Script 'mail_helper' called by obssrc Hello community, here is the log from the commit of package cosign for openSUSE:Factory checked in at 2026-09-24 23:04:16 ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Comparing /work/SRC/openSUSE:Factory/cosign (Old) and /work/SRC/openSUSE:Factory/.cosign.new.383539 (New) ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Package is "cosign" Thu Sep 24 23:04:16 2026 rev:38 rq:1380205 version:3.1.3 Changes: -------- --- /work/SRC/openSUSE:Factory/cosign/cosign.changes 2026-07-18 22:25:27.243019667 +0200 +++ /work/SRC/openSUSE:Factory/.cosign.new.383539/cosign.changes 2026-09-24 23:04:20.659529900 +0200 @@ -1,0 +2,23 @@ +Thu Sep 24 08:04:55 UTC 2026 - Dirk Müller <[email protected]> + +- update to 3.1.3 (bsc#1282542, GHSA-fx35-mq7g-6g98): + * This release resolves GHSA-fx35-mq7g-6g98, a verification + bypass using an unexpected public key in a legacy bundle. + * Auto-detect default digest algorithm for public keys + * fix(pkcs11key): return an error instead of panicking when no + key pair matches + * Supporting OCI Signing with X.509 Certificate Chain + * test(inspect): replace mock TSA client usage with local + timestamp response generator in + * fix: prevent shell completions for various options not taking + filenames + * fix(blob): compare file checksums case-insensitively in + * Verification bypass via public key in legacy bundle (GHSA- + fx35-mq7g-6g98) +- update vendor with: + * bsc#1278614, CVE-2026-56855,CVE-2026-56854,CVE-2026-78662 + * bsc#1275025, CVE-2026-56864 + * bsc#1272117, CVE-2026-56852 + * bsc#1279215, CVE-2026-84304 + +------------------------------------------------------------------- Old: ---- cosign-3.1.2.tar.gz New: ---- cosign-3.1.3.tar.gz ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Other differences: ------------------ ++++++ cosign.spec ++++++ --- /var/tmp/diff_new_pack.frUf9V/_old 2026-09-24 23:04:23.765659867 +0200 +++ /var/tmp/diff_new_pack.frUf9V/_new 2026-09-24 23:04:23.767659950 +0200 @@ -17,7 +17,7 @@ Name: cosign -Version: 3.1.2 +Version: 3.1.3 Release: 0 Summary: Container Signing, Verification and Storage in an OCI registry License: Apache-2.0 ++++++ _service ++++++ --- /var/tmp/diff_new_pack.frUf9V/_old 2026-09-24 23:04:23.804661498 +0200 +++ /var/tmp/diff_new_pack.frUf9V/_new 2026-09-24 23:04:23.807661624 +0200 @@ -2,6 +2,10 @@ <service name="download_files" mode="manual"/> <service name="go_modules" mode="manual"> <param name="compression">zst</param> + <param name="replace">golang.org/x/crypto=golang.org/x/[email protected]</param> + <param name="replace">golang.org/x/mod=golang.org/x/[email protected]</param> + <param name="replace">golang.org/x/text=golang.org/x/[email protected]</param> + <param name="replace">google.golang.org/grpc=google.golang.org/[email protected]</param> </service> </services> ++++++ cosign-3.1.2.tar.gz -> cosign-3.1.3.tar.gz ++++++ ++++ 2350 lines of diff (skipped) ++++++ vendor.tar.zst ++++++ /work/SRC/openSUSE:Factory/cosign/vendor.tar.zst /work/SRC/openSUSE:Factory/.cosign.new.383539/vendor.tar.zst differ: char 5, line 1
