Script 'mail_helper' called by obssrc Hello community, here is the log from the commit of package traefik for openSUSE:Factory checked in at 2026-03-27 16:51:17 ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Comparing /work/SRC/openSUSE:Factory/traefik (Old) and /work/SRC/openSUSE:Factory/.traefik.new.8177 (New) ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Package is "traefik" Fri Mar 27 16:51:17 2026 rev:49 rq:1343148 version:3.6.12 Changes: -------- --- /work/SRC/openSUSE:Factory/traefik/traefik.changes 2026-03-17 19:07:47.704869800 +0100 +++ /work/SRC/openSUSE:Factory/.traefik.new.8177/traefik.changes 2026-03-27 16:54:00.234741888 +0100 @@ -1,0 +2,46 @@ +Thu Mar 26 10:29:57 UTC 2026 - Johannes Weberhofer <[email protected]> + +- Version 3.6.12 +- Bugs fixes: + * acme + - Bump github.com/go-acme/lego/v4 to v4.33.0 + * api + - Fix allow colons and tildes in api.basePath validation + * grpc + - Bump google.golang.org/grpc to v1.79.3 + * k8s/ingress-nginx + - Fix auth-response-headers whitespace trimming in ingress-nginx provider + * middleware, authentication + - Prevent duplicate user headers in basic and digest auth middleware + * middleware + - Fix StripPrefix and StripPrefixRegex to slice the prefix using + encoded prefix length + * server + - Fix comment and unnecessary allocation in withRoutingPath + * server, tcp + - Fix postgres STARTTLS with TLS termination + +- Version 3.6.11 +- CVEs fixed: + * CVE-2026-32595 (Advisory GHSA-g3hg-j4jv-cwfr) boo#1260016 + * CVE-2026-32305 (Advisory GHSA-wvvq-wgcr-9q48) boo#1260017 + * CVE-2026-32695 (Advisory GHSA-67jx-r9pv-98rj) + +- Bugs fixes: + * http + - Add maxResponseBodySize configuration on HTTP provider + * tls + - Support fragmented TLS client hello + * middleware, authentication + - Make basic auth check timing constant + * k8s/ingress-nginx + - Fix proxy-ssl-verify annotation + * k8s/ingress + - Fix ingress router's rule + * k8s/gatewayapi + - Fix incorrect hostname matching between listener and route + * webui + - Remove AGPL license in code + * logs, otel + - Add OTel-conformant trace context attributes to access logs +------------------------------------------------------------------- Old: ---- traefik-v3.6.10.src.tar.gz New: ---- traefik-v3.6.12.src.tar.gz ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Other differences: ------------------ ++++++ traefik.spec ++++++ --- /var/tmp/diff_new_pack.g19NnG/_old 2026-03-27 16:54:01.254784588 +0100 +++ /var/tmp/diff_new_pack.g19NnG/_new 2026-03-27 16:54:01.254784588 +0100 @@ -23,7 +23,7 @@ %define buildmode pie %endif Name: traefik -Version: 3.6.10 +Version: 3.6.12 Release: 0 Summary: The Cloud Native Application Proxy License: MIT ++++++ traefik-v3.6.10.src.tar.gz -> traefik-v3.6.12.src.tar.gz ++++++ /work/SRC/openSUSE:Factory/traefik/traefik-v3.6.10.src.tar.gz /work/SRC/openSUSE:Factory/.traefik.new.8177/traefik-v3.6.12.src.tar.gz differ: char 11, line 1 ++++++ vendor.tar.gz ++++++ /work/SRC/openSUSE:Factory/traefik/vendor.tar.gz /work/SRC/openSUSE:Factory/.traefik.new.8177/vendor.tar.gz differ: char 14, line 1
