Script 'mail_helper' called by obssrc
Hello community,

here is the log from the commit of package osv-scanner for openSUSE:Factory 
checked in at 2026-09-19 22:21:06
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Comparing /work/SRC/openSUSE:Factory/osv-scanner (Old)
 and      /work/SRC/openSUSE:Factory/.osv-scanner.new.383539 (New)
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Package is "osv-scanner"

Sat Sep 19 22:21:06 2026 rev:49 rq:1378925 version:2.6.0

Changes:
--------
--- /work/SRC/openSUSE:Factory/osv-scanner/osv-scanner.changes  2026-08-28 
19:54:28.940866837 +0200
+++ /work/SRC/openSUSE:Factory/.osv-scanner.new.383539/osv-scanner.changes      
2026-09-19 22:22:15.464395346 +0200
@@ -1,0 +2,68 @@
+Fri Sep 18 05:40:47 UTC 2026 - Johannes Kastl 
<[email protected]>
+
+- Update to version 2.6.0:
+  * Features:
+    - Feature #2888 Publish multi-arch (linux/arm64) image for
+      osv-scanner-action.
+    - Feature #3066 Configure retry policy with exponential backoff
+      for transient gRPC errors in scalibr plugins.
+    - Dependency scanning & lockfile improvements via osv-scalibr:
+      - Extract Git repository URLs and support local OSV tag
+        matching for Git-based dependencies in JavaScript lockfiles
+        (package-lock.json, yarn.lock, pnpm-lock.yaml, bun.lock).
+      - Assign pkg:git PURL type to Git commit-pinned dependencies
+        across JS and Cargo lockfiles to avoid false positives
+        against registry packages (#2863).
+      - Retain packages without a version or PURL in SPDX output
+        (google/osv-scalibr#2375) and merge related packages based
+        on lineage relationships.
+    - New extractors and plugin support via osv-scalibr:
+      - Many additional filetypes are supported. These are not
+        enabled by default yet, so if you need a particular new
+        filetype, use --experimental-plugins flag. See "Supported
+        Inventory Types" for the extractor name.
+  * Fixes:
+    - Bug #3075 Ensure results property in JSON output is an empty
+      array [] instead of null when scanning with
+      --allow-no-lockfiles and no lockfiles are found.
+    - Bug #3071 Preserve valid UTF-8 sequences when truncating
+      multibyte text in vertical output.
+    - Bug #2919 Add filter to show packages with license violations
+      but no vulnerabilities in the HTML report.
+    - Bug #3049 Keep filter dropdown checklist open when clicking
+      options in the HTML report.
+    - Bug #3023 Guard against panic on empty or whitespace-only
+      license expressions in SPDX license evaluation.
+    - Bug #3032 Bound recursion depth when parsing SPDX license
+      expressions to prevent stack overflow on deeply nested
+      expressions.
+    - Bug #3061 Remove purl caching in scan filtering to avoid
+      dropping SBOM packages without purls.
+    - Bug #3063 Log plugin and enricher errors during container
+      scans instead of failing silently.
+    - Bug #2977 Return an error instead of aborting the process
+      (log.Fatalf) when an rlib archive has no object file during
+      Rust source analysis.
+    - Bug #3083 Return a descriptive error from DoContainerScan
+      when ScannerActions.Image is empty instead of panicking.
+    - Fixes via osv-scalibr:
+      - Fix false-positive Go standard library matches for packages
+        with module paths ending in /go (e.g.
+        pkg:golang/github.com/json-iterator/go) (#3017).
+      - Secure guided remediation file operations with os.Root to
+        prevent path traversal attacks (google/osv-scalibr#2363).
+      - Prevent OOM and disk exhaustion issues with tar bombs
+        during archive extraction.
+      - Strip platform suffix from RubyGems versions in CycloneDX
+        (google/osv-scalibr#2313).
+      - Ignore .deps.json files that don't have an object as their
+        root in dotnet/depsjson extractor
+        (google/osv-scalibr#2423).
+  * Misc:
+    - Update osv-scalibr to v0.5.3-0.20260911142458-3090dbb7aaa2
+      (#3079).
+    - Update Go to v1.27 and golangci-lint to v2.13 (#3046).
+      - This now supports call analysis on go v1.27 projects.
+    - Update google.golang.org/grpc to v1.83.2 (#3062).
+
+-------------------------------------------------------------------

Old:
----
  osv-scanner-2.5.1.obscpio

New:
----
  osv-scanner-2.6.0.obscpio

++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Other differences:
------------------
++++++ osv-scanner.spec ++++++
--- /var/tmp/diff_new_pack.g1OLnA/_old  2026-09-19 22:22:17.525481306 +0200
+++ /var/tmp/diff_new_pack.g1OLnA/_new  2026-09-19 22:22:17.527481389 +0200
@@ -17,14 +17,19 @@
 
 
 Name:           osv-scanner
-Version:        2.5.1
+Version:        2.6.0
 Release:        0
 Summary:        Vulnerability scanner written in Go
 License:        Apache-2.0
 URL:            https://github.com/google/osv-scanner
 Source:         osv-scanner-%{version}.tar.gz
 Source1:        vendor.tar.gz
-BuildRequires:  go1.26 >= 1.26.4
+BuildRequires:  go1.27 >= 1.27.0
+
+# Build Error
+# 
vendor/github.com/google/osv-scalibr/extractor/filesystem/embeddedfs/common/common_linux.go:27:9:
+# invalid operation: int64(stat.Bavail) * stat.Bsize (mismatched types int64 
and int32)
+ExcludeArch:    %{ix86} %{arm}
 
 %description
 Use OSV-Scanner to find existing vulnerabilities affecting your project's

++++++ _service ++++++
--- /var/tmp/diff_new_pack.g1OLnA/_old  2026-09-19 22:22:17.558482682 +0200
+++ /var/tmp/diff_new_pack.g1OLnA/_new  2026-09-19 22:22:17.560482765 +0200
@@ -3,7 +3,7 @@
     <param name="url">https://github.com/google/osv-scanner.git</param>
     <param name="scm">git</param>
     <param name="exclude">.git</param>
-    <param name="revision">refs/tags/v2.5.1</param>
+    <param name="revision">refs/tags/v2.6.0</param>
     <param name="match-tag">v*</param>
     <param name="versionformat">@PARENT_TAG@</param>
     <param name="versionrewrite-pattern">v(.*)</param>

++++++ _servicedata ++++++
--- /var/tmp/diff_new_pack.g1OLnA/_old  2026-09-19 22:22:17.582483683 +0200
+++ /var/tmp/diff_new_pack.g1OLnA/_new  2026-09-19 22:22:17.585483808 +0200
@@ -3,6 +3,6 @@
                 <param name="url">https://github.com/google/osv-scanner</param>
               <param 
name="changesrevision">b56b5191101d5f27d4787d5583d8d01e9518a7af</param></service><service
 name="tar_scm">
                 <param 
name="url">https://github.com/google/osv-scanner.git</param>
-              <param 
name="changesrevision">c84fa4568f2526d0333e9a914ea8a0a5f74ad68b</param></service></servicedata>
+              <param 
name="changesrevision">e840a6e8adb14b7777c78e26cfbf6e2abc1d1fc6</param></service></servicedata>
 (No newline at EOF)
 

++++++ osv-scanner-2.5.1.obscpio -> osv-scanner-2.6.0.obscpio ++++++
++++ 23748 lines of diff (skipped)

++++++ osv-scanner.obsinfo ++++++
--- /var/tmp/diff_new_pack.g1OLnA/_old  2026-09-19 22:22:18.360516132 +0200
+++ /var/tmp/diff_new_pack.g1OLnA/_new  2026-09-19 22:22:18.366516382 +0200
@@ -1,5 +1,5 @@
 name: osv-scanner
-version: 2.5.1
-mtime: 1786938266
-commit: c84fa4568f2526d0333e9a914ea8a0a5f74ad68b
+version: 2.6.0
+mtime: 1789350298
+commit: e840a6e8adb14b7777c78e26cfbf6e2abc1d1fc6
 

++++++ vendor.tar.gz ++++++
/work/SRC/openSUSE:Factory/osv-scanner/vendor.tar.gz 
/work/SRC/openSUSE:Factory/.osv-scanner.new.383539/vendor.tar.gz differ: char 
160, line 1

Reply via email to