Script 'mail_helper' called by obssrc
Hello community,

here is the log from the commit of package cosign for openSUSE:Factory checked 
in at 2026-09-24 23:04:16
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Comparing /work/SRC/openSUSE:Factory/cosign (Old)
 and      /work/SRC/openSUSE:Factory/.cosign.new.383539 (New)
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Package is "cosign"

Thu Sep 24 23:04:16 2026 rev:38 rq:1380205 version:3.1.3

Changes:
--------
--- /work/SRC/openSUSE:Factory/cosign/cosign.changes    2026-07-18 
22:25:27.243019667 +0200
+++ /work/SRC/openSUSE:Factory/.cosign.new.383539/cosign.changes        
2026-09-24 23:04:20.659529900 +0200
@@ -1,0 +2,23 @@
+Thu Sep 24 08:04:55 UTC 2026 - Dirk Müller <[email protected]>
+
+- update to 3.1.3 (bsc#1282542, GHSA-fx35-mq7g-6g98):
+  * This release resolves GHSA-fx35-mq7g-6g98, a verification
+    bypass using an unexpected public key in a legacy bundle.
+  * Auto-detect default digest algorithm for public keys
+  * fix(pkcs11key): return an error instead of panicking when no
+    key pair matches
+  * Supporting OCI Signing with X.509 Certificate Chain
+  * test(inspect): replace mock TSA client usage with local
+    timestamp response generator in
+  * fix: prevent shell completions for various options not taking
+    filenames
+  * fix(blob): compare file checksums case-insensitively in
+  * Verification bypass via public key in legacy bundle (GHSA-
+    fx35-mq7g-6g98)
+- update vendor with:
+  * bsc#1278614, CVE-2026-56855,CVE-2026-56854,CVE-2026-78662
+  * bsc#1275025, CVE-2026-56864
+  * bsc#1272117, CVE-2026-56852
+  * bsc#1279215, CVE-2026-84304
+
+-------------------------------------------------------------------

Old:
----
  cosign-3.1.2.tar.gz

New:
----
  cosign-3.1.3.tar.gz

++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Other differences:
------------------
++++++ cosign.spec ++++++
--- /var/tmp/diff_new_pack.frUf9V/_old  2026-09-24 23:04:23.765659867 +0200
+++ /var/tmp/diff_new_pack.frUf9V/_new  2026-09-24 23:04:23.767659950 +0200
@@ -17,7 +17,7 @@
 
 
 Name:           cosign
-Version:        3.1.2
+Version:        3.1.3
 Release:        0
 Summary:        Container Signing, Verification and Storage in an OCI registry
 License:        Apache-2.0

++++++ _service ++++++
--- /var/tmp/diff_new_pack.frUf9V/_old  2026-09-24 23:04:23.804661498 +0200
+++ /var/tmp/diff_new_pack.frUf9V/_new  2026-09-24 23:04:23.807661624 +0200
@@ -2,6 +2,10 @@
   <service name="download_files" mode="manual"/>
   <service name="go_modules" mode="manual">
     <param name="compression">zst</param>
+    <param 
name="replace">golang.org/x/crypto=golang.org/x/[email protected]</param>
+    <param name="replace">golang.org/x/mod=golang.org/x/[email protected]</param>
+    <param name="replace">golang.org/x/text=golang.org/x/[email protected]</param>
+    <param 
name="replace">google.golang.org/grpc=google.golang.org/[email protected]</param>
   </service>
 </services>
 

++++++ cosign-3.1.2.tar.gz -> cosign-3.1.3.tar.gz ++++++
++++ 2350 lines of diff (skipped)

++++++ vendor.tar.zst ++++++
/work/SRC/openSUSE:Factory/cosign/vendor.tar.zst 
/work/SRC/openSUSE:Factory/.cosign.new.383539/vendor.tar.zst differ: char 5, 
line 1

Reply via email to