Script 'mail_helper' called by obssrc Hello community, here is the log from the commit of package gitoxide for openSUSE:Factory checked in at 2026-09-28 10:43:32 ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Comparing /work/SRC/openSUSE:Factory/gitoxide (Old) and /work/SRC/openSUSE:Factory/.gitoxide.new.383539 (New) ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Package is "gitoxide" Mon Sep 28 10:43:32 2026 rev:13 rq:1380697 version:0.59.0 Changes: -------- --- /work/SRC/openSUSE:Factory/gitoxide/gitoxide.changes 2026-09-23 16:40:10.551807078 +0200 +++ /work/SRC/openSUSE:Factory/.gitoxide.new.383539/gitoxide.changes 2026-09-28 10:43:48.919322963 +0200 @@ -1,0 +2,14 @@ +Fri Sep 25 14:20:59 UTC 2026 - Martin Pluskal <[email protected]> + +- Update to version 0.59.0: + * Ships gix-transport 0.60.0, which rejects NUL/LF in + git-daemon connect requests: drops the backported fix + for CVE-2026-91986 (boo#1281749), now fixed upstream + * gix-transport-reject-control-bytes.patch + * New gix editor command with Git-compatible selection + * Raise the Rust floor to 1.88 (upstream MSRV, dua-core) +- Refresh the vendored dependencies. The linked graph + still carries MPL-2.0 only (uluru, option-ext); the + License tag is unchanged. + +------------------------------------------------------------------- Old: ---- gitoxide-0.58.0.tar.gz gix-transport-reject-control-bytes.patch New: ---- gitoxide-0.59.0.tar.gz ----------(Old B)---------- Old: for CVE-2026-91986 (boo#1281749), now fixed upstream * gix-transport-reject-control-bytes.patch * New gix editor command with Git-compatible selection ----------(Old E)---------- ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Other differences: ------------------ ++++++ gitoxide.spec ++++++ --- /var/tmp/diff_new_pack.wfTTXN/_old 2026-09-28 10:43:51.524432105 +0200 +++ /var/tmp/diff_new_pack.wfTTXN/_new 2026-09-28 10:43:51.525432147 +0200 @@ -17,13 +17,13 @@ Name: gitoxide -Version: 0.58.0 +Version: 0.59.0 Release: 0 Summary: An idiomatic & safe pure-Rust implementation of Git # Legal-Review-Notice: gitoxide itself is "Apache-2.0 OR MIT", but the # binaries statically link the vendored Rust dependencies. Derived on this # re-vendor with "cargo tree --offline -p gitoxide -e normal" over the -# vendored tree (538 crates, 304 in the linked graph): the only copyleft +# vendored tree (531 crates, 298 in the linked graph): the only copyleft # licence in the graph is MPL-2.0, from two crates - uluru, an LRU cache # pulled in via gix-pack (itself reached through gitoxide-core, gix and # gix-odb), and option-ext, reached through directories and dirs-sys, @@ -38,13 +38,11 @@ URL: https://github.com/GitoxideLabs/gitoxide Source0: https://github.com/GitoxideLabs/gitoxide/archive/refs/tags/v%{version}.tar.gz#/%{name}-%{version}.tar.gz Source1: vendor.tar.zst -# PATCH-FIX-UPSTREAM gix-transport-reject-control-bytes.patch GHSA-rc7h-wp5f-w3g5 (upstream commit 3e7f1857) -- reject NUL/LF in git-daemon connect request (CVE-2026-91986, boo#1281749) -Patch0: gix-transport-reject-control-bytes.patch BuildRequires: cargo-packaging BuildRequires: cmake BuildRequires: pkgconfig -# Upstream Cargo.toml: rust-version = "1.85" (edition 2024) -BuildRequires: rust >= 1.85 +# Upstream Cargo.toml: rust-version = "1.88" (edition 2024) +BuildRequires: rust >= 1.88 BuildRequires: pkgconfig(openssl) ExclusiveArch: %{rust_arches} ++++++ gitoxide-0.58.0.tar.gz -> gitoxide-0.59.0.tar.gz ++++++ /work/SRC/openSUSE:Factory/gitoxide/gitoxide-0.58.0.tar.gz /work/SRC/openSUSE:Factory/.gitoxide.new.383539/gitoxide-0.59.0.tar.gz differ: char 12, line 1 ++++++ vendor.tar.zst ++++++ /work/SRC/openSUSE:Factory/gitoxide/vendor.tar.zst /work/SRC/openSUSE:Factory/.gitoxide.new.383539/vendor.tar.zst differ: char 7, line 1
