Script 'mail_helper' called by obssrc Hello community, here is the log from the commit of package cargo-audit for openSUSE:Factory checked in at 2026-09-09 16:20:23 ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Comparing /work/SRC/openSUSE:Factory/cargo-audit (Old) and /work/SRC/openSUSE:Factory/.cargo-audit.new.1265 (New) ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Package is "cargo-audit" Wed Sep 9 16:20:23 2026 rev:32 rq:1376514 version:0.22.2~git0.281452c Changes: -------- --- /work/SRC/openSUSE:Factory/cargo-audit/cargo-audit.changes 2026-08-14 22:05:47.525456574 +0200 +++ /work/SRC/openSUSE:Factory/.cargo-audit.new.1265/cargo-audit.changes 2026-09-09 16:22:41.856894181 +0200 @@ -1,0 +2,9 @@ +Wed Sep 9 03:41:31 UTC 2026 - William Brown <[email protected]> + +- bsc#1278238 - CVE-2026-82247 - gitoxide's gix-url crate (<= 0.32.0, fixed in 0.37.1) uses a hand-rolled URL parser that does not treat '?' or '#' as terminating the authority +- bsc#1278228 - CVE-2026-82251 - gitoxide before 0.52.1 fails to validate submodule names from .gitmodules configuration, allowing path traversal +- bsc#1278129 - CVE-2026-82250 - gitoxide gix-packetline versions before 0.21.5 contain a panic vulnerability in the TextRef implementation +- bsc#1278107 - CVE-2026-82253 - gitoxide (Rust crates gix <= 0.72.0 and gix-validate <= 0.10.0) contains a path traversal vulnerability. +- bsc#1277888 - CVE-2026-82254 - gitoxide before 0.69.0 contains unchecked array indexing in delta application + +------------------------------------------------------------------- ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Other differences: ------------------ ++++++ vendor.tar.zst ++++++ /work/SRC/openSUSE:Factory/cargo-audit/vendor.tar.zst /work/SRC/openSUSE:Factory/.cargo-audit.new.1265/vendor.tar.zst differ: char 7, line 1
