diff --git a/_service b/_service index 1f29497..2a47ea9 100644 --- a/_service +++ b/_service @@ -3,7 +3,7 @@ https://github.com/str4d/rage.git @PARENT_TAG@+@TAG_OFFSET@ git - v0.11.0 + v0.11.1 * v(\d+\.\d+\.\d+) \1 diff --git a/_servicedata b/_servicedata index 27e8353..8c90118 100644 --- a/_servicedata +++ b/_servicedata @@ -1,4 +1,4 @@ https://github.com/str4d/rage.git - 17446612f865c705e44fe392d9d41dd102fed137 \ No newline at end of file + 07808823074013acab5417de9d6ad176133312c6 \ No newline at end of file diff --git a/rage-0.11.0+0.tar.gz b/rage-0.11.0+0.tar.gz deleted file mode 100644 index 51ad530..0000000 --- a/rage-0.11.0+0.tar.gz +++ /dev/null @@ -1,3 +0,0 @@ -version https://git-lfs.github.com/spec/v1 -oid sha256:e5896b280a872d407b6bdd50dbc3324421a08177d094565e1a58ac5c603073b1 -size 1664647 diff --git a/rage-0.11.1+0.tar.gz b/rage-0.11.1+0.tar.gz new file mode 100644 index 0000000..61f2a0a --- /dev/null +++ b/rage-0.11.1+0.tar.gz @@ -0,0 +1,3 @@ +version https://git-lfs.github.com/spec/v1 +oid sha256:c393108b925c50b7e819f3af64025d054a4de0eb8d4dbb89ac4b734c2837cd2c +size 1666088 diff --git a/rage-encryption.changes b/rage-encryption.changes index 47efdf7..2359d2c 100644 --- a/rage-encryption.changes +++ b/rage-encryption.changes @@ -1,10 +1,23 @@ +------------------------------------------------------------------- +Fri Dec 20 06:39:30 UTC 2024 - Joshua Smith + +- Fixes GHSA-4fg7-vxc8-qx5w +- Update to version 0.11.1+0: + * Fixed a security vulnerability that could allow an attacker to + execute an arbitrary binary under certain conditions. Plugin + names are now required to only contain alphanumeric characters + or the four special characters +-._. + * Replace the test `NoCallbacks` with the library version + * Restrict set of valid characters for plugin names + * Add tests for invalid plugin name chars + ------------------------------------------------------------------- Sun Nov 3 19:04:23 UTC 2024 - Joshua Smith - Update to 0.11.0+0: Added: * Partial French translation! -Fixed: + Fixed: * [Unix] Files can now be encrypted with rage --passphrase when piped over stdin, without requiring an explicit - argument as INPUT. diff --git a/rage-encryption.spec b/rage-encryption.spec index 8bbc968..873b24d 100644 --- a/rage-encryption.spec +++ b/rage-encryption.spec @@ -20,7 +20,7 @@ Name: rage-encryption # This will be set by osc services, that will run after this. -Version: 0.11.0+0 +Version: 0.11.1+0 Release: 0 Summary: X25519-based, simple, modern, and secure file encryption tool # If you know the license, put it's SPDX string here. diff --git a/vendor.tar.zst b/vendor.tar.zst index 323fbbd..3ceb1a8 100644 --- a/vendor.tar.zst +++ b/vendor.tar.zst @@ -1,3 +1,3 @@ version https://git-lfs.github.com/spec/v1 -oid sha256:e159f7c24abc8e3525da96ff31290b404434241f9a6321db162bdb3086fdfd72 -size 28348059 +oid sha256:3434e8d3ecef00bac49d9e1b5ac35150ee0aae65fb35071c988195c4139fb76d +size 28376778