Script 'mail_helper' called by obssrc Hello community, here is the log from the commit of package vexctl for openSUSE:Factory checked in at 2025-06-17 18:24:38 ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Comparing /work/SRC/openSUSE:Factory/vexctl (Old) and /work/SRC/openSUSE:Factory/.vexctl.new.19631 (New) ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Package is "vexctl" Tue Jun 17 18:24:38 2025 rev:2 rq:1286234 version:0.3.0+git133.ff97560 Changes: -------- --- /work/SRC/openSUSE:Factory/vexctl/vexctl.changes 2024-11-20 17:00:53.059077044 +0100 +++ /work/SRC/openSUSE:Factory/.vexctl.new.19631/vexctl.changes 2025-06-17 18:25:20.242078757 +0200 @@ -1,0 +2,84 @@ +Mon Jun 16 21:57:19 UTC 2025 - Jeff Kowalczyk <jkowalc...@suse.com> + +- Update to version 0.3.0+git133.ff97560: + * Bump the all group across 1 directory with 2 updates + * Bump softprops/action-gh-release from 2.3.0 to 2.3.2 in the all group + * Bump github.com/cloudflare/circl in the go_modules group + * Bump softprops/action-gh-release from 2.2.2 to 2.3.0 in the all group + * Bump github.com/google/go-containerregistry in the all group + * Bump actions/setup-go from 5.4.0 to 5.5.0 in the all group + * Bump github.com/sigstore/sigstore from 1.9.3 to 1.9.4 in the all group + * Bump the all group across 1 directory with 2 updates + * Bump sigstore/cosign-installer from 3.8.1 to 3.8.2 in the all group + * Bump softprops/action-gh-release from 2.2.1 to 2.2.2 in the all group + * Bump kubernetes-sigs/release-actions in the all group + * Bump ko-build/setup-ko from 0.8 to 0.9 in the all group + * Bump github.com/sigstore/cosign/v2 from 2.4.3 to 2.5.0 + * Bump goreleaser/goreleaser-action from 6.2.1 to 6.3.0 in the all group + * Bump sigs.k8s.io/release-utils from 0.11.0 to 0.11.1 in the all group + * Bump github.com/golang-jwt/jwt/v4 in the go_modules group + * Bump the all group with 2 updates + * Bump golangci/golangci-lint-action from 6.5.1 to 6.5.2 in the all group + * Bump github.com/sigstore/sigstore from 1.8.15 to 1.9.1 + * Bump golang.org/x/net from 0.35.0 to 0.36.0 in the go_modules group + * Bump golangci/golangci-lint-action from 6.5.0 to 6.5.1 in the all group + * Bump github.com/go-jose/go-jose/v3 in the go_modules group + * Bump github.com/go-jose/go-jose/v4 in the go_modules group + * Bump actions/upload-artifact from 4.6.0 to 4.6.1 in the all group + * Bump sigstore/cosign-installer from 3.8.0 to 3.8.1 in the all group + * Bump the all group with 2 updates + * use go1.24 and update golangci-lint + * Bump golangci/golangci-lint-action from 6.3.3 to 6.5.0 in the all group + * Bump github.com/spf13/cobra from 1.8.1 to 1.9.1 + * Bump github.com/sigstore/sigstore from 1.8.12 to 1.8.14 in the all group + * Bump golangci/golangci-lint-action from 6.3.2 to 6.3.3 in the all group + * Bump goreleaser/goreleaser-action from 6.1.0 to 6.2.1 in the all group + * Bump golangci/golangci-lint-action from 6.3.0 to 6.3.2 in the all group + * Bump sigstore/cosign-installer from 3.7.0 to 3.8.0 in the all group + * Bump golangci/golangci-lint-action from 6.2.0 to 6.3.0 in the all group + * Bump the all group with 2 updates + * Bump sigs.k8s.io/release-utils from 0.9.0 to 0.10.0 + * Bump github.com/sigstore/rekor from 1.3.8 to 1.3.9 in the all group + * Bump actions/setup-go from 5.2.0 to 5.3.0 in the all group + * Bump golangci/golangci-lint-action from 6.1.1 to 6.2.0 in the all group + * Bump sigs.k8s.io/release-utils from 0.8.5 to 0.9.0 + * Bump go dependencies manually + * Bump ko-build/setup-ko from 0.7 to 0.8 in the all group + * Bump actions/upload-artifact from 4.5.0 to 4.6.0 in the all group + * Bump softprops/action-gh-release from 2.2.0 to 2.2.1 in the all group + * Bump actions/upload-artifact from 4.4.3 to 4.5.0 in the all group + * Bump golang.org/x/crypto from 0.28.0 to 0.31.0 in the go_modules group + * Bump the all group with 2 updates + * Bump softprops/action-gh-release from 2.0.9 to 2.1.0 in the all group + * Bump github.com/golang-jwt/jwt/v4 in the go_modules group + * Bump goreleaser/goreleaser-action from 6.0.0 to 6.1.0 in the all group + * Bump softprops/action-gh-release from 2.0.8 to 2.0.9 in the all group + * Update verify.yaml + * Update release.yaml + * Update ci-build-test.yaml + * Bump actions/setup-go from 5.0.2 to 5.1.0 in the all group + * Bump actions/checkout from 4.2.1 to 4.2.2 in the all group + * Bump kubernetes-sigs/release-actions in the all group + * Bump github.com/sigstore/sigstore from 1.8.9 to 1.8.10 in the all group + * Bump actions/upload-artifact from 4.4.2 to 4.4.3 in the all group + * Bump actions/upload-artifact from 4.4.1 to 4.4.2 in the all group + * Bump the all group with 2 updates + * Bump sigstore/cosign-installer from 3.6.0 to 3.7.0 in the all group + * Bump golangci/golangci-lint-action from 6.1.0 to 6.1.1 in the all group + * Bump github.com/sigstore/cosign/v2 from 2.4.0 to 2.4.1 in the all group + * Bump actions/checkout from 4.1.7 to 4.2.0 in the all group + * Bump sigs.k8s.io/release-utils from 0.8.4 to 0.8.5 in the all group + * upgrade to go1.23 +- Packaging improvements: + * _service tar_scm set revision to branch main until upstream + next has a tagged release + * _service tar_scm when revision is a branch name e.g. master + use versionformat @PARENT_TAG@+git@TAG_OFFSET@.%h to represent + git commit history included beyond last tagged release. Archive + name will be: name-X.Y.Z+gitN.shortsha.tar.gz. When upstream + project resumes tagged releases drop the param versionformat + and restore revision to tag name e.g. vX.Y.Z. + * Update to BuildRequires: golang(API) >= 1.24 matching go.mod + * %install remove extraneous comment and dest path quoting + +------------------------------------------------------------------- Old: ---- vexctl-0.3.0.tar.gz New: ---- vexctl-0.3.0+git133.ff97560.tar.gz ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Other differences: ------------------ ++++++ vexctl.spec ++++++ --- /var/tmp/diff_new_pack.PNT3qn/_old 2025-06-17 18:25:21.034111692 +0200 +++ /var/tmp/diff_new_pack.PNT3qn/_new 2025-06-17 18:25:21.034111692 +0200 @@ -1,7 +1,7 @@ # # spec file for package vexctl # -# Copyright (c) 2024 SUSE LLC +# Copyright (c) 2025 SUSE LLC # # All modifications and additions to the file contributed by third parties # remain the property of their copyright owners, unless otherwise agreed @@ -17,7 +17,7 @@ Name: vexctl -Version: 0.3.0 +Version: 0.3.0+git133.ff97560 Release: 0 Summary: CLI tool to create, transform and attest VEX metadata License: Apache-2.0 @@ -25,7 +25,7 @@ URL: https://github.com/openvex/vexctl Source: %{name}-%{version}.tar.gz Source1: vendor.tar.gz -BuildRequires: golang(API) >= 1.23 +BuildRequires: golang(API) >= 1.24 %description vexctl is a CLI tool to create, apply, and attest VEX (Vulnerability @@ -51,8 +51,7 @@ ./%{name} --help %install -# Install the binary. -install -D -m 0755 %{name} "%{buildroot}/%{_bindir}/%{name}" +install -D -m 0755 %{name} %{buildroot}/%{_bindir}/%{name} %files %doc README.md ++++++ _service ++++++ --- /var/tmp/diff_new_pack.PNT3qn/_old 2025-06-17 18:25:21.066113022 +0200 +++ /var/tmp/diff_new_pack.PNT3qn/_new 2025-06-17 18:25:21.070113188 +0200 @@ -3,8 +3,8 @@ <param name="url">https://github.com/openvex/vexctl.git</param> <param name="scm">git</param> <param name="exclude">.git</param> - <param name="revision">v0.3.0</param> - <param name="versionformat">@PARENT_TAG@</param> + <param name="revision">main</param> + <param name="versionformat">@PARENT_TAG@+git@TAG_OFFSET@.%h</param> <param name="changesgenerate">enable</param> <param name="versionrewrite-pattern">v(.*)</param> </service> ++++++ _servicedata ++++++ --- /var/tmp/diff_new_pack.PNT3qn/_old 2025-06-17 18:25:21.094114186 +0200 +++ /var/tmp/diff_new_pack.PNT3qn/_new 2025-06-17 18:25:21.094114186 +0200 @@ -1,6 +1,6 @@ <servicedata> <service name="tar_scm"> <param name="url">https://github.com/openvex/vexctl.git</param> - <param name="changesrevision">c613023a69ce990a54c25c2f5e69d5d78285927f</param></service></servicedata> + <param name="changesrevision">ff97560be8be7de7f32d52c8cfabdad5034a90ad</param></service></servicedata> (No newline at EOF) ++++++ vendor.tar.gz ++++++ /work/SRC/openSUSE:Factory/vexctl/vendor.tar.gz /work/SRC/openSUSE:Factory/.vexctl.new.19631/vendor.tar.gz differ: char 5, line 1