Script 'mail_helper' called by obssrc
Hello community,
here is the log from the commit of package jackson-dataformats-binary for
openSUSE:Factory checked in at 2026-09-24 22:56:28
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Comparing /work/SRC/openSUSE:Factory/jackson-dataformats-binary (Old)
and /work/SRC/openSUSE:Factory/.jackson-dataformats-binary.new.383539
(New)
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Package is "jackson-dataformats-binary"
Thu Sep 24 22:56:28 2026 rev:13 rq:1380225 version:2.18.11
Changes:
--------
---
/work/SRC/openSUSE:Factory/jackson-dataformats-binary/jackson-dataformats-binary.changes
2026-07-15 17:12:23.221144358 +0200
+++
/work/SRC/openSUSE:Factory/.jackson-dataformats-binary.new.383539/jackson-dataformats-binary.changes
2026-09-24 22:58:41.941338229 +0200
@@ -1,0 +2,34 @@
+Wed Sep 23 07:50:37 UTC 2026 - Fridrich Strba <[email protected]>
+
+- Update to 2.18.11
+ * #783: (protobuf) Support StreamReadConstraints.maxDocumentLength
+ in ProtobufParser
+ * #785: (avro) Support StreamReadConstraints.maxDocumentLength and
+ maxTokenCount in Avro parser
+ * #803: (ion) Support StreamReadConstraints.maxNestingDepth in Ion
+ parser (partial fix for #358)
+ * #805: (ion) Support StreamReadConstraints.maxDocumentLength in
+ Ion parser (partial fix for #358)
+
+-------------------------------------------------------------------
+Thu Sep 17 08:19:48 UTC 2026 - Fridrich Strba <[email protected]>
+
+- Update to 2.18.10
+ * #725: (cbor) Ensure maxNameLength limit enforced for CBOR parser
+ (bsc#1282639, CVE-2026-68495)
+ * #726: (smile) Ensure maxNameLength limit enforced for Smile
+ parser (bsc#1282640, CVE-2026-68496)
+ * #727: (cbor) CBORParser.nextFieldName(SerializableString)
+ confuses 5-bit length marker 23 with 24 ("1-byte length suffix
+ follows")
+ * #728: (cbor) CBORParser.nextFieldName(SerializableString)
+ consumes Object entry slot twice on fast-path miss, truncating
+ definite-length Objects
+ * #733: (cbor) Long `String`s not added to "stringref" reference
+ table, breaking following references
+ * #735: (cbor) "stringref" property-name paths pass 5-bit length
+ marker instead of actual length to shouldReferenceString()
+ * #736: (cbor) Long Object property names added to "stringref"
+ reference table twice
+
+-------------------------------------------------------------------
Old:
----
jackson-dataformats-binary-2.18.9.tar.gz
New:
----
jackson-dataformats-binary-2.18.11.tar.gz
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Other differences:
------------------
++++++ jackson-dataformats-binary.spec ++++++
--- /var/tmp/diff_new_pack.x4v0Wn/_old 2026-09-24 22:58:42.577364825 +0200
+++ /var/tmp/diff_new_pack.x4v0Wn/_new 2026-09-24 22:58:42.579364909 +0200
@@ -19,7 +19,7 @@
%bcond_with extra_dataformats
# Extra formats are disabled because of circular dependencies
Name: jackson-dataformats-binary
-Version: 2.18.9
+Version: 2.18.11
Release: 0
Summary: Jackson standard binary data format backends
License: Apache-2.0 AND BSD-3-Clause
++++++ _scmsync.obsinfo ++++++
--- /var/tmp/diff_new_pack.x4v0Wn/_old 2026-09-24 22:58:42.611366247 +0200
+++ /var/tmp/diff_new_pack.x4v0Wn/_new 2026-09-24 22:58:42.614366373 +0200
@@ -1,6 +1,6 @@
-mtime: 1784115165
-commit: 354542f0cb121b9146f20e1ccc6dfbc0d7cd35a23b37e776e8cb2c5b4c4c5a00
+mtime: 1790265721
+commit: 4f5cb227ea6de366264a34b97a56150ee52e8897ef109bebad32861d3a4d7abc
url: https://src.opensuse.org/java-packages/jackson-dataformats-binary
-revision: 354542f0cb121b9146f20e1ccc6dfbc0d7cd35a23b37e776e8cb2c5b4c4c5a00
+revision: 4f5cb227ea6de366264a34b97a56150ee52e8897ef109bebad32861d3a4d7abc
projectscmsync: https://src.opensuse.org/java-packages/_ObsPrj
++++++ build.specials.obscpio ++++++
++++++ build.specials.obscpio ++++++
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn'
'--exclude=.svnignore' old/.gitignore new/.gitignore
--- old/.gitignore 1970-01-01 01:00:00.000000000 +0100
+++ new/.gitignore 2026-09-24 18:02:01.000000000 +0200
@@ -0,0 +1 @@
+.osc
++++++ jackson-dataformats-binary-2.18.9.tar.gz ->
jackson-dataformats-binary-2.18.11.tar.gz ++++++
++++ 7516 lines of diff (skipped)