Script 'mail_helper' called by obssrc Hello community, here is the log from the commit of package go1.21 for openSUSE:Factory checked in at 2023-12-07 19:09:02 ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Comparing /work/SRC/openSUSE:Factory/go1.21 (Old) and /work/SRC/openSUSE:Factory/.go1.21.new.25432 (New) ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Package is "go1.21" Thu Dec 7 19:09:02 2023 rev:9 rq:1131275 version:1.21.5 Changes: -------- --- /work/SRC/openSUSE:Factory/go1.21/go1.21.changes 2023-11-09 21:34:35.715109723 +0100 +++ /work/SRC/openSUSE:Factory/.go1.21.new.25432/go1.21.changes 2023-12-07 19:09:25.113074280 +0100 @@ -1,0 +2,21 @@ +Tue Dec 5 19:03:51 UTC 2023 - Jeff Kowalczyk <jkowalc...@suse.com> + +- go1.21.5 (released 2023-12-05) includes security fixes to the go + command, and the net/http and path/filepath packages, as well as + bug fixes to the compiler, the go command, the runtime, and the + crypto/rand, net, os, and syscall packages. + Refs boo#1212475 go1.21 release tracking + CVE-2023-45285 CVE-2023-45284 CVE-2023-39326 + * go#63973 go#63845 boo#1217834 security: fix CVE-2023-45285 cmd/go: git VCS qualifier in module path uses git:// scheme + * go#64041 go#63713 boo#1216943 security: fix CVE-2023-45284 path/filepath: Clean removes ending slash for volume on Windows in Go 1.21.4 + * go#64435 go#64433 boo#1217833 security: fix CVE-2023-39326 net/http: limit chunked data overhead + * go#62055 cmd/go: go mod download needs to support toolchain upgrades + * go#63743 cmd/compile: invalid pointer found on stack when compiled with -race + * go#63764 os: NTFS deduped file changed from regular to irregular + * go#63801 net: TCPConn.ReadFrom hangs when io.Reader is TCPConn or UnixConn, Linux kernel < 5.1 + * go#63984 cmd/compile: internal compiler error: panic during prove while compiling: unexpected induction with too many parents + * go#63994 syscall: TestOpenFileLimit unintentionally runs on non-Unix platforms + * go#64073 runtime: self-deadlock on mheap_.lock + * go#64413 crypto/rand: Legacy RtlGenRandom use on Windows + +------------------------------------------------------------------- Old: ---- go1.21.4.src.tar.gz New: ---- go1.21.5.src.tar.gz ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Other differences: ------------------ ++++++ go1.21.spec ++++++ --- /var/tmp/diff_new_pack.buFYKG/_old 2023-12-07 19:09:26.825137446 +0100 +++ /var/tmp/diff_new_pack.buFYKG/_new 2023-12-07 19:09:26.829137593 +0100 @@ -126,7 +126,7 @@ %endif Name: go1.21 -Version: 1.21.4 +Version: 1.21.5 Release: 0 Summary: A compiled, garbage-collected, concurrent programming language License: BSD-3-Clause ++++++ go1.21.4.src.tar.gz -> go1.21.5.src.tar.gz ++++++ /work/SRC/openSUSE:Factory/go1.21/go1.21.4.src.tar.gz /work/SRC/openSUSE:Factory/.go1.21.new.25432/go1.21.5.src.tar.gz differ: char 110, line 2