From 4dcb2da4e3b320631cc8e09439b1441da48b11d7daed1c21415b71846bf883f8 Mon Sep 17 00:00:00 2001 From: Robert Frohl Date: Wed, 26 Nov 2025 12:58:07 +0100 Subject: [PATCH] Update submodules from pool/gitea-tea#1 and create patchinfo.20251126115642933537.93181000773252/_patchinfo --- gitea-tea | 2 +- .../_patchinfo | 86 +++++++++++++++++++ 2 files changed, 87 insertions(+), 1 deletion(-) create mode 100644 patchinfo.20251126115642933537.93181000773252/_patchinfo diff --git a/gitea-tea b/gitea-tea index 5496ef4..91324b6 160000 --- a/gitea-tea +++ b/gitea-tea @@ -1 +1 @@ -Subproject commit 5496ef4b747974707595886cd2f8eb3c24a2e1ddf794a41871eaf1d8e44685db +Subproject commit 91324b6042d32b3af7d390d903cb8385767a6f7c54a34914ec5b3b80999310f3 diff --git a/patchinfo.20251126115642933537.93181000773252/_patchinfo b/patchinfo.20251126115642933537.93181000773252/_patchinfo new file mode 100644 index 0000000..8faa7f7 --- /dev/null +++ b/patchinfo.20251126115642933537.93181000773252/_patchinfo @@ -0,0 +1,86 @@ + + VUL-0: CVE-2025-47911: gitea-tea: golang.org/x/net/html: various algorithms with quadratic complexity when parsing HTML documents + VUL-0: CVE-2025-58190: gitea-tea: golang.org/x/net/html: excessive memory consumption by `html.ParseFragment` when processing specially crafted input + cve#2025-58190 not resolved: 404 Client Error: Not Found for url: https://bugzilla.suse.com/api2/issues/?references__name=CVE-2025-58190 + cve#2025-47911 not resolved: 404 Client Error: Not Found for url: https://bugzilla.suse.com/api2/issues/?references__name=CVE-2025-47911 + olh + moderate + security + Security update for gitea-tea + This update for gitea-tea fixes the following issues: + +Changes in gitea-tea: + +- update to 0.11.1: + * 61d4e57 Fix Pr Create crash (#823) + * 4f33146 add test for matching logins (#820) + * 08b8398 Update README.md (#819) + +- CVE-2025-58190: golang.org/x/net/html: excessive memory consumption by `html.ParseFragment` when processing specially crafted input (boo#1251663) +- CVE-2025-47911: golang.org/x/net/html: various algorithms with quadratic complexity when parsing HTML documents (boo#1251471) + +- update to 0.11.0: + * Fix yaml output single quote (#814) + * generate man page (#811) + * feat: add validation for object-format flag in repo create + command (#741) + * Fix release version (#815) + * update gitea sdk to v0.22 (#813) + * don't fallback login directly (#806) + * Check duplicated login name in interact mode when creating new + login (#803) + * Fix bug when output json with special chars (#801) + * add debug mode and update readme (#805) + * update go.mod to retract the wrong tag v1.3.3 (#802) + * revert completion scripts removal (#808) + * Remove pagination from context (#807) + * Continue auth when failed to open browser (#794) + * Fix bug (#793) + * Fix tea login add with ssh public key bug (#789) + * Add temporary authentication via environment variables (#639) + * Fix attachment size (#787) + * deploy image when tagging (#792) + * Add Zip URL for release list (#788) + * Use bubbletea instead of survey for interacting with TUI (#786) + * capitalize a few items + * rm out of date comparison file + * README: Document logging in to gitea (#790) + * remove autocomplete command (#782) + * chore(deps): update ghcr.io/devcontainers/features/git-lfs + docker tag to v1.2.5 (#773) + * replace arch package url (#783) + * fix: Reenable -p and --limit switches (#778) + +- Update to 0.10.1+git.1757695903.cc20b52: + - feat: add validation for object-format flag in repo create + command (see gh#openSUSE/openSUSE-git#60) + - Fix release version + - update gitea sdk to v0.22 + - don't fallback login directly + - Check duplicated login name in interact mode when creating + new login + - Fix bug when output json with special chars + - add debug mode and update readme + - update go.mod to retract the wrong tag v1.3.3 + - revert completion scripts removal + - Remove pagination from context + - Continue auth when failed to open browser + - Fix bug + - Fix tea login add with ssh public key bug + - Add temporary authentication via environment variables + - Fix attachment size + - deploy image when tagging + - Add Zip URL for release list + - Use bubbletea instead of survey for interacting with TUI + - capitalize a few items + - rm out of date comparison file + - README: Document logging in to gitea + - remove autocomplete command + - chore(deps): update ghcr.io/devcontainers/features/git-lfs + docker tag to v1.2.5 + - replace arch package url + - fix: Reenable `-p` and `--limit` switches + + gitea-tea + + -- 2.51.1