leap-16.1 #9

Manually merged
mcepl merged 29 commits from mcepl/git-bug:leap-16.1 into leap-16.1 2025-12-10 10:41:45 +01:00
Contributor
Tue Nov 25 17:41:00 UTC 2025 - Matej Cepl mcepl@cepl.eu

- Revendor to include fixed version of depending libraries:
- GO-2025-4116 (CVE-2025-47913, bsc#1253506) upgrade
golang.org/x/crypto to v0.43.0
- GO-2025-3900 (GHSA-2464-8j7c-4cjm) upgrade
github.com/go-viper/mapstructure/v2 to v2.4.0
- GO-2025-3787 (GHSA-fv92-fjc5-jj9h) included in the previous
- GO-2025-3754 (GHSA-2x5j-vhc8-9cwm) upgrade
github.com/cloudflare/circl to v1.6.1
- GO-2025-4134 (CVE-2025-58181, bsc#1253930) upgrade
golang.org/x/crypto/ssh to v0.45.0
- GO-2025-4135 (CVE-2025-47914, bsc#1254084) upgrade
golang.org/x/crypto/ssh/agent to v0.45.0

Wed Oct 15 20:05:09 UTC 2025 - Matej Cepl mcepl@cepl.eu

  • Revendor to include golang.org/x/net/html v 0.45.0 to prevent
    possible DoS by various algorithms with quadratic complexity
    when parsing HTML documents (bsc#1251463, CVE-2025-47911 and
    bsc#1251664, CVE-2025-58190).

Mon May 19 08:38:03 UTC 2025 - Matej Cepl mcepl@cepl.eu

  • Update to version 0.10.1:
    • cli: ignore missing sections when removing configuration (ddb22a2f)
  • Update to version 0.10.0:
    • bridge: correct command used to create a new bridge (9942337b)
    • web: simplify header navigation (7e95b169)
    • webui: remark upgrade + gfm + syntax highlighting (6ee47b96)
    • BREAKING CHANGE: dev-infra: remove gokart (89b880bd)
  • Update to version 0.10.0
    • bridge: correct command used to create a new bridge (9942337b)
    • web: simplify header navigation (7e95b169)
    • web: remark upgrade + gfm + syntax highlighting (6ee47b96)
  • Update to version 0.9.0:
    • completion: remove errata from string literal (aa102c91)
    • tui: improve readability of the help bar (23be684a)

Tue May 06 10:21:55 UTC 2025 - mcepl@cepl.eu

  • Update to version 0.8.1+git.1746484874.96c7a111:
    • docs: update install, contrib, and usage documentation (#1222)
    • fix: resolve the remote URI using url.*.insteadOf (#1394)
    • build(deps): bump the go_modules group across 1 directory with 3 updates (#1376)
    • chore: gofmt simplify gitlab/export_test.go (#1392)
    • fix: checkout repo before setting up go environment (#1390)
    • feat: bump to go v1.24.2 (#1389)
    • chore: update golang.org/x/net (#1379)
    • fix: use -0700 when formatting time (#1388)
    • fix: use correct url for gitlab PATs (#1384)
    • refactor: remove depdendency on pnpm for auto-label action (#1383)
    • feat: add action: auto-label (#1380)
    • feat: remove lifecycle/frozen (#1377)
    • build(deps): bump the npm_and_yarn group across 1 directory with 12 updates (#1378)
    • feat: support new exclusion label: lifecycle/pinned (#1375)
    • fix: refactor how gitlab title changes are detected (#1370)
    • revert: "Create Dependabot config file" (#1374)
    • refactor: rename //:git-bug.go to //:main.go (#1373)
    • build(deps): bump github.com/vektah/gqlparser/v2 from 2.5.16 to 2.5.25 (#1361)
    • fix: set GitLastTag to an empty string when git-describe errors (#1355)
    • chore: update go-git to v5@masterupdate_mods (#1284)
    • refactor: Directly swap two variables to optimize code (#1272)
    • Update README.md Matrix link to new room (#1275)
  • Remove upstreamed patch:
    • CVE-2025-22869-bump-go-crypto-ssh.patch

Tue Mar 25 15:29:50 UTC 2025 - mcepl@cepl.eu

  • Update to version 0.8.0+git.1742269202.0ab94c9:
    • deps(crypto): bump golang.org/x/crypto from v0.26.0 to v0.31.0 (fix for CVE-2024-45337) (#1312)
  • Remove upstreamed CVE-2024-45337-bump-go-crypto.patch
    (apparently upstream still didn’t see the other one).

Thu Mar 13 17:02:33 UTC 2025 - mcepl@cepl.eu

  • Add CVE-2025-22869-bump-go-crypto-ssh.patch to update
    golang.org/x/crypto/ssh to v0.35.0 (bsc#1239494,
    CVE-2025-22869).

Wed Jan 22 16:32:25 UTC 2025 - Matej Cepl mcepl@cepl.eu

  • Add missing Requires to completion subpackages.

Wed Jan 8 09:00:10 UTC 2025 - Matej Cepl mcepl@cepl.eu

  • Update vendorization.

Tue Dec 17 13:53:28 UTC 2024 - Matej Cepl mcepl@cepl.eu

  • Update to version 0.8.0+git.1733745604.d499b6e:
    • fix typos in docs (#1266)
    • build(deps): bump github.com/go-git/go-billy/v5 from 5.5.0 to 5.6.0 (#1289)
  • Add CVE-2024-45337-bump-go-crypto.patch to bump
    golang.org/x/crypto from v0.26.0 to v0.31.0 (fix for
    CVE-2024-45337, bsc#1234565).
------------------------------------------------------------------- Tue Nov 25 17:41:00 UTC 2025 - Matej Cepl <mcepl@cepl.eu> - Revendor to include fixed version of depending libraries: - GO-2025-4116 (CVE-2025-47913, bsc#1253506) upgrade golang.org/x/crypto to v0.43.0 - GO-2025-3900 (GHSA-2464-8j7c-4cjm) upgrade github.com/go-viper/mapstructure/v2 to v2.4.0 - GO-2025-3787 (GHSA-fv92-fjc5-jj9h) included in the previous - GO-2025-3754 (GHSA-2x5j-vhc8-9cwm) upgrade github.com/cloudflare/circl to v1.6.1 - GO-2025-4134 (CVE-2025-58181, bsc#1253930) upgrade golang.org/x/crypto/ssh to v0.45.0 - GO-2025-4135 (CVE-2025-47914, bsc#1254084) upgrade golang.org/x/crypto/ssh/agent to v0.45.0 ------------------------------------------------------------------- Wed Oct 15 20:05:09 UTC 2025 - Matej Cepl <mcepl@cepl.eu> - Revendor to include golang.org/x/net/html v 0.45.0 to prevent possible DoS by various algorithms with quadratic complexity when parsing HTML documents (bsc#1251463, CVE-2025-47911 and bsc#1251664, CVE-2025-58190). ------------------------------------------------------------------- Mon May 19 08:38:03 UTC 2025 - Matej Cepl <mcepl@cepl.eu> - Update to version 0.10.1: - cli: ignore missing sections when removing configuration (ddb22a2f) - Update to version 0.10.0: - bridge: correct command used to create a new bridge (9942337b) - web: simplify header navigation (7e95b169) - webui: remark upgrade + gfm + syntax highlighting (6ee47b96) - BREAKING CHANGE: dev-infra: remove gokart (89b880bd) - Update to version 0.10.0 - bridge: correct command used to create a new bridge (9942337b) - web: simplify header navigation (7e95b169) - web: remark upgrade + gfm + syntax highlighting (6ee47b96) - Update to version 0.9.0: - completion: remove errata from string literal (aa102c91) - tui: improve readability of the help bar (23be684a) ------------------------------------------------------------------- Tue May 06 10:21:55 UTC 2025 - mcepl@cepl.eu - Update to version 0.8.1+git.1746484874.96c7a111: * docs: update install, contrib, and usage documentation (#1222) * fix: resolve the remote URI using url.*.insteadOf (#1394) * build(deps): bump the go_modules group across 1 directory with 3 updates (#1376) * chore: gofmt simplify gitlab/export_test.go (#1392) * fix: checkout repo before setting up go environment (#1390) * feat: bump to go v1.24.2 (#1389) * chore: update golang.org/x/net (#1379) * fix: use -0700 when formatting time (#1388) * fix: use correct url for gitlab PATs (#1384) * refactor: remove depdendency on pnpm for auto-label action (#1383) * feat: add action: auto-label (#1380) * feat: remove lifecycle/frozen (#1377) * build(deps): bump the npm_and_yarn group across 1 directory with 12 updates (#1378) * feat: support new exclusion label: lifecycle/pinned (#1375) * fix: refactor how gitlab title changes are detected (#1370) * revert: "Create Dependabot config file" (#1374) * refactor: rename //:git-bug.go to //:main.go (#1373) * build(deps): bump github.com/vektah/gqlparser/v2 from 2.5.16 to 2.5.25 (#1361) * fix: set GitLastTag to an empty string when git-describe errors (#1355) * chore: update go-git to v5@masterupdate_mods (#1284) * refactor: Directly swap two variables to optimize code (#1272) * Update README.md Matrix link to new room (#1275) - Remove upstreamed patch: - CVE-2025-22869-bump-go-crypto-ssh.patch ------------------------------------------------------------------- Tue Mar 25 15:29:50 UTC 2025 - mcepl@cepl.eu - Update to version 0.8.0+git.1742269202.0ab94c9: * deps(crypto): bump golang.org/x/crypto from v0.26.0 to v0.31.0 (fix for CVE-2024-45337) (#1312) - Remove upstreamed CVE-2024-45337-bump-go-crypto.patch (apparently upstream still didn’t see the other one). ------------------------------------------------------------------- Thu Mar 13 17:02:33 UTC 2025 - mcepl@cepl.eu - Add CVE-2025-22869-bump-go-crypto-ssh.patch to update golang.org/x/crypto/ssh to v0.35.0 (bsc#1239494, CVE-2025-22869). ------------------------------------------------------------------- Wed Jan 22 16:32:25 UTC 2025 - Matej Cepl <mcepl@cepl.eu> - Add missing Requires to completion subpackages. ------------------------------------------------------------------- Wed Jan 8 09:00:10 UTC 2025 - Matej Cepl <mcepl@cepl.eu> - Update vendorization. ------------------------------------------------------------------- Tue Dec 17 13:53:28 UTC 2024 - Matej Cepl <mcepl@cepl.eu> - Update to version 0.8.0+git.1733745604.d499b6e: * fix typos in docs (#1266) * build(deps): bump github.com/go-git/go-billy/v5 from 5.5.0 to 5.6.0 (#1289) - Add CVE-2024-45337-bump-go-crypto.patch to bump golang.org/x/crypto from v0.26.0 to v0.31.0 (fix for CVE-2024-45337, bsc#1234565).
mcepl added 16 commits 2025-12-01 12:13:46 +01:00
OBS-URL: https://build.opensuse.org/package/show/devel:Factory:git-workflow:staging:mcepl:git-bug:1/git-bug?expand=0&rev=1
Update to version 0.8.0+git.1725552198.b0cc690:

Also switch to _service and generated tarball

(🤖: Submission of git-bug via #1 by mcepl)

OBS-URL: https://build.opensuse.org/request/show/1205581
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/git-bug?expand=0&rev=5
OBS-URL: https://build.opensuse.org/package/show/devel:Factory:git-workflow:staging:mcepl:git-bug:2/git-bug?expand=0&rev=2
Cve 2024 45337 Crypto Bump

- Update to version 0.8.0+git.1733745604.d499b6e:
  * fix typos in docs (#1266)
  * build(deps): bump github.com/go-git/go-billy/v5 from 5.5.0 to 5.6.0 (#1289)
- Add CVE-2024-45337-bump-go-crypto.patch to bump
  golang.org/x/crypto from v0.26.0 to v0.31.0 (fix for
  CVE-2024-45337, bsc#1234565).

(🤖: Submission of git-bug via #2 by mcepl)

OBS-URL: https://build.opensuse.org/request/show/1231700
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/git-bug?expand=0&rev=6
OBS-URL: https://build.opensuse.org/package/show/devel:Factory:git-workflow:staging:mcepl:git-bug:4/git-bug?expand=0&rev=1
OBS-URL: https://build.opensuse.org/package/show/devel:Factory:git-workflow:staging:mcepl:git-bug:4/git-bug?expand=0&rev=2
OBS-URL: https://build.opensuse.org/package/show/devel:Factory:git-workflow:staging:mcepl:git-bug:4/git-bug?expand=0&rev=3
OBS-URL: https://build.opensuse.org/package/show/devel:Factory:git-workflow:staging:mcepl:git-bug:4/git-bug?expand=0&rev=4
Update To D499b6e

Update to the commit d499b6e.

(🤖: Submission of git-bug via #4 by mcepl)

OBS-URL: https://build.opensuse.org/request/show/1235844
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/git-bug?expand=0&rev=7
OBS-URL: https://build.opensuse.org/package/show/devel:Factory:git-workflow:staging:mcepl:git-bug:4/git-bug?expand=0&rev=5
OBS-URL: https://build.opensuse.org/package/show/devel:Factory:git-workflow:staging:mcepl:git-bug:4/git-bug?expand=0&rev=6
Update To D499b6e

Update to the commit d499b6e.

(🤖: Submission of git-bug via #4 by mcepl)

OBS-URL: https://build.opensuse.org/request/show/1239615
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/git-bug?expand=0&rev=8
- Update to version 0.8.0+git.1742269202.0ab94c9:

- Update to version 0.8.0+git.1742269202.0ab94c9:

(🤖: Submission of git-bug via #7 by mcepl)

OBS-URL: https://build.opensuse.org/request/show/1256145
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/git-bug?expand=0&rev=9
- Update to version 0.8.1+git.1746484874.96c7a111:
* docs: update install, contrib, and usage documentation (#1222)
* fix: resolve the remote URI using url.*.insteadOf (#1394)
* build(deps): bump the go_modules group across 1 directory with 3 updates (#1376)
* chore: gofmt simplify gitlab/export_test.go (#1392)
* fix: checkout repo before setting up go environment (#1390)
* feat: bump to go v1.24.2 (#1389)
* chore: update golang.org/x/net (#1379)
* fix: use -0700 when formatting time (#1388)
* fix: use correct url for gitlab PATs (#1384)
* refactor: remove depdendency on pnpm for auto-label action (#1383)
* feat: add action: auto-label (#1380)
* feat: remove lifecycle/frozen (#1377)
* build(deps): bump the npm_and_yarn group across 1 directory with 12 updates (#1378)
* feat: support new exclusion label: lifecycle/pinned (#1375)
* fix: refactor how gitlab title changes are detected (#1370)
* revert: "Create Dependabot config file" (#1374)
* refactor: rename //:git-bug.go to //:main.go (#1373)
* build(deps): bump github.com/vektah/gqlparser/v2 from 2.5.16 to 2.5.25 (#1361)
* fix: set GitLastTag to an empty string when git-describe errors (#1355)
* chore: update go-git to v5@masterupdate_mods (#1284)
* refactor: Directly swap two variables to optimize code (#1272)
* Update README.md Matrix link to new room (#1275)
- Remove upstreamed patch:
- CVE-2025-22869-bump-go-crypto-ssh.patch

OBS-URL: https://build.opensuse.org/request/show/1275060
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/git-bug?expand=0&rev=10
- Update to version 0.10.1:
  - cli: ignore missing sections when removing configuration (ddb22a2f)
- Update to version 0.10.0:
  - bridge: correct command used to create a new bridge (9942337b)
  - web: simplify header navigation (7e95b169)
  - webui: remark upgrade + gfm + syntax highlighting (6ee47b96)
  - BREAKING CHANGE: dev-infra: remove gokart (89b880bd)
- Update to version 0.10.0
  - bridge: correct command used to create a new bridge (9942337b)
  - web: simplify header navigation (7e95b169)
  - web: remark upgrade + gfm + syntax highlighting (6ee47b96)
- Update to version 0.9.0:
  - completion: remove errata from string literal (aa102c91)
  - tui: improve readability of the help bar (23be684a)

OBS-URL: https://build.opensuse.org/request/show/1278375
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/git-bug?expand=0&rev=11
- Revendor to include golang.org/x/net/html v 0.45.0 to prevent
  possible DoS by various algorithms with quadratic complexity
  when parsing HTML documents (bsc#1251463, CVE-2025-47911 and
  bsc#1251664, CVE-2025-58190).

OBS-URL: https://build.opensuse.org/request/show/1312668
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/git-bug?expand=0&rev=12
autogits_workflow_pr_bot requested review from legaldb 2025-12-01 12:14:13 +01:00
autogits_workflow_pr_bot requested review from packagehub-review 2025-12-01 12:14:13 +01:00
packagehub-review requested review from bigironman 2025-12-01 12:21:38 +01:00
packagehub-review requested review from lkocman-factory 2025-12-01 12:21:38 +01:00
packagehub-review requested review from maxlin_factory 2025-12-01 12:21:38 +01:00
packagehub-review requested review from smithfarm 2025-12-01 12:21:38 +01:00

Review by packagehub-review represents a group of reviewers: bigironman, lkocman-factory, maxlin_factory, smithfarm .

Do not use standard review interface to review on behalf of the group.
To accept the review on behalf of the group, create the following comment: @packagehub-review: approve.
To request changes on behalf of the group, create the following comment: @packagehub-review: decline followed with lines justifying the decision.
Future edits of the comments are ignored, a new comment is required to change the review state.

Review by packagehub-review represents a group of reviewers: bigironman, lkocman-factory, maxlin_factory, smithfarm . Do **not** use standard review interface to review on behalf of the group. To accept the review on behalf of the group, create the following comment: `@packagehub-review: approve`. To request changes on behalf of the group, create the following comment: `@packagehub-review: decline` followed with lines justifying the decision. Future edits of the comments are ignored, a new comment is required to change the review state.
Member

Legal reviewed as acceptable_by_lawyer:

Accepted because previously reviewed under the same license (491249)
Legal reviewed as [acceptable_by_lawyer](https://legaldb.suse.de/reviews/details/491937): ``` Accepted because previously reviewed under the same license (491249) ```
1.5 KiB
legaldb approved these changes 2025-12-01 12:29:17 +01:00
Dismissed
mcepl added 1 commit 2025-12-01 12:51:43 +01:00
- GO-2025-4116 (CVE-2025-47913, bsc#1253506) upgrade
    golang.org/x/crypto to v0.43.0
  - GO-2025-3900 (GHSA-2464-8j7c-4cjm) upgrade
    github.com/go-viper/mapstructure/v2 to v2.4.0
  - GO-2025-3787 (GHSA-fv92-fjc5-jj9h) included in the previous
  - GO-2025-3754 (GHSA-2x5j-vhc8-9cwm) upgrade
    github.com/cloudflare/circl to v1.6.1
  - GO-2025-4134 (CVE-2025-58181, bsc#1253930) upgrade
    golang.org/x/crypto/ssh to v0.45.0
  - GO-2025-4135 (CVE-2025-47914, bsc#1254084) upgrade
    golang.org/x/crypto/ssh/agent to v0.45.0
mcepl dismissed legaldb's review 2025-12-01 12:51:43 +01:00
Reason:

New commits pushed, approval review dismissed automatically according to repository settings

Review by packagehub-review represents a group of reviewers: bigironman, lkocman-factory, maxlin_factory, smithfarm .

Do not use standard review interface to review on behalf of the group.
To accept the review on behalf of the group, create the following comment: @packagehub-review: approve.
To request changes on behalf of the group, create the following comment: @packagehub-review: decline followed with lines justifying the decision.
Future edits of the comments are ignored, a new comment is required to change the review state.

Review by packagehub-review represents a group of reviewers: bigironman, lkocman-factory, maxlin_factory, smithfarm . Do **not** use standard review interface to review on behalf of the group. To accept the review on behalf of the group, create the following comment: `@packagehub-review: approve`. To request changes on behalf of the group, create the following comment: `@packagehub-review: decline` followed with lines justifying the decision. Future edits of the comments are ignored, a new comment is required to change the review state.
autogits_workflow_pr_bot requested review from legaldb 2025-12-01 12:52:14 +01:00
Member

Legal reviewed as acceptable_by_lawyer:

Accepted because previously reviewed under the same license (491937)
Legal reviewed as [acceptable_by_lawyer](https://legaldb.suse.de/reviews/details/491941): ``` Accepted because previously reviewed under the same license (491937) ```
1.5 KiB
legaldb approved these changes 2025-12-01 13:09:27 +01:00
Member
@packagehub-review: approve
packagehub-review approved these changes 2025-12-10 10:41:12 +01:00
packagehub-review left a comment
Member

maxlin_factory approved a review on behalf of packagehub-review

maxlin_factory approved a review on behalf of packagehub-review
packagehub-review removed review request for bigironman 2025-12-10 10:41:12 +01:00
packagehub-review removed review request for lkocman-factory 2025-12-10 10:41:13 +01:00
packagehub-review removed review request for maxlin_factory 2025-12-10 10:41:13 +01:00
packagehub-review removed review request for smithfarm 2025-12-10 10:41:13 +01:00
mcepl manually merged commit 2390ae6cee into leap-16.1 2025-12-10 10:41:45 +01:00

This PR is merged via the associated Project PR.

This PR is merged via the associated Project PR.
Sign in to join this conversation.