Script 'mail_helper' called by obssrc Hello community, here is the log from the commit of package go1.18 for openSUSE:Factory checked in at 2022-06-03 14:15:34 ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Comparing /work/SRC/openSUSE:Factory/go1.18 (Old) and /work/SRC/openSUSE:Factory/.go1.18.new.1548 (New) ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Package is "go1.18" Fri Jun 3 14:15:34 2022 rev:11 rq:980420 version:1.18.3 Changes: -------- --- /work/SRC/openSUSE:Factory/go1.18/go1.18.changes 2022-05-12 22:58:18.504631502 +0200 +++ /work/SRC/openSUSE:Factory/.go1.18.new.1548/go1.18.changes 2022-06-03 14:15:47.941248862 +0200 @@ -1,0 +2,25 @@ +Wed Jun 1 17:51:26 UTC 2022 - Jeff Kowalczyk <jkowalc...@suse.com> + +- go1.18.3 (released 2022-06-01) includes security fixes to the + crypto/rand, crypto/tls, os/exec, and path/filepath packages, as + well as bug fixes to the compiler, and the crypto/tls and + text/template/parse packages. + Refs boo#1193742 go1.18 release tracking + CVE-2022-30634 CVE-2022-30629 CVE-2022-30580 CVE-2022-29804 + * boo#1200134 go#52561 CVE-2022-30634 + * go#52933 crypto/rand: Read hangs when passed buffer larger than 1<<32 - 1 + * boo#1200135 go#52814 CVE-2022-30629 + * go#52833 crypto/tls: randomly generate ticket_age_add + * boo#1200136 go#52574 CVE-2022-30580 + * go#53057 os/exec: Cmd.{Run,Start} should fail if Cmd.Path is unset + * boo#1200137 go#52476 CVE-2022-29804 + * go#52479 path/filepath: Clean(.\c:) returns c: on Windows + * go#51849 cmd/compile: crash on pointer conversion in call to mapaccess2 + * go#52242 cmd/compile: compiler crash on valid code + * go#52286 cmd/compile: compiler crash with "Dictionary should have already been generated" + * go#52791 crypto/tls: 500% increase in allocations from (*tls.Conn).Read in go 1.17 + * go#52878 text/template: break/continue require no whitespace around them + * go#53043 misc/cgo/testsanitizers: occasional hangs in TestTSAN/tsan12 + * go#53115 misc/cgo/testsanitizers: deadlock in TestTSAN/tsan11 + +------------------------------------------------------------------- Old: ---- go1.18.2.src.tar.gz New: ---- go1.18.3.src.tar.gz ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Other differences: ------------------ ++++++ go1.18.spec ++++++ --- /var/tmp/diff_new_pack.xpZLu1/_old 2022-06-03 14:15:48.669249808 +0200 +++ /var/tmp/diff_new_pack.xpZLu1/_new 2022-06-03 14:15:48.673249814 +0200 @@ -145,7 +145,7 @@ %endif Name: go1.18 -Version: 1.18.2 +Version: 1.18.3 Release: 0 Summary: A compiled, garbage-collected, concurrent programming language License: BSD-3-Clause ++++++ go1.18.2.src.tar.gz -> go1.18.3.src.tar.gz ++++++ /work/SRC/openSUSE:Factory/go1.18/go1.18.2.src.tar.gz /work/SRC/openSUSE:Factory/.go1.18.new.1548/go1.18.3.src.tar.gz differ: char 17, line 1