Script 'mail_helper' called by obssrc Hello community, here is the log from the commit of package syft for openSUSE:Factory checked in at 2025-10-23 16:37:52 ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Comparing /work/SRC/openSUSE:Factory/syft (Old) and /work/SRC/openSUSE:Factory/.syft.new.1980 (New) ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Package is "syft" Thu Oct 23 16:37:52 2025 rev:109 rq:1313148 version:1.36.0 Changes: -------- --- /work/SRC/openSUSE:Factory/syft/syft.changes 2025-10-21 11:17:41.025978636 +0200 +++ /work/SRC/openSUSE:Factory/.syft.new.1980/syft.changes 2025-10-23 16:38:50.589930130 +0200 @@ -1,0 +2,27 @@ +Thu Oct 23 05:40:41 UTC 2025 - Johannes Kastl <[email protected]> + +- Update to version 1.36.0 (1.35.0 was not released): + * Added Features + - Add the ability to fetch remote licenses for pnpm-lock.yaml + files [#4286 @timols] + - support universal (fat) mach-o binary files [#4278 + @JoeyShapiro] + - pdm support [#2709 #4234 @paulslaby] + * Bug Fixes + - Remove duplicate image source providers [#4289 @Rupikz] + - syft can't extract go module information from executables on + Windows [#4271 #4285 @JoeyShapiro] + * Dependencies + - chore(deps): update tools to latest versions (#4302) + - chore(deps): bump github.com/github/go-spdx/v2 from 2.3.3 to + 2.3.4 (#4301) + - chore(deps): bump github/codeql-action from 4.30.8 to 4.30.9 + (#4299) + - chore(deps): bump sigstore/cosign-installer from 3.10.0 to + 4.0.0 (#4296) + - chore(deps): bump anchore/sbom-action from 0.20.7 to 0.20.8 + (#4297) + - chore(deps): bump anchore/sbom-action from 0.20.6 to 0.20.7 + (#4293) + +------------------------------------------------------------------- Old: ---- syft-1.34.2.obscpio New: ---- syft-1.36.0.obscpio ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Other differences: ------------------ ++++++ syft.spec ++++++ --- /var/tmp/diff_new_pack.K9q27x/_old 2025-10-23 16:38:52.970030498 +0200 +++ /var/tmp/diff_new_pack.K9q27x/_new 2025-10-23 16:38:52.970030498 +0200 @@ -17,7 +17,7 @@ Name: syft -Version: 1.34.2 +Version: 1.36.0 Release: 0 Summary: CLI tool and library for generating a Software Bill of Materials License: Apache-2.0 ++++++ _service ++++++ --- /var/tmp/diff_new_pack.K9q27x/_old 2025-10-23 16:38:53.034033198 +0200 +++ /var/tmp/diff_new_pack.K9q27x/_new 2025-10-23 16:38:53.038033366 +0200 @@ -3,7 +3,7 @@ <param name="url">https://github.com/anchore/syft</param> <param name="scm">git</param> <param name="exclude">.git</param> - <param name="revision">v1.34.2</param> + <param name="revision">v1.36.0</param> <param name="versionformat">@PARENT_TAG@</param> <param name="versionrewrite-pattern">v(.*)</param> <param name="changesgenerate">enable</param> ++++++ _servicedata ++++++ --- /var/tmp/diff_new_pack.K9q27x/_old 2025-10-23 16:38:53.074034884 +0200 +++ /var/tmp/diff_new_pack.K9q27x/_new 2025-10-23 16:38:53.078035053 +0200 @@ -1,6 +1,6 @@ <servicedata> <service name="tar_scm"> <param name="url">https://github.com/anchore/syft</param> - <param name="changesrevision">0c98a364d503789ff8d7f122763bb8748de9772f</param></service></servicedata> + <param name="changesrevision">8be463911ce718ff70179ded9a2a4dd37549d374</param></service></servicedata> (No newline at EOF) ++++++ syft-1.34.2.obscpio -> syft-1.36.0.obscpio ++++++ ++++ 5731 lines of diff (skipped) ++++++ syft.obsinfo ++++++ --- /var/tmp/diff_new_pack.K9q27x/_old 2025-10-23 16:38:58.186250466 +0200 +++ /var/tmp/diff_new_pack.K9q27x/_new 2025-10-23 16:38:58.190250634 +0200 @@ -1,5 +1,5 @@ name: syft -version: 1.34.2 -mtime: 1760612552 -commit: 0c98a364d503789ff8d7f122763bb8748de9772f +version: 1.36.0 +mtime: 1761140298 +commit: 8be463911ce718ff70179ded9a2a4dd37549d374 ++++++ vendor.tar.gz ++++++ /work/SRC/openSUSE:Factory/syft/vendor.tar.gz /work/SRC/openSUSE:Factory/.syft.new.1980/vendor.tar.gz differ: char 136, line 1
