Script 'mail_helper' called by obssrc
Hello community,

here is the log from the commit of package gitoxide for openSUSE:Factory 
checked in at 2026-09-28 10:43:32
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Comparing /work/SRC/openSUSE:Factory/gitoxide (Old)
 and      /work/SRC/openSUSE:Factory/.gitoxide.new.383539 (New)
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Package is "gitoxide"

Mon Sep 28 10:43:32 2026 rev:13 rq:1380697 version:0.59.0

Changes:
--------
--- /work/SRC/openSUSE:Factory/gitoxide/gitoxide.changes        2026-09-23 
16:40:10.551807078 +0200
+++ /work/SRC/openSUSE:Factory/.gitoxide.new.383539/gitoxide.changes    
2026-09-28 10:43:48.919322963 +0200
@@ -1,0 +2,14 @@
+Fri Sep 25 14:20:59 UTC 2026 - Martin Pluskal <[email protected]>
+
+- Update to version 0.59.0:
+  * Ships gix-transport 0.60.0, which rejects NUL/LF in
+    git-daemon connect requests: drops the backported fix
+    for CVE-2026-91986 (boo#1281749), now fixed upstream
+    * gix-transport-reject-control-bytes.patch
+  * New gix editor command with Git-compatible selection
+  * Raise the Rust floor to 1.88 (upstream MSRV, dua-core)
+- Refresh the vendored dependencies. The linked graph
+  still carries MPL-2.0 only (uluru, option-ext); the
+  License tag is unchanged.
+
+-------------------------------------------------------------------

Old:
----
  gitoxide-0.58.0.tar.gz
  gix-transport-reject-control-bytes.patch

New:
----
  gitoxide-0.59.0.tar.gz

----------(Old B)----------
  Old:    for CVE-2026-91986 (boo#1281749), now fixed upstream
    * gix-transport-reject-control-bytes.patch
  * New gix editor command with Git-compatible selection
----------(Old E)----------

++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Other differences:
------------------
++++++ gitoxide.spec ++++++
--- /var/tmp/diff_new_pack.wfTTXN/_old  2026-09-28 10:43:51.524432105 +0200
+++ /var/tmp/diff_new_pack.wfTTXN/_new  2026-09-28 10:43:51.525432147 +0200
@@ -17,13 +17,13 @@
 
 
 Name:           gitoxide
-Version:        0.58.0
+Version:        0.59.0
 Release:        0
 Summary:        An idiomatic & safe pure-Rust implementation of Git
 # Legal-Review-Notice: gitoxide itself is "Apache-2.0 OR MIT", but the
 # binaries statically link the vendored Rust dependencies. Derived on this
 # re-vendor with "cargo tree --offline -p gitoxide -e normal" over the
-# vendored tree (538 crates, 304 in the linked graph): the only copyleft
+# vendored tree (531 crates, 298 in the linked graph): the only copyleft
 # licence in the graph is MPL-2.0, from two crates - uluru, an LRU cache
 # pulled in via gix-pack (itself reached through gitoxide-core, gix and
 # gix-odb), and option-ext, reached through directories and dirs-sys,
@@ -38,13 +38,11 @@
 URL:            https://github.com/GitoxideLabs/gitoxide
 Source0:        
https://github.com/GitoxideLabs/gitoxide/archive/refs/tags/v%{version}.tar.gz#/%{name}-%{version}.tar.gz
 Source1:        vendor.tar.zst
-# PATCH-FIX-UPSTREAM gix-transport-reject-control-bytes.patch 
GHSA-rc7h-wp5f-w3g5 (upstream commit 3e7f1857) -- reject NUL/LF in git-daemon 
connect request (CVE-2026-91986, boo#1281749)
-Patch0:         gix-transport-reject-control-bytes.patch
 BuildRequires:  cargo-packaging
 BuildRequires:  cmake
 BuildRequires:  pkgconfig
-# Upstream Cargo.toml: rust-version = "1.85" (edition 2024)
-BuildRequires:  rust >= 1.85
+# Upstream Cargo.toml: rust-version = "1.88" (edition 2024)
+BuildRequires:  rust >= 1.88
 BuildRequires:  pkgconfig(openssl)
 ExclusiveArch:  %{rust_arches}
 

++++++ gitoxide-0.58.0.tar.gz -> gitoxide-0.59.0.tar.gz ++++++
/work/SRC/openSUSE:Factory/gitoxide/gitoxide-0.58.0.tar.gz 
/work/SRC/openSUSE:Factory/.gitoxide.new.383539/gitoxide-0.59.0.tar.gz differ: 
char 12, line 1

++++++ vendor.tar.zst ++++++
/work/SRC/openSUSE:Factory/gitoxide/vendor.tar.zst 
/work/SRC/openSUSE:Factory/.gitoxide.new.383539/vendor.tar.zst differ: char 7, 
line 1

Reply via email to