing) would error out instead of
	  skipping to the next start of a frame. An invalid frame would be considered as a
	  valid frame of size 0 and then error out.
	  Fixes https://gitlab.freedesktop.org/gstreamer/gstreamer/-/work_items/5314
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12574>

2026-09-23 18:56:50 +0300  Sebastian Dröge <sebastian@centricular.com>

	* gst/matroska/matroska-demux.c:
	* gst/matroska/matroska-ids.c:
	* gst/matroska/matroska-ids.h:
	* gst/matroska/matroska-mux.c:
	  matroska: Use the display unit for storing the display aspect ratio more accurately
	  With Matroska (not WebM) the display aspect ratio can be stored directly as
	  display size when setting the display unit to DAR. This allows to avoid rounding
	  errors.
	  For WebM the best we can do is the existing code as it requires pixels as
	  display unit.
	  In the demuxer, avoid some overflows in the code and also don't calculate the
	  pixel aspect ratio for unknown display units.
	  Fixes https://gitlab.freedesktop.org/gstreamer/gstreamer/-/work_items/5272
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12572>

2026-09-20 13:37:47 +0200  Remus Lazar <remus@lazar.info>

	* ext/adaptivedemux2/meson.build:
	  adaptivedemux2: Remove redundant hls_dep fallback
	  hls/meson.build unconditionally declares hls_dep, but the fallback
	  assignment afterwards overwrites it. This makes hls_dep.found() always
	  return false, silently skipping hlsdemux_m3u8.
	  Remove the redundant fallback so the test runs again.
	  The bug was introduced in 3de86b2b9725c111998d6e42b54a2f67582a3db7; the test
	  has not run since 2025-01-13.
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12553>

2026-09-24 22:34:42 +0300  Maxandre Ogeret <maxandreogeret@gmail.com>

	* gst/rtp/gstrtph265pay.c:
	  rtph265pay: unmap the RTP header before appending the payload
	  gst_rtp_h265_pay_payload_nal_single() kept the RTP header buffer mapped
	  for writing while appending the payload. With aggregate-mode=zero-latency
	  an aggregation packet can carry 16 memories, so the append merges all
	  memories, the read map of the still write-mapped header fails, and the
	  buffer ends up with a dangling memory.
	  Unmap before appending, as the FU path and rtph264pay already do.
	  Fixes https://gitlab.freedesktop.org/gstreamer/gstreamer/-/issues/5327
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12549>

2026-09-23 15:31:30 +0900  Qi Hou <qi.hou@nxp.com>

	* sys/v4l2/gstv4l2object.c:
	  v4l2: object: Don't corrupt the caller's filter caps when probing
	  In gst_v4l2_object_probe_caps(), the DMABuf candidate branch built the
	  temporary format_caps with gst_caps_append_structure() and then called
	  gst_caps_set_features() on the incoming filter caps to attach
	  GST_CAPS_FEATURE_MEMORY_DMABUF.
	  That is wrong for three reasons:
	  - filter is owned by the caller (the pad caps query), so modifying it
	  leaks a side effect back to the caller and can hit a writability
	  assertion when the caps refcount is greater than one.
	  - only structure index 0 was touched, leaving any other structure in
	  the filter untouched.
	  - the feature belongs on the candidate caps we are about to intersect
	  against the filter, not on the filter itself, so the pre-probe
	  intersection test could pick the wrong formats.
	  Attach the memory:DMABuf feature to the candidate structure directly via
	  gst_caps_append_structure_full(), which is what the rest of the file
	  (gst_v4l2_object_get_caps_helper(), gst_v4l2_object_update_and_append())
	  already does, and leave filter untouched.
	  No functional change intended for the resulting probed caps; this only
	  fixes the filter corruption and makes the cheap pre-probe rejection test
	  behave as documented.
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12537>

2026-09-23 09:55:11 +0300  Sebastian Dröge <sebastian@centricular.com>

	* gst/rtp/gstrtph263depay.c:
	  rtph263depay: Make payload buffer writable before modifying its content
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12533>

2026-09-23 09:47:00 +0300  Sebastian Dröge <sebastian@centricular.com>

	* gst/rtp/gstrtpvp9depay.c:
	  rtpvp9depay: Check for enough data before parsing scalability structure with PG description
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12533>

2026-09-23 09:44:55 +0300  Sebastian Dröge <sebastian@centricular.com>

	* gst/rtp/gstrtpmparobustdepay.c:
	  rtpmparobustdepay: Check for enough available data in all cases before parsing payload descriptor
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12533>

2026-09-23 09:43:48 +0300  Sebastian Dröge <sebastian@centricular.com>

	* gst/rtp/gstrtpsv3vdepay.c:
	  rtpsv3vdepay: Check for enough available data before parsing extending width/height
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12533>

2026-09-23 09:42:36 +0300  Sebastian Dröge <sebastian@centricular.com>

	* gst/rtp/gstrtph261depay.c:
	  rtph261depay: Check for enough available data before checking for picture start code
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12533>

2026-09-23 09:38:46 +0300  Sebastian Dröge <sebastian@centricular.com>

	* gst/rtp/gstrtptheoradepay.c:
	* gst/rtp/gstrtpvorbisdepay.c:
	  rtpvorbisdepay: rtptheoradepay: Copy only the out-of-band config and not the whole payload
	  This should be harmless because the length is included in the data but including
	  unnecessary garbage at the end is not very clean.
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12533>

2026-09-14 18:59:25 +0530  Sanchayan Maity <sanchayan@centricular.com>

	* gst/rtsp/gstrtspsrc.c:
	  rtspsrc: Fix handling of missing control attribute with multiple media sections
	  Issue reported and fix suggested by Jeremiah Morrill.
	  https://gitlab.freedesktop.org/gstreamer/gstreamer/-/work_items/5270
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12504>

2026-09-11 16:37:53 +0800  Zhaoxuan Zhai <zhai.zhaoxuan@canonical.com>

	* sys/v4l2/gstv4l2object.c:
	* sys/v4l2/gstv4l2object.h:
	  v4l2: Fix sizeimage when VIDIOC_ENUM_FRAMESIZES is not supported
	  This patch changes the behavior of calculate_max_sizeimage, it now
	  calculates the sizeimage based on requested frame size instead of the
	  probed max image size. And this patch also removed max_width/max_height
	  field from GstV4l2Object, as they are no longer used.
	  The new calculate_max_sizeimage uses guint64 to do the calculation to
	  avoid overflow in `width * height * pixel_bitdepth`. For example,
	  if width = height = 32768 (2^15) and pixel_bitdepth = 8,
	  width * height * pixel_bitdepth = 8589934592 (2^33).
	  And the return value is guarded by G_MAXSIZE in-case the return
	  value is too large.
	  Before this patch, when VIDIOC_ENUM_FRAMESIZES is not implemented
	  by the V4L2 device driver, the `default_frame_sizes:` path in
	  gst_v4l2_object_probe_caps_for_format() uses max_w = max_h =
	  GST_V4L2_MAX_SIZE. And it results a overflow error in
	  calculate_max_sizeimage().
	  As a result, calculate_max_sizeimage() always returning 256 KiB when
	  VIDIOC_ENUM_FRAMESIZES is not supported. And 256KiB is not sufficient
	  for images with 4K resolution.
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12494>

2026-09-10 13:30:56 +0300  Sebastian Dröge <sebastian@centricular.com>

	* ext/adaptivedemux2/downloadhelper.c:
	  adaptivedemux2: Drain downloadhelper main context with the main context as the thread default
	  The draining was introduced in 0fcb93a087cdc085563b52e9c2a0ac9610acd181 and not
	  making the main context the thread default will lead to assertions in libsoup if
	  a transfer was still running at this time.
	  Fixes https://gitlab.freedesktop.org/gstreamer/gstreamer/-/work_items/5296
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12472>

2026-09-07 20:17:18 +0100  Tim-Philipp Müller <tim@centricular.com>

	* meson.build:
	  Back to development after 1.28.7

=== release 1.28.7 ===

2026-09-07 20:11:13 +0100  Tim-Philipp Müller <tim@centricular.com>

	* gst-plugins-good.doap:
	* meson.build:
	  Release 1.28.7

2026-07-10 20:47:29 +0200  Mathieu Duponchelle <mathieu@centricular.com>

	* docs/gst_plugins_cache.json:
	* gst/rtpmanager/rtpsession.c:
	* gst/rtpmanager/rtpsession.h:
	* gst/rtpmanager/rtpsource.c:
	* gst/rtpmanager/rtpsource.h:
	* tests/check/elements/rtpsession.c:
	  rtpsession: implement DoS protection mechanisms
	  Prior to this commit, the number of sources tracked by RTPSession
	  was unlimited, opening it up to malicious attacks.
	  This implements two mechanisms:
	  * A global maximum for the total number of non-internal sources, with
	  a LRU mechanism for discarding the least-recently seen SSRC / CSRC.
	  Selected default: 150
	  * A per SSRC maximum for limiting the number of contributing sources
	  for a single synchronization source, with a LRU mechanism for
	  discarding the least-recently seen CSRC.
	  Selected default: 15
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12436>

2026-08-31 15:03:59 +0300  Sebastian Dröge <sebastian@centricular.com>

	* ext/adaptivedemux2/downloadhelper.c:
	* ext/adaptivedemux2/downloadhelper.h:
	* ext/adaptivedemux2/gstadaptivedemux.c:
	* ext/meson.build:
	* ext/soup/gstsouploader.c:
	* ext/soup/gstsouploader.h:
	* ext/soup/stub/soup.h:
	  adaptivedemux2: Use a SoupCookieJar and keep track of cookie origins correctly
	  This makes sure we're not leaking cookies to different origins. Same fix as for
	  souphttpsrc but not behind a property, which should be unnecessary here.
	  Require libsoup 2.68 (released in 2019) for the soup_cookie_jar_add_cookie_full() API.
	  Fixes https://gitlab.freedesktop.org/gstreamer/gstreamer/-/work_items/5174
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12438>

2026-08-12 20:48:37 +0300  Sebastian Dröge <sebastian@centricular.com>

	* docs/gst_plugins_cache.json:
	* ext/soup/gstsouphttpsrc.c:
	* ext/soup/gstsouphttpsrc.h:
	* ext/soup/gstsouploader.c:
	* ext/soup/gstsouploader.h:
	  souphttpsrc: Add new `location-trusted` property
	  When disabled (default), explicitly set cookies or extra-headers or
	  authentication information are not set when handling automatic redirects to a
	  different origin.
	  This is the same as CVE-2018-1000007 in curl and CVE-2021-31879 in wget, and the
	  solution is the same as in curl.
	  Fixes https://gitlab.freedesktop.org/gstreamer/gstreamer/-/work_items/5174
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12438>

2026-08-07 16:21:42 +0300  Sebastian Dröge <sebastian@centricular.com>

	* gst/isomp4/qtdemux.c:
	  qtdemux: Don't try splitting CEA608 samples without known framerate
	  Splitting them would lead to invalid sized buffers and divisions by zero for the
	  timestamp calculations.
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12437>

2026-08-07 16:21:05 +0300  Sebastian Dröge <sebastian@centricular.com>

	* gst/isomp4/qtdemux.c:
	  qtdemux: Ensure enough data is available for reading closed caption boxes
	  Fixes https://gitlab.freedesktop.org/gstreamer/gstreamer/-/work_items/5235
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12437>

2026-08-31 12:55:53 +0800  aisuneko icecat <aicecat@igalia.com>

	* gst/effectv/gstquark.c:
	* gst/effectv/gstquark.h:
	  effectv: quarktv: apply proper stride for pixel iteration
	  Iterate row by row with GST_VIDEO_FRAME_PLANE_STRIDE to ensure
	  the last row is touched and the pixels are correctly indexed.
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12422>

2026-08-31 12:48:18 +0800  aisuneko icecat <aicecat@igalia.com>

	* gst/effectv/gstquark.c:
	  effectv: quarktv: add error checking for gst_buffer_map
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12422>

2026-08-19 22:42:20 +0800  aisuneko icecat <aicecat@igalia.com>

	* gst/effectv/gstquark.c:
	  effectv: quarktv: read from mapped memory to improve performance
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12422>

2026-08-12 11:13:39 +0200  Frank Wennerdahl <frank.wennerdahl@soundtrack.io>

	* ext/soup/gstsouphttpsrc.c:
	  soup: fix redirect uri when not using automatic redirects
	  If `automatic-redirects` is set to `false`, the resulting
	  error should contain the redirect URI in the field
	  `"http-redirect-uri"`. This isn't the case, as
	  `src->redirection_uri` is never set before the error
	  is constructed.
	  This fix ensures that the URI is set when the status
	  is a redirect, allowing manual handling of redirects.
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12391>

2026-09-01 10:51:50 +0200  Edward Hervey <edward@centricular.com>

	* gst/flx/gstflxdec.c:
	  flxdec: Actually read full palette
	  The default 0 in file means there's a full 256 palette
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12387>

2026-09-01 10:47:12 +0200  Edward Hervey <edward@centricular.com>

	* gst/flx/gstflxdec.c:
	  flxdec: Check for invalid header values
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12387>

2026-08-25 10:55:23 -0400  Eric <eric.chandrasekhar@ipconfigure.com>

	* gst/rtpmanager/gstrtpbin.c:
	* gst/rtpmanager/gstrtpjitterbuffer.c:
	* gst/rtpmanager/rtpsession.c:
	  rtpmanager: Fix malformed SDES processing segfault
	  gst_rtcp_packet_sdes_get_entry can return FALSE when the SDES entry is
	  malformed, and this wasn't being handled by the callers.
	  Now if gst_rtcp_packet_sdes_get_entry returns FALSE, the rest of the
	  SDES packet is skipped.
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12375>

2026-04-14 13:08:55 +0200  Pablo García <pgarcia@fluendo.com>

	* gst/isomp4/qtdemux.c:
	  qtdemux: Add 'stream-format' field for AC-4 caps
	  According to Annex G of the AC-4 spec, the syncframe is an optional
	  layer for encapsulating AC-4 raw frames. This demuxer always outputs
	  raw frames, but the AC-4 parser/decoder needs to know.
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12371>

2026-04-14 13:08:34 +0200  Pablo García <pgarcia@fluendo.com>

	* gst/isomp4/fourcc.h:
	* gst/isomp4/qtdemux_types.c:
	  qtdemux: Add AC-4 atoms
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12371>

2026-08-19 18:05:11 +1000  Matthew Waters <matthew@centricular.com>

	* ext/qt6/qt6glrenderer.cc:
	* ext/qt6/qt6glrenderer.h:
	  qt6renderer: keep output GL memory alive until next render
	  Qml seems to not correctly render an output if the output texture id is
	  the same as previously set. This can easily happen if the output texture
	  is destroyed and a new texture created with the same ID. This is
	  particularly evident with a downstream element that reads from the
	  texture and then unrefs it causing the texture to be destroyed.
	  Fix by keeping the output texture alive until we have rendered the next
	  frame.
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12342>

2026-08-19 15:13:43 +1000  Matthew Waters <matthew@centricular.com>

	* ext/qt6/qt6glrenderer.cc:
	  qml6gloverlay: map output memory write|gl
	  So that if a gldownload is downstream, it can successfully transfer the
	  contents.
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12342>

2026-08-06 21:28:28 +0200  Marcus Hanestad <marlhan@proton.me>

	* gst/audiofx/gstscaletempo.c:
	  scaletempo: fix integer overflow in output_overlap_s16
	  The blend weights and sample delta can each approach 65535, so their product
	  overflows the 32-bit intermediate.
	  Compute the product and shift in 64 bits.
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12265>

2026-08-05 13:04:46 +0100  Tim-Philipp Müller <tim@centricular.com>

	* meson.build:
	  Back to development after 1.28.6

=== release 1.28.6 ===

2026-08-05 12:59:39 +0100  Tim-Philipp Müller <tim@centricular.com>

	* gst-plugins-good.doap:
	* meson.build:
	  Release 1.28.6

2026-08-04 20:05:57 +0300  Sebastian Dröge <sebastian@centricular.com>

	* gst/rtp/gstrtph264depay.c:
	* gst/rtp/gstrtph265depay.c:
	  rtph264depay: rtph265depay: Reset missing fields when resetting during fragmentation unit handling
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12244>

2026-07-29 17:39:56 +0300  Sebastian Dröge <sebastian@centricular.com>

	* docs/gst_plugins_cache.json:
	* gst/rtp/gstrtph264depay.c:
	* gst/rtp/gstrtph264depay.h:
	* gst/rtp/gstrtph265depay.c:
	* gst/rtp/gstrtph265depay.h:
	  rtph264depay: rtph265depay: Limit the maximum fragmentation unit size
	  Fixes https://gitlab.freedesktop.org/gstreamer/gstreamer/-/work_items/5224
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12244>

2026-07-20 13:12:48 +0100  Tim-Philipp Müller <tim@centricular.com>

	* gst/rtp/gstrtpqcelpdepay.c:
	  rtpqcelpdepay: use clear_packets also in finalize function
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12237>

2026-07-09 10:28:00 +0300  Sebastian Dröge <sebastian@centricular.com>

	* gst/rtp/gstrtpqcelpdepay.c:
	  rtpqcelp: Clear queued packets on invalid input packets
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12237>

2026-07-09 10:26:20 +0300  Sebastian Dröge <sebastian@centricular.com>

	* gst/rtp/gstrtpqcelpdepay.c:
	  rtpqcelpdepay: Don't push NULL buffers downstream
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12237>

2026-07-09 10:24:34 +0300  Sebastian Dröge <sebastian@centricular.com>

	* gst/rtp/gstrtpqcelpdepay.c:
	* gst/rtp/gstrtpqcelpdepay.h:
	  rtpqcelpdepay: Handle changes in interleave value correctly
	  Fixes https://gitlab.freedesktop.org/gstreamer/gstreamer/-/work_items/5194
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12237>

2026-07-14 13:39:30 +0300  Sebastian Dröge <sebastian@centricular.com>

	* gst/matroska/matroska-ids.c:
	  matroskademux: Make sure enough data is available when parsing FLAC headers
	  Fixes https://gitlab.freedesktop.org/gstreamer/gstreamer/-/work_items/5206
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12242>

2026-07-14 13:22:38 +0300  Sebastian Dröge <sebastian@centricular.com>

	* gst/avi/gstavidemux.c:
	  avidemux: Don't read a subindex with too many items
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12241>

2026-07-14 13:22:04 +0300  Sebastian Dröge <sebastian@centricular.com>

	* gst/avi/gstavidemux.c:
	  avidemux: Avoid integer overflow in bounds checks when parsing the index
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12241>

2026-07-14 12:35:12 +0300  Sebastian Dröge <sebastian@centricular.com>

	* gst/avi/gstavidemux.c:
	  avidemux: Use correct divisor for calculating available number of vprp field infos
	  Fixes https://gitlab.freedesktop.org/gstreamer/gstreamer/-/work_items/5213
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12241>

2026-07-14 12:29:14 +0300  Sebastian Dröge <sebastian@centricular.com>

	* gst/avi/gstavidemux.c:
	  avidemux: Check that at least 1 byte is available before dereferencing tag pointer
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12241>

2026-07-14 12:27:37 +0300  Sebastian Dröge <sebastian@centricular.com>

	* gst/avi/gstavidemux.c:
	  avidemux: Don't modify read-only mapped buffer data
	  And improve const-correctness in many places.
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12241>

2026-07-14 12:00:34 +0300  Sebastian Dröge <sebastian@centricular.com>

	* gst/avi/gstavidemux.c:
	  avidemux: Make sure enough data is available when parsing FUJIFILM strd
	  Fixes https://gitlab.freedesktop.org/gstreamer/gstreamer/-/work_items/5213
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12241>

2026-07-16 14:12:56 +0300  Sebastian Dröge <sebastian@centricular.com>

	* gst/audioparsers/gstaacparse.c:
	  aacparse: Don't assert on parsing errors or insufficient data
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12143>

2026-07-18 16:19:17 +0200  Tim-Philipp Müller <tim@centricular.com>

	* ext/gdk_pixbuf/gstgdkanimation.h:
	* sys/ximage/gstximagesrc.h:
	  gdkpixbuf, ximage: remove incorrect G_GNUC_CONST annotation for get_type() functions
	  G_GNUC_CONST must only be used for functions that don't modify global state.
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12157>

2026-07-30 01:45:49 -0400  Thibault Saunier <tsaunier@igalia.com>

	* tests/check/elements/qtmux.c:
	  tests: qtmux: drain to EOS before teardown in test_caps_renego
	  The test pulled one output buffer and immediately tore the harness down.
	  gst_harness_teardown() releases the request sink pad while the element is
	  still running, racing the aggregator srcpad task inside
	  gst_qt_mux_aggregate(): depending on the interleaving it either trips the
	  buf/last_buf assertion there or leaks the clipped buffer stored into
	  pad->last_buf after gst_qt_mux_pad_reset() ran. The window is wide under
	  valgrind, which is where it shows up in CI.
	  Pull events until EOS before teardown: once the muxer has pushed EOS it is
	  in GST_QT_MUX_STATE_EOS and aggregate() no longer touches the sink pads, so
	  releasing the request pad can't race. Does not fix the underlying element
	  race, only the test.
	  Example failed CI job:
	  https://gitlab.freedesktop.org/gstreamer/gstreamer/-/jobs/104277021
	  Relates: https://gitlab.freedesktop.org/gstreamer/gstreamer/-/work_items/4970
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12200>

2026-06-16 16:49:47 +0900  Qi Hou <qi.hou@nxp.com>

	* sys/v4l2/gstv4l2object.c:
	* sys/v4l2/gstv4l2object.h:
	  v4l2: Use MPLANE flag to determine n_v4l_planes directly
	  Add GST_V4L2_MPLANE flag to GstV4L2FormatFlags and mark all
	  non-contiguous multi-planar V4L2 formats (e.g. YUV420M, NV12M)
	  with this flag in gst_v4l2_formats[].
	  Instead of using prefered_non_contiguous field, determine
	  the number of n_v4l_planes directly by checking the GST_V4L2_MPLANE
	  flag of the selected format descriptor. This avoids the
	  contiguity check for format lookup.
	  Remove the prefered_non_contiguous field from GstV4l2Object as
	  it's no longer needed.
	  Fixes #4269
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12177>

2026-06-09 20:31:25 +0200  Mathieu Duponchelle <mathieu@centricular.com>

	* gst/rtpmanager/rtpsession.c:
	* gst/rtpmanager/rtpsource.c:
	* gst/rtpmanager/rtpsource.h:
	* gst/rtpmanager/rtpstats.h:
	  rtpsource: fix bitrate estimation for RTX
	  RTX packets with decreasing running times routinely come through
	  send_rtp , causing miscalculation of elapsed.
	  Fix by using current_time instead to calculate the bandwidth for RTX
	  sources, and also guard against potential underflows in elapsed
	  calculation.
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12171>

2026-07-16 12:56:53 +0300  Sebastian Dröge <sebastian@centricular.com>

	* gst/y4m/gsty4mdec.c:
	  y4mdec: Don't read more data than available when skipping over frame header
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12122>

2026-07-16 12:56:16 +0300  Sebastian Dröge <sebastian@centricular.com>

	* gst/y4m/gsty4mdec.c:
	  y4mdec: Don't assert on too small header buffers
	  This might happen on EOS before enough data is available.
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12122>

2026-07-08 23:48:39 +0200  Tim-Philipp Müller <tim@centricular.com>

	* meson.build:
	  Back to development after 1.28.5

=== release 1.28.5 ===

2026-07-08 23:42:39 +0200  Tim-Philipp Müller <tim@centricular.com>

	* gst-plugins-good.doap:
	* meson.build:
	  Release 1.28.5

2026-07-02 18:33:04 +0300  Sebastian Dröge <sebastian@centricular.com>

	* gst/matroska/lzo.c:
	* gst/matroska/lzo.h:
	  matroska: Update lzo decompression implementation from latest ffmpeg
	  See also CVE-2014-4610.
	  Fixes https://gitlab.freedesktop.org/gstreamer/gstreamer/-/work_items/5184
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12079>

2026-06-26 12:03:09 +0300  Sebastian Dröge <sebastian@centricular.com>

	* gst/wavparse/gstwavparse.c:
	  wavparse: Avoid NULL pointer dereference when parsing adtl in push mode
	  Fix provided by Michael Bommarito, who also reported this.
	  Fixes https://gitlab.freedesktop.org/gstreamer/gstreamer/-/work_items/5177
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12078>

2026-06-23 10:34:39 +0300  Sebastian Dröge <sebastian@centricular.com>

	* gst/rtp/gstrtpjpegdepay.c:
	  rtpjpegdepay: Ensure that quantization table is big enough
	  Fixes https://gitlab.freedesktop.org/gstreamer/gstreamer/-/work_items/5158
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12071>

2026-06-19 13:20:04 +0300  Sebastian Dröge <sebastian@centricular.com>

	* ext/gdk_pixbuf/gstgdkpixbufdec.c:
	  gdkpixbufdec: Handle format and resolution changes correctly
	  Fixes https://gitlab.freedesktop.org/gstreamer/gstreamer/-/work_items/5121
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12060>

2026-06-19 13:15:02 +0300  Sebastian Dröge <sebastian@centricular.com>

	* docs/gst_plugins_cache.json:
	* ext/gdk_pixbuf/gstgdkpixbufdec.c:
	  gdkpixbufdec: Drop rank to NONE
	  gdk-pixbuf is not mean to be used on untrusted inputs so let's not ask for
	  problems here.
	  For the common image formats we have specialized elements with higher ranks and
	  for a proper replacement follow this issue:
	  https://gitlab.freedesktop.org/gstreamer/gst-plugins-rs/-/issues/764
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12060>

2026-06-19 13:00:27 +0300  Sebastian Dröge <sebastian@centricular.com>

	* gst/rtp/gstrtpsbcdepay.c:
	  rtpsbcdepay: Remove wrong variable shadowing
	  `samples` is expected to be set in the outer scope at a later time.
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12059>

2026-06-19 12:55:34 +0300  Sebastian Dröge <sebastian@centricular.com>

	* gst/rtp/gstrtpsbcdepay.c:
	  rtpsbcdepay: Check that enough data is available for the payload header
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12059>

2026-06-19 12:50:32 +0300  Sebastian Dröge <sebastian@centricular.com>

	* gst/rtp/gstrtpsbcdepay.c:
	  rtpsbcdepay: Check for available data in the adapter before getting data
	  Consider empty packets with the last flag as bad packets.
	  Also reset buffers to NULL after giving away ownership of them to avoid
	  returning an already freed buffer.
	  Fixes https://gitlab.freedesktop.org/gstreamer/gstreamer/-/work_items/5119
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12059>

2026-06-17 16:18:50 +0300  Sebastian Dröge <sebastian@centricular.com>

	* gst/isomp4/atomsrecovery.c:
	  qtmoovrecover: Validate box sizes
	  Also validate box versions where it matters.
	  Fixes https://gitlab.freedesktop.org/gstreamer/gstreamer/-/work_items/5118
	  Fixes https://gitlab.freedesktop.org/gstreamer/gstreamer/-/work_items/5120
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12058>

2026-06-14 23:46:02 +0100  Tim-Philipp Müller <tim@centricular.com>

	* gst/rtp/gstrtpceltdepay.c:
	  rtpceltdepay: error out if anyone tries to use this element
	  Forbid use of this element and comment out all processing code.
	  There is no plausible reason this code should ever be executed in 2026
	  seeing that this was an experimental audio codec that never really gained
	  adoption and was superseded by (and included in) Opus more than a decade
	  ago. There are no decoders or encoders in GStreamer for this, and the
	  RTP mapping RFC never made it out of draft state either.
	  We post an error message in the state change function, so this processing
	  function should never be reached, we just ifdef the code out for clarity.
	  If anyone actually does have a legitimate need for this and can provide
	  sample streams, we will happily implement a depayloader in Rust.
	  Fixes https://gitlab.freedesktop.org/gstreamer/gstreamer/-/work_items/5157
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12039>

2026-07-03 09:22:31 +0200  Pablo García <pgarcia@fluendo.com>

	* docs/gst_plugins_cache.json:
	* gst/isomp4/gstqtmuxmap.c:
	  qtmux: Allow connection to ac3parse
	  ac3parse doesn't output the field 'parsed' so they cannot connect.
	  'framed' is also required by the muxer.
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12028>

2026-07-03 08:50:07 +0900  amy.ko <amy.ko@lge.com>

	* gst/shapewipe/gstshapewipe.c:
	  shapewipe: Fix missing mutex unlock in shutdown path
	  A deadlock may occur if the function returns with the
	  mask_mutex locked when the element is shutting down.
	  Add the missing g_mutex_unlock() in the shutdown label.
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12016>

2026-03-27 17:27:47 -0300  L. E. Segovia <amy@centricular.com>

	* ext/libpng/gstpngdec.c:
	  pngdec: fix wrong macro being used for ICC support test
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/11972>

2026-06-22 12:14:35 +0300  Sebastian Dröge <sebastian@centricular.com>

	* gst/matroska/matroska-read-common.c:
	  matroskademux: Don't pass non-GstElement pointers to GST_ELEMENT_ERROR
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/11918>

2026-03-30 09:44:27 -0300  L. E. Segovia <amy@centricular.com>

	* docs/gst_plugins_cache.json:
	* ext/gdk_pixbuf/gstgdkpixbufdec.c:
	* ext/gdk_pixbuf/meson.build:
	  gdkpixbufdec: remove Sun and Andrew raster formats
	  They were both removed in 2.32.1:
	  https://github.com/GNOME/gdk-pixbuf/commit/af2fca9bba5c127ca092c3a4bf7656015d6168ad
	  Moreover, the Andrew raster format (image/x-cmu-raster) doesn't match at
	  all the Sun raster format, the former is similar to LaTeX while the
	  latter is binary.
	  As a double safety measure, let's bump the minimum gdk-pixbuf version as
	  2.32.1 was released in 2015 [1] while 2.8.0 is from 2005 [2].
	  Fixes #5004
	  [1]: https://gitlab.gnome.org/GNOME/gdk-pixbuf/-/tags/2.32.0
	  [2]: https://gitlab.gnome.org/GNOME/gdk-pixbuf/-/tags/GTK_2_8_0
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/11901>

2026-06-15 15:24:24 +0200  Benoît Mauduit <benoit.mauduit@devialet.com>

	* ext/flac/gstflacenc.c:
	  flacenc: Use dash for property name in DO_UPDATE
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/11860>

2026-05-06 14:31:21 +0200  Benoît Mauduit <benoit.mauduit@devialet.com>

	* ext/flac/gstflacenc.c:
	  flacenc: Fix g_object_notify on loose-mid-side-stereo property
	  Fix an assertion warning on g_object_notify (in DO_UPDATE macro)
	  because there is no Gobject property named `loose_mid_side` (property
	  is loose_mid_side_stereo).
	  Assertion was :
	  ```
	  g_object_notify: object class 'GstFlacEnc' has no property named
	  'loose_mid_side'
	  ```
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/11860>

2026-06-12 13:27:54 +0100  Tim-Philipp Müller <tim@centricular.com>

	* meson.build:
	  Back to development after 1.28.4

=== release 1.28.4 ===

2026-06-12 13:19:43 +0100  Tim-Philipp Müller <tim@centricular.com>

	* gst-plugins-good.doap:
	* meson.build:
	  Release 1.28.4

2026-06-11 15:43:40 +1000  Matthew Waters <matthew@centricular.com>

	* ext/qt6/qt6glrenderer.cc:
	  qt6: remove an unneeded QOpenGLContext->makeCurrent()
	  This is no longer needed with Qt6.
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/11833>

2026-06-05 12:33:30 +0300  Sebastian Dröge <sebastian@centricular.com>

	* gst/audioparsers/gstsbcparse.c:
	  sbcparse: Add bounds checking to header parsing
	  Also the minimum valid frame size is 7 and not 6 (assertion) or 8 (header
	  parsing).
	  Fixes https://gitlab.freedesktop.org/gstreamer/gstreamer/-/work_items/5087
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/11817>

2026-06-05 11:24:33 +0300  Sebastian Dröge <sebastian@centricular.com>

	* ext/wavpack/gstwavpackdec.c:
	  wavpackdec: Unmap input buffer directly after decoding
	  In case of decoder errors we would otherwise unmap the buffer after
	  finish_frame(), which potentially invalidates the input buffer already.
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/11811>

2026-06-05 11:24:29 +0300  Sebastian Dröge <sebastian@centricular.com>

	* ext/wavpack/gstwavpackdec.c:
	  wavpackdec: Avoid integer overflow when checking input buffer size
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/11811>

2026-06-05 11:24:25 +0300  Sebastian Dröge <sebastian@centricular.com>

	* ext/wavpack/gstwavpackdec.c:
	  wavpackdec: Use correctly-sized variable types
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/11811>

2026-06-05 11:24:21 +0300  Sebastian Dröge <sebastian@centricular.com>

	* ext/wavpack/gstwavpackdec.c:
	  wavpackdec: Avoid integer overflow when calculating output buffer size
	  Fixes https://gitlab.freedesktop.org/gstreamer/gstreamer/-/work_items/5069
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/11811>

2026-05-31 14:46:21 +0300  Sebastian Dröge <sebastian@centricular.com>

	* ext/wavpack/gstwavpackenc.c:
	  wavpackenc: Handle >8 channels correctly when reordering
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/11757>

2026-05-31 13:42:32 +0300  Sebastian Dröge <sebastian@centricular.com>

	* gst/audioparsers/gstwavpackparse.c:
	  wavpackparse: Fix parsing of number of channels in new-style channel info chunks
	  The number of channels is spread out over three bytes, not two.
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/11757>

2026-05-31 13:41:36 +0300  Sebastian Dröge <sebastian@centricular.com>

	* gst/audioparsers/gstwavpackparse.c:
	  wavpackparse: Only default channel mask if no channels are given
	  A zero channel mask is completely valid for unpositioned channels.
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/11757>

2026-05-31 12:30:58 +0300  Sebastian Dröge <sebastian@centricular.com>

	* gst/audioparsers/gstwavpackparse.c:
	  wavpackparse: Map unsupported channel layouts to unpositioned channels
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/11757>

2026-05-31 12:13:47 +0300  Sebastian Dröge <sebastian@centricular.com>

	* ext/wavpack/gstwavpackdec.c:
	* ext/wavpack/gstwavpackdec.h:
	  wavpackdec: Handle unsupported channel layouts by mapping to unpositioned channels
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/11757>

2026-05-31 12:03:49 +0300  Sebastian Dröge <sebastian@centricular.com>

	* ext/wavpack/gstwavpackenc.c:
	  wavpackenc: Handle unpositioned and unsupported channel layouts
	  Fixes https://gitlab.freedesktop.org/gstreamer/gstreamer/-/work_items/5129
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/11757>

2026-05-31 12:00:39 +0300  Sebastian Dröge <sebastian@centricular.com>

	* ext/wavpack/gstwavpackcommon.c:
	  wavpack: Map unknown/invalid channel positions to an unpositioned layout
	  Instead of randomly failing or producing incomplete channel masks.
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/11757>

2026-05-31 11:58:59 +0300  Sebastian Dröge <sebastian@centricular.com>

	* ext/wavpack/gstwavpackcommon.c:
	* ext/wavpack/gstwavpackcommon.h:
	  wavpack: Remove unused function
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/11757>

2026-05-31 11:45:48 +0300  Sebastian Dröge <sebastian@centricular.com>

	* ext/wavpack/gstwavpackcommon.c:
	* ext/wavpack/gstwavpackcommon.h:
	* ext/wavpack/gstwavpackdec.c:
	* ext/wavpack/gstwavpackdec.h:
	* ext/wavpack/gstwavpackenc.c:
	* ext/wavpack/gstwavpackenc.h:
	  wavpack: Use more correct types and add some const qualifiers
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/11757>

2026-05-29 11:53:08 +0900  Hou Qi <qi.hou@nxp.com>

	* sys/v4l2/gstv4l2bufferpool.c:
	  v4l2: Fix buffer leak on qbuf failure
	  When gst_v4l2_buffer_pool_qbuf() fails in the output buffer processing
	  path of gst_v4l2_buffer_pool_process(), the to_queue buffer is not
	  unreferenced before jumping to the queue_failed error label. This buffer
	  was either obtained via gst_buffer_ref() on the input buffer or acquired
	  from the buffer pool, both of which take a reference that must be
	  released on failure.
	  Add the missing gst_buffer_unref() call to prevent leaking a buffer
	  reference each time qbuf fails.
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/11759>

2026-05-29 17:37:07 +0200  Jan Schmidt <jan@centricular.com>

	* tests/check/elements/mpegaudioparse.c:
	  tests/mpegaudioparse: Fix raciness in the state change handling
	  This test_parse_gapless_and_skip_padding_samples test sometimes
	  got stuck changing state synchronously if appsink prerolled too
	  quickly. Fix it to use asynchronous state changes and waiting
	  in all the required places.
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/11724>

2026-05-29 11:00:33 +0800  Hou Qi <qi.hou@nxp.com>

	* gst/matroska/matroska-mux.c:
	* gst/matroska/matroska-mux.h:
	  matroska-mux: Write ReferenceBlock for non-keyframe video in BlockGroups
	  When writing video frames using BlockGroups, the muxer did not include
	  a ReferenceBlock element for non-keyframe frames. According to the
	  Matroska specification, the absence of ReferenceBlock in a BlockGroup
	  signals that the block is a keyframe. Without it, demuxers have no way
	  to distinguish keyframes from delta frames when parsing BlockGroups.
	  This caused interoperability issues with demuxers that rely on
	  ReferenceBlock presence to identify non-keyframe video frames as delta
	  units, which is the standard behavior per the Matroska spec.
	  Add a ReferenceBlock element to BlockGroups for non-keyframe video
	  blocks so that demuxers can correctly flag them as delta units.
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/11722>

2026-05-29 13:26:37 +0300  Rares Branici <rares.branici@senstar.com>

	* gst/rtp/gstrtph265depay.c:
	  rtph265depay: fix mem leak
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/11715>

2026-05-19 10:29:37 +0200  Piotr Brzeziński <piotr@centricular.com>

	* sys/osxaudio/gstosxcoreaudio.c:
	  osxaudio: Fix stack overflow with >64ch audio devices
	  The fallback path for invalid channel positions didn't account for the
	  64 channel limit we have in osxaudio including the positions array, and
	  would overflow it if more channels were present.
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/11658>

2026-05-19 18:09:25 +0200  dec05eba <dec05eba@protonmail.com>

	* gst/isomp4/qtdemux.c:
	  qtdemux: parse mastering luminance as u32 instead of u16
	  According to the specification in ISO/IEC 14496-12 2020 12.1.7.1
	  these fields should be u32, not u16.
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/11661>

2026-05-11 18:33:25 +0100  Tim-Philipp Müller <tim@centricular.com>

	* meson.build:
	  Back to development after 1.28.3

=== release 1.28.3 ===

2026-05-11 18:28:12 +0100  Tim-Philipp Müller <tim@centricular.com>

	* gst-plugins-good.doap:
	* meson.build:
	  Release 1.28.3

2026-04-16 17:03:44 +0300  Sebastian Dröge <sebastian@centricular.com>

	* gst/isomp4/qtdemux.c:
	  qtdemux: Check for minimum stride requirements and width/height constraints with uncompressed video
	  And return an explicit error on mismatches.
	  Fixes https://gitlab.freedesktop.org/gstreamer/gstreamer/-/work_items/5043
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/11591>

2026-05-08 22:58:24 +1000  Jan Schmidt <jan@centricular.com>

	* ext/adaptivedemux2/hls/gsthlsdemux.c:
	  hlsdemux2: Abort wait for variant playlist on shutdown
	  If the element is stopped while waiting for the variant playlist,
	  exit the loop.
	  Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/11572>

2026-05-08 22:24:52 +1000  Jan Schmidt <jan@centricular.com>

	* ext/adaptivedemux2/gstadaptivedemux-stream.c:
