Script 'mail_helper' called by obssrc
Hello community,

here is the log from the commit of package go1.26 for openSUSE:Factory checked 
in at 2026-08-15 22:39:38
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Comparing /work/SRC/openSUSE:Factory/go1.26 (Old)
 and      /work/SRC/openSUSE:Factory/.go1.26.new.1258 (New)
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Package is "go1.26"

Sat Aug 15 22:39:38 2026 rev:16 rq:1371108 version:1.26.6

Changes:
--------
--- /work/SRC/openSUSE:Factory/go1.26/go1.26.changes    2026-07-21 
22:53:31.171605616 +0200
+++ /work/SRC/openSUSE:Factory/.go1.26.new.1258/go1.26.changes  2026-08-15 
22:39:44.334712514 +0200
@@ -1,0 +2,37 @@
+Thu Aug 13 17:25:07 UTC 2026 - Jeff Kowalczyk <[email protected]>
+
+- go1.26.6 (released 2026-08-13) includes security fixes to the go
+  command, and the crypto/tls, encoding/asn1, encoding/xml,
+  html/template, net, net/http, and net/url packages, as well as
+  bug fixes to the compiler, the linker, the runtime, and the
+  crypto/tls and os packages.
+  Refs boo#1255111 go1.26 release tracking
+  CVE-2026-56853 CVE-2026-39821 CVE-2026-56862 CVE-2026-56859 CVE-2026-56860 
CVE-2026-56865 CVE-2026-56864 CVE-2026-33818 CVE-2026-56858
+  * go#80224 go#80205 boo#1275028 security: fix CVE-2026-56853 net/http: apply 
ReadHeaderTimeout when doing unencrypted HTTP/2 check
+  * go#80298 go#78760 boo#1266609 security: fix CVE-2026-39821 x/net/idna: 
failure to reject ASCII-only Punycode-encoded labels
+  * go#80531 go#80528 boo#1275032 security: fix CVE-2026-56862 crypto/tls: 
limit handshake messages we are willing to accept post-handshake
+  * go#80628 go#80481 boo#1275026 security: fix CVE-2026-56859 encoding/xml: 
add recursion depth guard during decode
+  * go#80630 go#80494 boo#1275029 security: fix CVE-2026-56860 net/url: avoid 
quadratic complexity in resolvePath
+  * go#80765 go#80744 boo#1275024 security: fix CVE-2026-56865 
x/mod/sumdb/tlog: fix transparency log tile verification bypass
+  * go#80767 go#80745 boo#1275025 security: fix CVE-2026-56864 x/mod/sumdb: 
ignore unrelated, unauthenticated hashes in Lookup
+  * go#80769 go#80405 boo#1275034 security: fix CVE-2026-33818 encoding/asn1: 
enforce maximum recursion depth
+  * go#80867 go#80435 boo#1275033 security: fix CVE-2026-56858 html/template: 
fix Javascript regexp context tracking
+  * go#79876 cmd/compile: prove misscompilation in slicemask folding leaves 
garbage in the upper bits
+  * go#80099 cmd/compile: internal compiler error invalid heap allocated var 
without Heapaddr
+  * go#80131 cmd/link: peCreateExportFile generates invalid .def file when 
output name has trailing dot (c-shared on Windows)
+  * go#80365 os: Root's MkdirAll can't create paths ending in forward slashes
+  * go#80367 os: TestRootMultiReadFile fails on netbsd/arm64 after CL 797880
+  * go#80369 os: TestRootConsistencyRemoveAll fails on Plan 9 after CL 797880
+  * go#80394 runtime: arm64 found pointer to free object with safe code
+  * go#80441 runtime: uninitialized register due to wrong ABI in 
mach_vm_region_trampoline leads to libc following garbage stack data as a 
pointer
+  * go#80478 cmd/compile: riscv64 miscompiles struct copy, corrupting a []byte 
slice field
+  * go#80499 runtime: js/wasm: "found bad pointer in Go heap" — 
link-layout-constant value recorded as a pointer in the write-barrier buffer
+  * go#80579 cmd/compile: regalloc uses unreliable type data (like 
v.Type.IsSigned()) to choose the restore of spills
+  * go#80606 crypto/tls: escape hatch for FIPS 140-3 mode Extended Master 
Secret enforcement
+  * go#80609 net, x/net/dns/dnsmessage: panic when parsing invalid SVCB record
+  * go#80615 cmd/compile: mips64le misscompile OffPtr by a const which doesn't 
fit 32bits resulting in panic
+  * go#80617 cmd/compile: mips/mips64, multiply/divide results spilled from 
HI/LO corrupted w/ big stack frames
+  * go#80619 cmd/compile: prove bug causes invalid indirect call
+  * go#80715 runtime: fpTracebackPartialExpand SIGSEGV under high panic load
+
+-------------------------------------------------------------------

Old:
----
  go1.26.5.src.tar.gz

New:
----
  go1.26.6.src.tar.gz

++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Other differences:
------------------
++++++ go1.26.spec ++++++
--- /var/tmp/diff_new_pack.hyfbLO/_old  2026-08-15 22:39:45.429751069 +0200
+++ /var/tmp/diff_new_pack.hyfbLO/_new  2026-08-15 22:39:45.430751104 +0200
@@ -96,7 +96,7 @@
 %endif
 
 Name:           go1.26
-Version:        1.26.5
+Version:        1.26.6
 Release:        0
 Summary:        A compiled, garbage-collected, concurrent programming language
 License:        BSD-3-Clause

++++++ go1.26.5.src.tar.gz -> go1.26.6.src.tar.gz ++++++
/work/SRC/openSUSE:Factory/go1.26/go1.26.5.src.tar.gz 
/work/SRC/openSUSE:Factory/.go1.26.new.1258/go1.26.6.src.tar.gz differ: char 
110, line 1

Reply via email to