Script 'mail_helper' called by obssrc Hello community, here is the log from the commit of package xdg-desktop-portal for openSUSE:Factory checked in at 2026-06-19 16:30:49 ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Comparing /work/SRC/openSUSE:Factory/xdg-desktop-portal (Old) and /work/SRC/openSUSE:Factory/.xdg-desktop-portal.new.1956 (New) ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Package is "xdg-desktop-portal" Fri Jun 19 16:30:49 2026 rev:59 rq:1360254 version:1.22.1 Changes: -------- --- /work/SRC/openSUSE:Factory/xdg-desktop-portal/xdg-desktop-portal.changes 2026-06-11 17:25:32.885759285 +0200 +++ /work/SRC/openSUSE:Factory/.xdg-desktop-portal.new.1956/xdg-desktop-portal.changes 2026-06-19 17:23:26.562342621 +0200 @@ -1,0 +2,20 @@ +Wed Jun 17 16:57:14 UTC 2026 - Bjørn Lie <[email protected]> + +- Update to version 1.22.1: + + Security fixes: + - Fix a security issue which allows a malicious sandboxed + applications to redirect drag-and-drop and copy-paste data to + itself via a predictable key in FileTransfer.RetrieveFiles + (GHSA-c5cf-79w8-pvfh) + - Fix a security issue which allows a malicious sandboxed + applications to gain arbitrary write access to nonexistent + files outside of the sandbox via the "files" option in + FileChooser.SaveFiles (GHSA-cm83-2936-gxjm) + - Validate all App IDs in the Document Portal to prevent + malicious applications from providing a well-crafted App ID + which causes the parsing of arbitrary files on the host as + Glib.KeyFiles + + Enhancements: Disable PipeWire's realtime module to prevent + deadlocks + +------------------------------------------------------------------- Old: ---- xdg-desktop-portal-1.22.0.tar.xz New: ---- xdg-desktop-portal-1.22.1.tar.xz ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Other differences: ------------------ ++++++ xdg-desktop-portal.spec ++++++ --- /var/tmp/diff_new_pack.ZFrDDx/_old 2026-06-19 17:23:27.518375571 +0200 +++ /var/tmp/diff_new_pack.ZFrDDx/_new 2026-06-19 17:23:27.522375710 +0200 @@ -28,7 +28,7 @@ %define oname xdg-desktop-portal Name: %{oname}%{?psuffix} -Version: 1.22.0 +Version: 1.22.1 Release: 0 %if "%{flavor}" == "" Summary: A portal frontend service for Flatpak ++++++ _scmsync.obsinfo ++++++ --- /var/tmp/diff_new_pack.ZFrDDx/_old 2026-06-19 17:23:27.566377226 +0200 +++ /var/tmp/diff_new_pack.ZFrDDx/_new 2026-06-19 17:23:27.574377502 +0200 @@ -1,6 +1,6 @@ -mtime: 1780934945 -commit: 3c0e7c989e793fe63cdb02e3544b7e7fa91e102f61db89bfa5461952f824f62c +mtime: 1781715582 +commit: 01dea17f0f54d55ed9d11a5215171feedeeadf57766cd43e76f35f1c2022e41b url: https://src.opensuse.org/GNOME/xdg-desktop-portal -revision: 3c0e7c989e793fe63cdb02e3544b7e7fa91e102f61db89bfa5461952f824f62c +revision: 01dea17f0f54d55ed9d11a5215171feedeeadf57766cd43e76f35f1c2022e41b projectscmsync: https://src.opensuse.org/GNOME/_ObsPrj ++++++ build.specials.obscpio ++++++ ++++++ build.specials.obscpio ++++++ diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/.gitignore new/.gitignore --- old/.gitignore 1970-01-01 01:00:00.000000000 +0100 +++ new/.gitignore 2026-06-17 18:59:42.000000000 +0200 @@ -0,0 +1,4 @@ +*.obscpio +*.osc +_build.* +.pbuild ++++++ xdg-desktop-portal-1.22.0.tar.xz -> xdg-desktop-portal-1.22.1.tar.xz ++++++ ++++ 4120 lines of diff (skipped)
