Script 'mail_helper' called by obssrc
Hello community,

here is the log from the commit of package cargo-audit for openSUSE:Factory 
checked in at 2026-09-09 16:20:23
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Comparing /work/SRC/openSUSE:Factory/cargo-audit (Old)
 and      /work/SRC/openSUSE:Factory/.cargo-audit.new.1265 (New)
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Package is "cargo-audit"

Wed Sep  9 16:20:23 2026 rev:32 rq:1376514 version:0.22.2~git0.281452c

Changes:
--------
--- /work/SRC/openSUSE:Factory/cargo-audit/cargo-audit.changes  2026-08-14 
22:05:47.525456574 +0200
+++ /work/SRC/openSUSE:Factory/.cargo-audit.new.1265/cargo-audit.changes        
2026-09-09 16:22:41.856894181 +0200
@@ -1,0 +2,9 @@
+Wed Sep  9 03:41:31 UTC 2026 - William Brown <[email protected]>
+
+- bsc#1278238 - CVE-2026-82247 - gitoxide's gix-url crate (<= 0.32.0, fixed in 
0.37.1) uses a hand-rolled URL parser that does not treat '?' or '#' as 
terminating the authority
+- bsc#1278228 - CVE-2026-82251 - gitoxide before 0.52.1 fails to validate 
submodule names from .gitmodules configuration, allowing path traversal
+- bsc#1278129 - CVE-2026-82250 - gitoxide gix-packetline versions before 
0.21.5 contain a panic vulnerability in the TextRef implementation
+- bsc#1278107 - CVE-2026-82253 - gitoxide (Rust crates gix <= 0.72.0 and 
gix-validate <= 0.10.0) contains a path traversal vulnerability.
+- bsc#1277888 - CVE-2026-82254 - gitoxide before 0.69.0 contains unchecked 
array indexing in delta application
+
+-------------------------------------------------------------------

++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Other differences:
------------------
++++++ vendor.tar.zst ++++++
/work/SRC/openSUSE:Factory/cargo-audit/vendor.tar.zst 
/work/SRC/openSUSE:Factory/.cargo-audit.new.1265/vendor.tar.zst differ: char 7, 
line 1

Reply via email to