Script 'mail_helper' called by obssrc
Hello community,

here is the log from the commit of package go1.27 for openSUSE:Factory checked 
in at 2026-08-18 16:35:45
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Comparing /work/SRC/openSUSE:Factory/go1.27 (Old)
 and      /work/SRC/openSUSE:Factory/.go1.27.new.1258 (New)
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Package is "go1.27"

Tue Aug 18 16:35:45 2026 rev:2 rq:1371109 version:1.27rc3

Changes:
--------
--- /work/SRC/openSUSE:Factory/go1.27/go1.27.changes    2026-07-28 
17:54:08.740575866 +0200
+++ /work/SRC/openSUSE:Factory/.go1.27.new.1258/go1.27.changes  2026-08-18 
16:36:07.152147063 +0200
@@ -1,0 +2,18 @@
+Thu Aug 13 17:38:53 UTC 2026 - Jeff Kowalczyk <[email protected]>
+
+- go1.27rc3 (released 2026-08-13) is a release candidate version of
+  go1.27 cut from the master branch at the revision tagged
+  go1.27rc3.
+  Refs boo#1272545 go1.27 release tracking
+  CVE-2026-56853 CVE-2026-39821 CVE-2026-56862 CVE-2026-56859 CVE-2026-56860 
CVE-2026-56865 CVE-2026-56864 CVE-2026-33818 CVE-2026-56858
+  * go#80205 boo#1275028 security: fix CVE-2026-56853 net/http: apply 
ReadHeaderTimeout when doing unencrypted HTTP/2 check
+  * go#78760 boo#1266609 security: fix CVE-2026-39821 x/net/idna: failure to 
reject ASCII-only Punycode-encoded labels
+  * go#80528 boo#1275032 security: fix CVE-2026-56862 crypto/tls: limit 
handshake messages we are willing to accept post-handshake
+  * go#80481 boo#1275026 security: fix CVE-2026-56859 encoding/xml: add 
recursion depth guard during decode
+  * go#80494 boo#1275029 security: fix CVE-2026-56860 net/url: avoid quadratic 
complexity in resolvePath
+  * go#80744 boo#1275024 security: fix CVE-2026-56865 x/mod/sumdb/tlog: fix 
transparency log tile verification bypass
+  * go#80745 boo#1275025 security: fix CVE-2026-56864 x/mod/sumdb: ignore 
unrelated, unauthenticated hashes in Lookup
+  * go#80405 boo#1275034 security: fix CVE-2026-33818 encoding/asn1: enforce 
maximum recursion depth
+  * go#80435 boo#1275033 security: fix CVE-2026-56858 html/template: fix 
Javascript regexp context tracking
+
+-------------------------------------------------------------------

Old:
----
  go1.27rc2.src.tar.gz

New:
----
  go1.27rc3.src.tar.gz

++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Other differences:
------------------
++++++ go1.27.spec ++++++
--- /var/tmp/diff_new_pack.qRFkjR/_old  2026-08-18 16:36:09.675237326 +0200
+++ /var/tmp/diff_new_pack.qRFkjR/_new  2026-08-18 16:36:09.678237433 +0200
@@ -96,7 +96,7 @@
 %endif
 
 Name:           go1.27
-Version:        1.27rc2
+Version:        1.27rc3
 Release:        0
 Summary:        A compiled, garbage-collected, concurrent programming language
 License:        BSD-3-Clause

++++++ go1.27rc2.src.tar.gz -> go1.27rc3.src.tar.gz ++++++
/work/SRC/openSUSE:Factory/go1.27/go1.27rc2.src.tar.gz 
/work/SRC/openSUSE:Factory/.go1.27.new.1258/go1.27rc3.src.tar.gz differ: char 
13, line 1

Reply via email to