Script 'mail_helper' called by obssrc
Hello community,

here is the log from the commit of package syft for openSUSE:Factory checked in 
at 2026-10-02 23:04:10
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Comparing /work/SRC/openSUSE:Factory/syft (Old)
 and      /work/SRC/openSUSE:Factory/.syft.new.1631729 (New)
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Package is "syft"

Fri Oct  2 23:04:10 2026 rev:134 rq:1381998 version:1.54.0

Changes:
--------
--- /work/SRC/openSUSE:Factory/syft/syft.changes        2026-09-18 
22:08:24.121279343 +0200
+++ /work/SRC/openSUSE:Factory/.syft.new.1631729/syft.changes   2026-10-02 
23:04:36.717477579 +0200
@@ -1,0 +2,156 @@
+Fri Oct 02 04:51:43 UTC 2026 - Johannes Kastl 
<[email protected]>
+
+- Update to version 1.54.0 (1.53.0 was not released):
+  * Added Features
+    - report the perl interpreter as a cpan package [PR #5132]
+    - Add package cataloger for perl ecosystem [Issue #1906] [PR
+      #5131]
+    - Analyze with Non-Daemon podman [Issue #1173]
+  * Bug Fixes
+    - write a name for the root package when the source has none
+      [PR #5349]
+    - match opensource.org license URLs across SPDX URL forms [PR
+      #5361]
+    - Account for malformed GGUF and safetensors parameter counts
+      [PR #5343]
+    - don't panic on a root file without a supplier or null entries
+      [PR #5326]
+    - do not panic on a stack.yaml rev pin [PR #5310]
+    - report scanner errors and raise the line cap in metadata
+      parsers [PR #5353]
+    - Harden cataloger parsers against truncated input (do not
+      panic) [PR #5355]
+    - bound CPE candidate generation for pathological package
+      metadata [PR #5356]
+    - account for UPX's loader padding when unpacking Go binaries
+      [PR #5347]
+    - handle malformed GGUF headers without panicking [PR #5345]
+    - bound model companion file reads and validate their contents
+      [PR #5344]
+    - don't fail the whole SBOM when a cataloger panics on one file
+      [PR #5342]
+    - release package collection lock in Ubuntu ESM detection [PR
+      #5336]
+    - render TUI log lines on their own rows, with colors and a
+      small header [PR #5324]
+    - uv.lock: dependents are linked to every locked version of a
+      dependency [Issue #5340] [PR #5351]
+    - java-archive-cataloger maps Apache Groovy 4+
+      (org.apache.groovy) to obsolete org.codehaus.groovy [Issue
+      #5311] [PR #5313]
+    - Support traefik binary various versions [Issue #4980] [PR
+      #5281]
+    - File Digests Remain at Zero, No Hashes Available Despite
+      .syft.yaml Settings Should Support [Issue #5325] [PR #5341]
+    - not showing expat CVEs from syft generated sbom [Issue #4771]
+      [PR #5259]
+    - PHP extensions are cataloged as upstream products using the
+      PHP version [Issue #5014] [PR #5102]
+    - Panic during scanning with
+      gguf-cataloger/safetensors-cataloger [Issue #5327] [PR #5328]
+    - github-actions cataloger emits an invalid PURL for docker://
+      use statements [Issue #5299] [PR #5302]
+    - Crash when running syft on a directory that is the root file
+      system of a Yocto build [Issue #5320] [PR #5321]
+    - Invalid PURLs when cataloging instrumentation classes/jars
+      [Issue #2596]
+  * Dependencies
+    79 dependency changes (48 updated, 28 added, 3 removed). 2
+    vulnerabilities remediated.
+    - Remediated (2)
+      - GHSA-8wmf-6v46-5gfg (Low) — go.opentelemetry.io/otel/sdk
+      - GHSA-pg57-6jwg-q645 (Medium) —
+        github.com/containerd/containerd/v2
+    - Toolchains (1)
+      - Go minimum version: 1.26.3 → 1.26.8
+    - Updated (48 packages)
+      - github.com/Microsoft/hcsshim v0.15.0-rc.1 → v0.15.0-rc.4
+      - github.com/anchore/bubbly v0.2.1 → v0.2.2
+      - github.com/anchore/go-logger v0.1.1 → v0.2.0
+      - github.com/anchore/stereoscope v0.3.2 → v0.3.3
+      - github.com/bmatcuk/doublestar/v4 v4.10.0 → v4.10.2
+      - github.com/containerd/containerd/api v1.11.1 → v1.12.0
+      - github.com/containerd/containerd/v2 v2.3.5 → v2.4.1 (🟢
+        remediated GHSA-pg57-6jwg-q645)
+      - github.com/containerd/log v0.1.0 → v0.2.0
+      - github.com/containerd/ttrpc v1.2.8 → v1.2.9
+      - github.com/containerd/typeurl/v2 v2.2.3 → v2.3.0
+      - github.com/cyphar/filepath-securejoin v0.6.1 → v0.7.0
+      - github.com/docker/cli v29.8.0+incompatible →
+        v29.8.1+incompatible
+      - github.com/docker/docker-credential-helpers v0.9.5 → v0.9.8
+      - github.com/dustin/go-humanize v1.0.1 → v1.1.0
+      - github.com/erofs/go-erofs v0.3.0 → v0.3.1
+      - github.com/felixge/httpsnoop v1.0.4 → v1.1.0
+      - github.com/fsnotify/fsnotify v1.9.0 → v1.10.1
+      - github.com/go-jose/go-jose/v4 v4.1.4 → v4.1.5
+      - github.com/go-logr/logr v1.4.3 → v1.4.4
+      - github.com/hashicorp/hcl/v2 v2.24.0 → v2.25.0
+      - github.com/magiconair/properties v1.18.11 → v1.18.12
+      - github.com/mattn/go-runewidth v0.0.21 → v0.0.27
+      - github.com/moby/sys/user v0.4.0 → v0.4.1
+      - github.com/moby/sys/userns v0.1.0 → v0.2.1
+      - github.com/nwaples/rardecode/v2 v2.2.0 → v2.4.1
+      - github.com/olekukonko/tablewriter v1.1.4 → v1.1.5
+      - github.com/sirupsen/logrus v1.9.4 → v1.10.2
+      - github.com/ulikunitz/xz v0.5.16 → v0.5.17
+      - github.com/zclconf/go-cty v1.16.3 → v1.19.0
+      - 
go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc
+        v0.68.0 → v0.71.0
+      - go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp
+        v0.68.0 → v0.71.0
+      - go.opentelemetry.io/otel v1.44.0 → v1.46.0
+      - go.opentelemetry.io/otel/metric v1.44.0 → v1.46.0
+      - go.opentelemetry.io/otel/metric/x v0.66.0 → v0.68.0
+      - go.opentelemetry.io/otel/sdk v1.44.0 → v1.46.0 (
+        remediated GHSA-8wmf-6v46-5gfg)
+      - go.opentelemetry.io/otel/sdk/metric v1.44.0 → v1.46.0
+      - go.opentelemetry.io/otel/trace v1.44.0 → v1.46.0
+      - golang.org/x/crypto v0.56.0 → v0.57.0
+      - golang.org/x/net v0.58.0 → v0.59.0
+      - golang.org/x/sync v0.22.0 → v0.23.0
+      - golang.org/x/sys v0.47.0 → v0.48.0
+      - golang.org/x/term v0.45.0 → v0.46.0
+      - golang.org/x/text v0.41.0 → v0.42.0
+      - golang.org/x/tools v0.49.0 → v0.50.0
+      - google.golang.org/genproto/googleapis/api v0.0.0-e75dac1 →
+        v0.0.0-da73d73
+      - google.golang.org/genproto/googleapis/rpc v0.0.0-08b0e42 →
+        v0.0.0-da73d73
+      - modernc.org/libc v1.75.6 → v1.75.7
+      - modernc.org/sqlite v1.58.0 → v1.59.0
+    - Added (28 packages)
+      - cyphar.com/go-pathrs v0.2.5
+      - github.com/VividCortex/ewma v1.2.0
+      - github.com/apparentlymart/go-textseg/v17 v17.0.1
+      - github.com/containerd/log/otel v0.1.0
+      - github.com/containerd/stargz-snapshotter/estargz v0.18.2
+      - github.com/containers/libtrust v0.0.0-c1716e8
+      - github.com/containers/ocicrypt v1.3.2
+      - github.com/cyberphone/json-canonicalization v0.0.0-19d51d7
+      - github.com/google/go-intervals v0.0.2
+      - github.com/mattn/go-sqlite3 v1.14.48
+      - github.com/miekg/pkcs11 v1.1.2
+      - github.com/mistifyio/go-zfs/v4 v4.0.0
+      - github.com/moby/sys/capability v0.4.0
+      - github.com/opencontainers/selinux v1.15.1
+      - github.com/proglottis/gpgme v0.1.6
+      - github.com/secure-systems-lab/go-securesystemslib v0.11.0
+      - github.com/sigstore/fulcio v1.8.7
+      - github.com/sigstore/protobuf-specs v0.5.1
+      - github.com/sigstore/sigstore v1.10.8
+      - github.com/smallstep/pkcs7 v0.2.1
+      - github.com/stefanberger/go-pkcs11uri v0.0.0-7828495
+      - github.com/tchap/go-patricia/v2 v2.3.3
+      - github.com/vbatts/tar-split v0.12.3
+      - github.com/vbauerster/cupwriter v0.0.4
+      - github.com/vbauerster/mpb/v8 v8.14.0
+      - github.com/youmark/pkcs8 v0.0.0-a2c0da2
+      - go.podman.io/image/v5 v5.41.2
+      - go.podman.io/storage v1.64.1
+    - Removed (3 packages)
+      - github.com/gogo/protobuf v1.3.2
+      - github.com/moby/sys/sequential v0.6.0
+      - go.opencensus.io v0.24.0
+
+-------------------------------------------------------------------

Old:
----
  syft-1.52.0.obscpio

New:
----
  syft-1.54.0.obscpio

++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Other differences:
------------------
++++++ syft.spec ++++++
--- /var/tmp/diff_new_pack.x0Ra1V/_old  2026-10-02 23:04:39.716603106 +0200
+++ /var/tmp/diff_new_pack.x0Ra1V/_new  2026-10-02 23:04:39.721603315 +0200
@@ -17,7 +17,7 @@
 
 
 Name:           syft
-Version:        1.52.0
+Version:        1.54.0
 Release:        0
 Summary:        CLI tool and library for generating a Software Bill of 
Materials
 License:        Apache-2.0
@@ -26,7 +26,7 @@
 Source1:        vendor.tar.gz
 BuildRequires:  bash-completion
 BuildRequires:  fish
-BuildRequires:  go1.26 >= 1.26.3
+BuildRequires:  go1.26 >= 1.26.8
 BuildRequires:  zsh
 
 %description

++++++ _service ++++++
--- /var/tmp/diff_new_pack.x0Ra1V/_old  2026-10-02 23:04:39.793606329 +0200
+++ /var/tmp/diff_new_pack.x0Ra1V/_new  2026-10-02 23:04:39.801606664 +0200
@@ -3,7 +3,7 @@
     <param name="url">https://github.com/anchore/syft.git</param>
     <param name="scm">git</param>
     <param name="exclude">.git</param>
-    <param name="revision">refs/tags/v1.52.0</param>
+    <param name="revision">refs/tags/v1.54.0</param>
     <param name="versionformat">@PARENT_TAG@</param>
     <param name="versionrewrite-pattern">v(.*)</param>
     <param name="changesgenerate">enable</param>

++++++ _servicedata ++++++
--- /var/tmp/diff_new_pack.x0Ra1V/_old  2026-10-02 23:04:39.844608464 +0200
+++ /var/tmp/diff_new_pack.x0Ra1V/_new  2026-10-02 23:04:39.850608715 +0200
@@ -3,6 +3,6 @@
                 <param name="url">https://github.com/anchore/syft</param>
               <param 
name="changesrevision">b15c5dbfe2bb21c9d73002c1056a829c8c411c75</param></service><service
 name="tar_scm">
                 <param name="url">https://github.com/anchore/syft.git</param>
-              <param 
name="changesrevision">02ba369d13b4248395b20a504eca94b0cab564d8</param></service></servicedata>
+              <param 
name="changesrevision">cc326e45a6213360266dda4b30cc68095946d676</param></service></servicedata>
 (No newline at EOF)
 

++++++ syft-1.52.0.obscpio -> syft-1.54.0.obscpio ++++++
++++ 21733 lines of diff (skipped)

++++++ syft.obsinfo ++++++
--- /var/tmp/diff_new_pack.x0Ra1V/_old  2026-10-02 23:04:44.491802969 +0200
+++ /var/tmp/diff_new_pack.x0Ra1V/_new  2026-10-02 23:04:44.496803178 +0200
@@ -1,5 +1,5 @@
 name: syft
-version: 1.52.0
-mtime: 1789654186
-commit: 02ba369d13b4248395b20a504eca94b0cab564d8
+version: 1.54.0
+mtime: 1790881250
+commit: cc326e45a6213360266dda4b30cc68095946d676
 

++++++ vendor.tar.gz ++++++
/work/SRC/openSUSE:Factory/syft/vendor.tar.gz 
/work/SRC/openSUSE:Factory/.syft.new.1631729/vendor.tar.gz differ: char 13, 
line 1

Reply via email to