Script 'mail_helper' called by obssrc Hello community, here is the log from the commit of package osv-scanner for openSUSE:Factory checked in at 2026-09-19 22:21:06 ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Comparing /work/SRC/openSUSE:Factory/osv-scanner (Old) and /work/SRC/openSUSE:Factory/.osv-scanner.new.383539 (New) ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Package is "osv-scanner" Sat Sep 19 22:21:06 2026 rev:49 rq:1378925 version:2.6.0 Changes: -------- --- /work/SRC/openSUSE:Factory/osv-scanner/osv-scanner.changes 2026-08-28 19:54:28.940866837 +0200 +++ /work/SRC/openSUSE:Factory/.osv-scanner.new.383539/osv-scanner.changes 2026-09-19 22:22:15.464395346 +0200 @@ -1,0 +2,68 @@ +Fri Sep 18 05:40:47 UTC 2026 - Johannes Kastl <[email protected]> + +- Update to version 2.6.0: + * Features: + - Feature #2888 Publish multi-arch (linux/arm64) image for + osv-scanner-action. + - Feature #3066 Configure retry policy with exponential backoff + for transient gRPC errors in scalibr plugins. + - Dependency scanning & lockfile improvements via osv-scalibr: + - Extract Git repository URLs and support local OSV tag + matching for Git-based dependencies in JavaScript lockfiles + (package-lock.json, yarn.lock, pnpm-lock.yaml, bun.lock). + - Assign pkg:git PURL type to Git commit-pinned dependencies + across JS and Cargo lockfiles to avoid false positives + against registry packages (#2863). + - Retain packages without a version or PURL in SPDX output + (google/osv-scalibr#2375) and merge related packages based + on lineage relationships. + - New extractors and plugin support via osv-scalibr: + - Many additional filetypes are supported. These are not + enabled by default yet, so if you need a particular new + filetype, use --experimental-plugins flag. See "Supported + Inventory Types" for the extractor name. + * Fixes: + - Bug #3075 Ensure results property in JSON output is an empty + array [] instead of null when scanning with + --allow-no-lockfiles and no lockfiles are found. + - Bug #3071 Preserve valid UTF-8 sequences when truncating + multibyte text in vertical output. + - Bug #2919 Add filter to show packages with license violations + but no vulnerabilities in the HTML report. + - Bug #3049 Keep filter dropdown checklist open when clicking + options in the HTML report. + - Bug #3023 Guard against panic on empty or whitespace-only + license expressions in SPDX license evaluation. + - Bug #3032 Bound recursion depth when parsing SPDX license + expressions to prevent stack overflow on deeply nested + expressions. + - Bug #3061 Remove purl caching in scan filtering to avoid + dropping SBOM packages without purls. + - Bug #3063 Log plugin and enricher errors during container + scans instead of failing silently. + - Bug #2977 Return an error instead of aborting the process + (log.Fatalf) when an rlib archive has no object file during + Rust source analysis. + - Bug #3083 Return a descriptive error from DoContainerScan + when ScannerActions.Image is empty instead of panicking. + - Fixes via osv-scalibr: + - Fix false-positive Go standard library matches for packages + with module paths ending in /go (e.g. + pkg:golang/github.com/json-iterator/go) (#3017). + - Secure guided remediation file operations with os.Root to + prevent path traversal attacks (google/osv-scalibr#2363). + - Prevent OOM and disk exhaustion issues with tar bombs + during archive extraction. + - Strip platform suffix from RubyGems versions in CycloneDX + (google/osv-scalibr#2313). + - Ignore .deps.json files that don't have an object as their + root in dotnet/depsjson extractor + (google/osv-scalibr#2423). + * Misc: + - Update osv-scalibr to v0.5.3-0.20260911142458-3090dbb7aaa2 + (#3079). + - Update Go to v1.27 and golangci-lint to v2.13 (#3046). + - This now supports call analysis on go v1.27 projects. + - Update google.golang.org/grpc to v1.83.2 (#3062). + +------------------------------------------------------------------- Old: ---- osv-scanner-2.5.1.obscpio New: ---- osv-scanner-2.6.0.obscpio ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Other differences: ------------------ ++++++ osv-scanner.spec ++++++ --- /var/tmp/diff_new_pack.g1OLnA/_old 2026-09-19 22:22:17.525481306 +0200 +++ /var/tmp/diff_new_pack.g1OLnA/_new 2026-09-19 22:22:17.527481389 +0200 @@ -17,14 +17,19 @@ Name: osv-scanner -Version: 2.5.1 +Version: 2.6.0 Release: 0 Summary: Vulnerability scanner written in Go License: Apache-2.0 URL: https://github.com/google/osv-scanner Source: osv-scanner-%{version}.tar.gz Source1: vendor.tar.gz -BuildRequires: go1.26 >= 1.26.4 +BuildRequires: go1.27 >= 1.27.0 + +# Build Error +# vendor/github.com/google/osv-scalibr/extractor/filesystem/embeddedfs/common/common_linux.go:27:9: +# invalid operation: int64(stat.Bavail) * stat.Bsize (mismatched types int64 and int32) +ExcludeArch: %{ix86} %{arm} %description Use OSV-Scanner to find existing vulnerabilities affecting your project's ++++++ _service ++++++ --- /var/tmp/diff_new_pack.g1OLnA/_old 2026-09-19 22:22:17.558482682 +0200 +++ /var/tmp/diff_new_pack.g1OLnA/_new 2026-09-19 22:22:17.560482765 +0200 @@ -3,7 +3,7 @@ <param name="url">https://github.com/google/osv-scanner.git</param> <param name="scm">git</param> <param name="exclude">.git</param> - <param name="revision">refs/tags/v2.5.1</param> + <param name="revision">refs/tags/v2.6.0</param> <param name="match-tag">v*</param> <param name="versionformat">@PARENT_TAG@</param> <param name="versionrewrite-pattern">v(.*)</param> ++++++ _servicedata ++++++ --- /var/tmp/diff_new_pack.g1OLnA/_old 2026-09-19 22:22:17.582483683 +0200 +++ /var/tmp/diff_new_pack.g1OLnA/_new 2026-09-19 22:22:17.585483808 +0200 @@ -3,6 +3,6 @@ <param name="url">https://github.com/google/osv-scanner</param> <param name="changesrevision">b56b5191101d5f27d4787d5583d8d01e9518a7af</param></service><service name="tar_scm"> <param name="url">https://github.com/google/osv-scanner.git</param> - <param name="changesrevision">c84fa4568f2526d0333e9a914ea8a0a5f74ad68b</param></service></servicedata> + <param name="changesrevision">e840a6e8adb14b7777c78e26cfbf6e2abc1d1fc6</param></service></servicedata> (No newline at EOF) ++++++ osv-scanner-2.5.1.obscpio -> osv-scanner-2.6.0.obscpio ++++++ ++++ 23748 lines of diff (skipped) ++++++ osv-scanner.obsinfo ++++++ --- /var/tmp/diff_new_pack.g1OLnA/_old 2026-09-19 22:22:18.360516132 +0200 +++ /var/tmp/diff_new_pack.g1OLnA/_new 2026-09-19 22:22:18.366516382 +0200 @@ -1,5 +1,5 @@ name: osv-scanner -version: 2.5.1 -mtime: 1786938266 -commit: c84fa4568f2526d0333e9a914ea8a0a5f74ad68b +version: 2.6.0 +mtime: 1789350298 +commit: e840a6e8adb14b7777c78e26cfbf6e2abc1d1fc6 ++++++ vendor.tar.gz ++++++ /work/SRC/openSUSE:Factory/osv-scanner/vendor.tar.gz /work/SRC/openSUSE:Factory/.osv-scanner.new.383539/vendor.tar.gz differ: char 160, line 1
