Script 'mail_helper' called by obssrc Hello community, here is the log from the commit of package skillspector for openSUSE:Factory checked in at 2026-09-28 10:44:16 ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Comparing /work/SRC/openSUSE:Factory/skillspector (Old) and /work/SRC/openSUSE:Factory/.skillspector.new.383539 (New) ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Package is "skillspector" Mon Sep 28 10:44:16 2026 rev:9 rq:1380721 version:2.12.0 Changes: -------- --- /work/SRC/openSUSE:Factory/skillspector/skillspector.changes 2026-09-10 15:37:35.846474732 +0200 +++ /work/SRC/openSUSE:Factory/.skillspector.new.383539/skillspector.changes 2026-09-28 10:44:23.447769570 +0200 @@ -1,0 +2,25 @@ +Fri Sep 25 19:24:48 UTC 2026 - Martin Pluskal <[email protected]> + +- Add skillspector-fifo-timeout.patch: raise the fifo-swap + regression test child timeout 5s -> 30s. The cold import of + the langchain cone in a fresh interpreter alone takes ~8s + on aarch64 builders, so the test killed its own child + during import (returncode -9); the FIFO guard itself is + correct. Upstream-test-only change. + +------------------------------------------------------------------- +Fri Sep 25 18:23:07 UTC 2026 - Martin Pluskal <[email protected]> + +- Update to version 2.12.0: + * Opt-in CLI gate for any active finding, + configurable static-analysis allowance + * OpenCode integrations, Gemini 3.5 Flash registry + guidance, interactive scan progress + * TP4 analysis of executable Markdown fences + * Stronger local input and report handling, wider + detection of reflective Python access and shipped + bytecode, retries for transient provider failures + * Missing references distinguished from ambiguous + MCP installation blockers + +------------------------------------------------------------------- Old: ---- skillspector-2.11.2.tar.gz New: ---- skillspector-2.12.0.tar.gz skillspector-fifo-timeout.patch ----------(New B)---------- New: - Add skillspector-fifo-timeout.patch: raise the fifo-swap regression test child timeout 5s -> 30s. The cold import of ----------(New E)---------- ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Other differences: ------------------ ++++++ skillspector.spec ++++++ --- /var/tmp/diff_new_pack.Hxxv3R/_old 2026-09-28 10:44:24.964833129 +0200 +++ /var/tmp/diff_new_pack.Hxxv3R/_new 2026-09-28 10:44:24.965833171 +0200 @@ -21,13 +21,17 @@ # %%{primary_python} so it stays correct as the primary interpreter moves. %define pythons %{primary_python} Name: skillspector -Version: 2.11.2 +Version: 2.12.0 Release: 0 Summary: Security scanner for AI agent skills License: Apache-2.0 URL: https://github.com/NVIDIA/skillspector # Official GitHub release sdist (not on PyPI; not a git auto-archive). Source: https://github.com/NVIDIA/skillspector/releases/download/v%{version}/%{name}-%{version}.tar.gz +# Upstream test spawns a fresh interpreter whose cold import of the +# langchain cone exceeds the hardcoded 5s child timeout on constrained +# builders; 30s still bounds a regressed blocking open. (upstream-test-only) +Patch0: skillspector-fifo-timeout.patch # Test suite - exercises the full langchain/langgraph runtime cone BuildRequires: %{python_module PyYAML >= 6.0.1} BuildRequires: %{python_module anthropic} ++++++ skillspector-2.11.2.tar.gz -> skillspector-2.12.0.tar.gz ++++++ ++++ 53591 lines of diff (skipped) ++++++ skillspector-fifo-timeout.patch ++++++ --- a/tests/unit/test_mcp_registry.py +++ b/tests/unit/test_mcp_registry.py @@ -494,7 +494,10 @@ ], capture_output=True, text=True, - timeout=5, + # Cold import of the langchain cone in a fresh interpreter takes + # >5s on constrained builders (e.g. aarch64 chroots); the timeout + # only bounds a regressed blocking open, not the import itself. + timeout=30, check=False, ) assert result.returncode == 0, result.stdout + result.stderr
