Script 'mail_helper' called by obssrc Hello community, here is the log from the commit of package mistral-vibe for openSUSE:Factory checked in at 2026-09-14 16:22:43 ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Comparing /work/SRC/openSUSE:Factory/mistral-vibe (Old) and /work/SRC/openSUSE:Factory/.mistral-vibe.new.1265 (New) ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Package is "mistral-vibe" Mon Sep 14 16:22:43 2026 rev:21 rq:1377760 version:2.25.4 Changes: -------- --- /work/SRC/openSUSE:Factory/mistral-vibe/mistral-vibe.changes 2026-09-12 21:25:31.367951842 +0200 +++ /work/SRC/openSUSE:Factory/.mistral-vibe.new.1265/mistral-vibe.changes 2026-09-14 16:22:45.215503230 +0200 @@ -1,0 +2,20 @@ +Sun Sep 13 16:55:02 UTC 2026 - Martin Pluskal <[email protected]> + +- Update to 2.25.4: + * Shell permission checks now require approval for risky syntax + and command options that could bypass workspace and denylist + controls (CVE-2026-87984, CVE-2026-87985, CVE-2026-87986, + CVE-2026-87987, and residual CVE-2026-87988 variants) + * Connector discovery excludes raw HTTP connectors without MCP + tools; one invalid connector no longer blocks the rest, and + over-cap accounts keep a bounded catalog + * Automatic session titles use the active model on custom + endpoints; ACP clients always list the active mode + * Smart-approve appears in the Vibe Desktop mode picker and + escalates a repeated risky action to a confirmation prompt + with the reason; auto-approved calls show a note, not a warning + * @ file mentions resolve against every workspace root including + --add-dir ones; --add-dir keeps the working directory in roots +- All nine patches re-apply cleanly, no rebase needed + +------------------------------------------------------------------- Old: ---- mistral-vibe-2.25.3.tar.gz New: ---- mistral-vibe-2.25.4.tar.gz ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Other differences: ------------------ ++++++ mistral-vibe.spec ++++++ --- /var/tmp/diff_new_pack.iCQDC2/_old 2026-09-14 16:22:46.741567296 +0200 +++ /var/tmp/diff_new_pack.iCQDC2/_new 2026-09-14 16:22:46.743567380 +0200 @@ -28,7 +28,7 @@ %endif %define origname mistral-vibe Name: %{origname}%{psuffix} -Version: 2.25.3 +Version: 2.25.4 Release: 0 Summary: Minimal CLI coding agent by Mistral License: Apache-2.0 ++++++ _scmsync.obsinfo ++++++ --- /var/tmp/diff_new_pack.iCQDC2/_old 2026-09-14 16:22:46.873572838 +0200 +++ /var/tmp/diff_new_pack.iCQDC2/_new 2026-09-14 16:22:46.881573174 +0200 @@ -1,5 +1,5 @@ -mtime: 1789198921 -commit: 410b7c748e51d55eb5a098c4fb55e99715d22a2079fcfec617cfa406eefb5ce0 +mtime: 1789319620 +commit: ef25ca8d7a609d354780161982786da34888317bf5d41e677dea43f769268b97 url: https://src.opensuse.org/AI/mistral-vibe.git revision: factory ++++++ build.specials.obscpio ++++++ ++++++ build.specials.obscpio ++++++ diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/.gitignore new/.gitignore --- old/.gitignore 1970-01-01 01:00:00.000000000 +0100 +++ new/.gitignore 2026-09-13 19:13:40.000000000 +0200 @@ -0,0 +1,9 @@ +.assets +_build.* +*.obscpio +*.obsinfo +*.osc +.pbuild +_service:* +mistral-vibe-*-build/ +.aider* ++++++ mistral-vibe-2.25.3.tar.gz -> mistral-vibe-2.25.4.tar.gz ++++++ ++++ 4027 lines of diff (skipped)
