Script 'mail_helper' called by obssrc Hello community, here is the log from the commit of package distribution for openSUSE:Factory checked in at 2026-09-24 22:57:15 ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Comparing /work/SRC/openSUSE:Factory/distribution (Old) and /work/SRC/openSUSE:Factory/.distribution.new.383539 (New) ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Package is "distribution" Thu Sep 24 22:57:15 2026 rev:19 rq:1380039 version:3.1.1 Changes: -------- --- /work/SRC/openSUSE:Factory/distribution/distribution.changes 2026-09-10 15:39:58.203434909 +0200 +++ /work/SRC/openSUSE:Factory/.distribution.new.383539/distribution.changes 2026-09-24 22:59:54.267362664 +0200 @@ -1,0 +2,9 @@ +Wed Sep 23 20:37:03 UTC 2026 - Dirk Müller <[email protected]> + +- update vendor.tar to address: + * bsc#1281468, CVE-2026-81871: OpenTelemetry-Go: TLS certificate + bypass allows log telemetry interception and alteration + * bsc#1281469, CVE-2026-81872: OpenTelemetry-Go: Denial of + Service via attacker-driven log emission + +------------------------------------------------------------------- ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Other differences: ------------------ ++++++ _service ++++++ --- /var/tmp/diff_new_pack.wcznBY/_old 2026-09-24 22:59:55.222402601 +0200 +++ /var/tmp/diff_new_pack.wcznBY/_new 2026-09-24 22:59:55.224402685 +0200 @@ -10,13 +10,23 @@ </service> <service name="go_modules" mode="manual"> <param name="compression">zst</param> - <param name="replace">golang.org/x/crypto=golang.org/x/[email protected]</param> + <param name="replace">golang.org/x/crypto=golang.org/x/[email protected]</param> <param name="replace">golang.org/x/net=golang.org/x/[email protected]</param> <param name="replace">golang.org/x/text=golang.org/x/[email protected]</param> - <param name="replace">go.opentelemetry.io/otel=go.opentelemetry.io/[email protected]</param> + <param name="replace">go.opentelemetry.io/otel=go.opentelemetry.io/[email protected]</param> <param name="replace">google.golang.org/grpc=google.golang.org/[email protected]</param> <param name="replace">cloud.google.com/go/auth=cloud.google.com/go/[email protected]</param> <param name="replace">github.com/grpc-ecosystem/grpc-gateway/v2=github.com/grpc-ecosystem/grpc-gateway/[email protected]</param> + <param name="replace">go.opentelemetry.io/otel/sdk/log=go.opentelemetry.io/otel/sdk/[email protected]</param> + <param name="replace">go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploghttp=go.opentelemetry.io/otel/exporters/otlp/otlplog/[email protected]</param> + <param name="replace">go.opentelemetry.io/otel/log=go.opentelemetry.io/otel/[email protected]</param> + <param name="replace">go.opentelemetry.io/otel/exporters/stdout/stdoutlog=go.opentelemetry.io/otel/exporters/stdout/[email protected]</param> + <param name="replace">go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploghttp=go.opentelemetry.io/otel/exporters/otlp/otlplog/[email protected]</param> + <param name="replace">go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploggrpc=go.opentelemetry.io/otel/exporters/otlp/otlplog/[email protected]</param> + <param name="replace">go.opentelemetry.io/otel/exporters/stdout/stdoutlog=go.opentelemetry.io/otel/exporters/stdout/[email protected]</param> + <param name="replace">go.opentelemetry.io/otel/exporters/otlp/otlptrace=go.opentelemetry.io/otel/exporters/otlp/[email protected]</param> + <param name="replace">go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc=go.opentelemetry.io/otel/exporters/otlp/otlptrace/[email protected]</param> + <param name="replace">go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp=go.opentelemetry.io/otel/exporters/otlp/otlptrace/[email protected]</param> </service> <service name="recompress" mode="manual"> <param name="file">distribution-*.tar</param> ++++++ vendor.tar.zst ++++++ ++++ 68238 lines of diff (skipped)
