Script 'mail_helper' called by obssrc Hello community, here is the log from the commit of package syft for openSUSE:Factory checked in at 2026-10-02 23:04:10 ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Comparing /work/SRC/openSUSE:Factory/syft (Old) and /work/SRC/openSUSE:Factory/.syft.new.1631729 (New) ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Package is "syft" Fri Oct 2 23:04:10 2026 rev:134 rq:1381998 version:1.54.0 Changes: -------- --- /work/SRC/openSUSE:Factory/syft/syft.changes 2026-09-18 22:08:24.121279343 +0200 +++ /work/SRC/openSUSE:Factory/.syft.new.1631729/syft.changes 2026-10-02 23:04:36.717477579 +0200 @@ -1,0 +2,156 @@ +Fri Oct 02 04:51:43 UTC 2026 - Johannes Kastl <[email protected]> + +- Update to version 1.54.0 (1.53.0 was not released): + * Added Features + - report the perl interpreter as a cpan package [PR #5132] + - Add package cataloger for perl ecosystem [Issue #1906] [PR + #5131] + - Analyze with Non-Daemon podman [Issue #1173] + * Bug Fixes + - write a name for the root package when the source has none + [PR #5349] + - match opensource.org license URLs across SPDX URL forms [PR + #5361] + - Account for malformed GGUF and safetensors parameter counts + [PR #5343] + - don't panic on a root file without a supplier or null entries + [PR #5326] + - do not panic on a stack.yaml rev pin [PR #5310] + - report scanner errors and raise the line cap in metadata + parsers [PR #5353] + - Harden cataloger parsers against truncated input (do not + panic) [PR #5355] + - bound CPE candidate generation for pathological package + metadata [PR #5356] + - account for UPX's loader padding when unpacking Go binaries + [PR #5347] + - handle malformed GGUF headers without panicking [PR #5345] + - bound model companion file reads and validate their contents + [PR #5344] + - don't fail the whole SBOM when a cataloger panics on one file + [PR #5342] + - release package collection lock in Ubuntu ESM detection [PR + #5336] + - render TUI log lines on their own rows, with colors and a + small header [PR #5324] + - uv.lock: dependents are linked to every locked version of a + dependency [Issue #5340] [PR #5351] + - java-archive-cataloger maps Apache Groovy 4+ + (org.apache.groovy) to obsolete org.codehaus.groovy [Issue + #5311] [PR #5313] + - Support traefik binary various versions [Issue #4980] [PR + #5281] + - File Digests Remain at Zero, No Hashes Available Despite + .syft.yaml Settings Should Support [Issue #5325] [PR #5341] + - not showing expat CVEs from syft generated sbom [Issue #4771] + [PR #5259] + - PHP extensions are cataloged as upstream products using the + PHP version [Issue #5014] [PR #5102] + - Panic during scanning with + gguf-cataloger/safetensors-cataloger [Issue #5327] [PR #5328] + - github-actions cataloger emits an invalid PURL for docker:// + use statements [Issue #5299] [PR #5302] + - Crash when running syft on a directory that is the root file + system of a Yocto build [Issue #5320] [PR #5321] + - Invalid PURLs when cataloging instrumentation classes/jars + [Issue #2596] + * Dependencies + 79 dependency changes (48 updated, 28 added, 3 removed). 2 + vulnerabilities remediated. + - Remediated (2) + - GHSA-8wmf-6v46-5gfg (Low) — go.opentelemetry.io/otel/sdk + - GHSA-pg57-6jwg-q645 (Medium) — + github.com/containerd/containerd/v2 + - Toolchains (1) + - Go minimum version: 1.26.3 → 1.26.8 + - Updated (48 packages) + - github.com/Microsoft/hcsshim v0.15.0-rc.1 → v0.15.0-rc.4 + - github.com/anchore/bubbly v0.2.1 → v0.2.2 + - github.com/anchore/go-logger v0.1.1 → v0.2.0 + - github.com/anchore/stereoscope v0.3.2 → v0.3.3 + - github.com/bmatcuk/doublestar/v4 v4.10.0 → v4.10.2 + - github.com/containerd/containerd/api v1.11.1 → v1.12.0 + - github.com/containerd/containerd/v2 v2.3.5 → v2.4.1 (🟢 + remediated GHSA-pg57-6jwg-q645) + - github.com/containerd/log v0.1.0 → v0.2.0 + - github.com/containerd/ttrpc v1.2.8 → v1.2.9 + - github.com/containerd/typeurl/v2 v2.2.3 → v2.3.0 + - github.com/cyphar/filepath-securejoin v0.6.1 → v0.7.0 + - github.com/docker/cli v29.8.0+incompatible → + v29.8.1+incompatible + - github.com/docker/docker-credential-helpers v0.9.5 → v0.9.8 + - github.com/dustin/go-humanize v1.0.1 → v1.1.0 + - github.com/erofs/go-erofs v0.3.0 → v0.3.1 + - github.com/felixge/httpsnoop v1.0.4 → v1.1.0 + - github.com/fsnotify/fsnotify v1.9.0 → v1.10.1 + - github.com/go-jose/go-jose/v4 v4.1.4 → v4.1.5 + - github.com/go-logr/logr v1.4.3 → v1.4.4 + - github.com/hashicorp/hcl/v2 v2.24.0 → v2.25.0 + - github.com/magiconair/properties v1.18.11 → v1.18.12 + - github.com/mattn/go-runewidth v0.0.21 → v0.0.27 + - github.com/moby/sys/user v0.4.0 → v0.4.1 + - github.com/moby/sys/userns v0.1.0 → v0.2.1 + - github.com/nwaples/rardecode/v2 v2.2.0 → v2.4.1 + - github.com/olekukonko/tablewriter v1.1.4 → v1.1.5 + - github.com/sirupsen/logrus v1.9.4 → v1.10.2 + - github.com/ulikunitz/xz v0.5.16 → v0.5.17 + - github.com/zclconf/go-cty v1.16.3 → v1.19.0 + - go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc + v0.68.0 → v0.71.0 + - go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp + v0.68.0 → v0.71.0 + - go.opentelemetry.io/otel v1.44.0 → v1.46.0 + - go.opentelemetry.io/otel/metric v1.44.0 → v1.46.0 + - go.opentelemetry.io/otel/metric/x v0.66.0 → v0.68.0 + - go.opentelemetry.io/otel/sdk v1.44.0 → v1.46.0 ( + remediated GHSA-8wmf-6v46-5gfg) + - go.opentelemetry.io/otel/sdk/metric v1.44.0 → v1.46.0 + - go.opentelemetry.io/otel/trace v1.44.0 → v1.46.0 + - golang.org/x/crypto v0.56.0 → v0.57.0 + - golang.org/x/net v0.58.0 → v0.59.0 + - golang.org/x/sync v0.22.0 → v0.23.0 + - golang.org/x/sys v0.47.0 → v0.48.0 + - golang.org/x/term v0.45.0 → v0.46.0 + - golang.org/x/text v0.41.0 → v0.42.0 + - golang.org/x/tools v0.49.0 → v0.50.0 + - google.golang.org/genproto/googleapis/api v0.0.0-e75dac1 → + v0.0.0-da73d73 + - google.golang.org/genproto/googleapis/rpc v0.0.0-08b0e42 → + v0.0.0-da73d73 + - modernc.org/libc v1.75.6 → v1.75.7 + - modernc.org/sqlite v1.58.0 → v1.59.0 + - Added (28 packages) + - cyphar.com/go-pathrs v0.2.5 + - github.com/VividCortex/ewma v1.2.0 + - github.com/apparentlymart/go-textseg/v17 v17.0.1 + - github.com/containerd/log/otel v0.1.0 + - github.com/containerd/stargz-snapshotter/estargz v0.18.2 + - github.com/containers/libtrust v0.0.0-c1716e8 + - github.com/containers/ocicrypt v1.3.2 + - github.com/cyberphone/json-canonicalization v0.0.0-19d51d7 + - github.com/google/go-intervals v0.0.2 + - github.com/mattn/go-sqlite3 v1.14.48 + - github.com/miekg/pkcs11 v1.1.2 + - github.com/mistifyio/go-zfs/v4 v4.0.0 + - github.com/moby/sys/capability v0.4.0 + - github.com/opencontainers/selinux v1.15.1 + - github.com/proglottis/gpgme v0.1.6 + - github.com/secure-systems-lab/go-securesystemslib v0.11.0 + - github.com/sigstore/fulcio v1.8.7 + - github.com/sigstore/protobuf-specs v0.5.1 + - github.com/sigstore/sigstore v1.10.8 + - github.com/smallstep/pkcs7 v0.2.1 + - github.com/stefanberger/go-pkcs11uri v0.0.0-7828495 + - github.com/tchap/go-patricia/v2 v2.3.3 + - github.com/vbatts/tar-split v0.12.3 + - github.com/vbauerster/cupwriter v0.0.4 + - github.com/vbauerster/mpb/v8 v8.14.0 + - github.com/youmark/pkcs8 v0.0.0-a2c0da2 + - go.podman.io/image/v5 v5.41.2 + - go.podman.io/storage v1.64.1 + - Removed (3 packages) + - github.com/gogo/protobuf v1.3.2 + - github.com/moby/sys/sequential v0.6.0 + - go.opencensus.io v0.24.0 + +------------------------------------------------------------------- Old: ---- syft-1.52.0.obscpio New: ---- syft-1.54.0.obscpio ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Other differences: ------------------ ++++++ syft.spec ++++++ --- /var/tmp/diff_new_pack.x0Ra1V/_old 2026-10-02 23:04:39.716603106 +0200 +++ /var/tmp/diff_new_pack.x0Ra1V/_new 2026-10-02 23:04:39.721603315 +0200 @@ -17,7 +17,7 @@ Name: syft -Version: 1.52.0 +Version: 1.54.0 Release: 0 Summary: CLI tool and library for generating a Software Bill of Materials License: Apache-2.0 @@ -26,7 +26,7 @@ Source1: vendor.tar.gz BuildRequires: bash-completion BuildRequires: fish -BuildRequires: go1.26 >= 1.26.3 +BuildRequires: go1.26 >= 1.26.8 BuildRequires: zsh %description ++++++ _service ++++++ --- /var/tmp/diff_new_pack.x0Ra1V/_old 2026-10-02 23:04:39.793606329 +0200 +++ /var/tmp/diff_new_pack.x0Ra1V/_new 2026-10-02 23:04:39.801606664 +0200 @@ -3,7 +3,7 @@ <param name="url">https://github.com/anchore/syft.git</param> <param name="scm">git</param> <param name="exclude">.git</param> - <param name="revision">refs/tags/v1.52.0</param> + <param name="revision">refs/tags/v1.54.0</param> <param name="versionformat">@PARENT_TAG@</param> <param name="versionrewrite-pattern">v(.*)</param> <param name="changesgenerate">enable</param> ++++++ _servicedata ++++++ --- /var/tmp/diff_new_pack.x0Ra1V/_old 2026-10-02 23:04:39.844608464 +0200 +++ /var/tmp/diff_new_pack.x0Ra1V/_new 2026-10-02 23:04:39.850608715 +0200 @@ -3,6 +3,6 @@ <param name="url">https://github.com/anchore/syft</param> <param name="changesrevision">b15c5dbfe2bb21c9d73002c1056a829c8c411c75</param></service><service name="tar_scm"> <param name="url">https://github.com/anchore/syft.git</param> - <param name="changesrevision">02ba369d13b4248395b20a504eca94b0cab564d8</param></service></servicedata> + <param name="changesrevision">cc326e45a6213360266dda4b30cc68095946d676</param></service></servicedata> (No newline at EOF) ++++++ syft-1.52.0.obscpio -> syft-1.54.0.obscpio ++++++ ++++ 21733 lines of diff (skipped) ++++++ syft.obsinfo ++++++ --- /var/tmp/diff_new_pack.x0Ra1V/_old 2026-10-02 23:04:44.491802969 +0200 +++ /var/tmp/diff_new_pack.x0Ra1V/_new 2026-10-02 23:04:44.496803178 +0200 @@ -1,5 +1,5 @@ name: syft -version: 1.52.0 -mtime: 1789654186 -commit: 02ba369d13b4248395b20a504eca94b0cab564d8 +version: 1.54.0 +mtime: 1790881250 +commit: cc326e45a6213360266dda4b30cc68095946d676 ++++++ vendor.tar.gz ++++++ /work/SRC/openSUSE:Factory/syft/vendor.tar.gz /work/SRC/openSUSE:Factory/.syft.new.1631729/vendor.tar.gz differ: char 13, line 1
