Script 'mail_helper' called by obssrc
Hello community,
here is the log from the commit of package python-Werkzeug for openSUSE:Factory
checked in at 2026-10-01 16:59:52
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Comparing /work/SRC/openSUSE:Factory/python-Werkzeug (Old)
and /work/SRC/openSUSE:Factory/.python-Werkzeug.new.1253 (New)
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Package is "python-Werkzeug"
Thu Oct 1 16:59:52 2026 rev:55 rq:1381644 version:3.1.9
Changes:
--------
--- /work/SRC/openSUSE:Factory/python-Werkzeug/python-Werkzeug.changes
2026-04-16 17:25:46.624486106 +0200
+++
/work/SRC/openSUSE:Factory/.python-Werkzeug.new.1253/python-Werkzeug.changes
2026-10-01 17:00:05.051782482 +0200
@@ -1,0 +2,23 @@
+Wed Sep 30 09:49:49 UTC 2026 - Markéta Machová <[email protected]>
+
+- Update to 3.1.9 (CVE-2026-102598, bsc#1283316):
+ * safe_join on Windows does not allow special devices names with
+ empty ADS markers on NTFS.
+ * ProfilerMiddleware uses profiling.tracing on Python 3.15.
+ * uri_to_iri and iri_to_uri preserve empty username, password,
+ and port 0.
+ * Improve performance of parsing methods.
+ * get_host also checks that the port is in the valid range.
+ * The int URL converter returns a 404 instead of 500 error when
+ the value is longer than sys.get_int_max_str_digits().
+ * Improve debugger PIN generation from cgroup data inside Podman.
+ * Authorization parsing basic auth disallows non-base64 characters.
+ * application/x-www-form-urlencoded form data is no longer limited
+ to max_form_memory_size, only max_content_length.
+ * LimitedStream.readinto does not resize the buffer when it reads
+ less than the remaining size.
+ * Rules with 10 or more converters in a single part assign
+ matched values correctly.
+ * The invalid Range suffix length -0 is no longer accepted.
+
+-------------------------------------------------------------------
Old:
----
werkzeug-3.1.8.tar.gz
New:
----
werkzeug-3.1.9.tar.gz
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Other differences:
------------------
++++++ python-Werkzeug.spec ++++++
--- /var/tmp/diff_new_pack.rEzFed/_old 2026-10-01 17:00:05.829815072 +0200
+++ /var/tmp/diff_new_pack.rEzFed/_new 2026-10-01 17:00:05.831815156 +0200
@@ -27,7 +27,7 @@
%{?sle15_python_module_pythons}
Name: python-Werkzeug%{psuffix}
-Version: 3.1.8
+Version: 3.1.9
Release: 0
Summary: The Swiss Army knife of Python web development
License: BSD-3-Clause
@@ -47,13 +47,12 @@
BuildRequires: %{python_module pytest-xprocess}
BuildRequires: %{python_module requests}
BuildRequires: %{python_module sortedcontainers}
-BuildRequires: %{python_module watchdog >= 3.0.0}
+BuildRequires: %{python_module watchdog >= 6}
%endif
BuildRequires: fdupes
BuildRequires: python-rpm-macros
-Requires: python-MarkupSafe >= 2.1.2
-Recommends: python-termcolor
-Recommends: python-watchdog >= 3.0.0
+Requires: python-MarkupSafe >= 3.0.3
+Recommends: python-watchdog >= 6
Obsoletes: python-Werkzeug-doc < %{version}
Provides: python-Werkzeug-doc = %{version}
BuildArch: noarch
++++++ werkzeug-3.1.8.tar.gz -> werkzeug-3.1.9.tar.gz ++++++
++++ 5092 lines of diff (skipped)