Script 'mail_helper' called by obssrc Hello community, here is the log from the commit of package traefik for openSUSE:Factory checked in at 2026-05-05 15:15:23 ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Comparing /work/SRC/openSUSE:Factory/traefik (Old) and /work/SRC/openSUSE:Factory/.traefik.new.30200 (New) ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Package is "traefik" Tue May 5 15:15:23 2026 rev:50 rq:1350760 version:3.6.15 Changes: -------- --- /work/SRC/openSUSE:Factory/traefik/traefik.changes 2026-03-27 16:54:00.234741888 +0100 +++ /work/SRC/openSUSE:Factory/.traefik.new.30200/traefik.changes 2026-05-05 15:16:41.614432968 +0200 @@ -1,0 +2,49 @@ +Mon May 4 15:29:06 UTC 2026 - Johannes Weberhofer <[email protected]> + +- Version 3.6.15 +- Bug fixes: + * acme + - Bump github.com/go-acme/lego/v4 to v4.35.2 + * k8s/ingress-nginx + - Do not require a port for ExternalName services + * middleware + - Add errorRequestHeaders option to Errors middleware + * server + - Bump github.com/vulcand/oxy to v2.1.0 + +- Version 3.6.14 +- CVE fixed: + CVE-2026-40912 (Advisory GHSA-6jwx-7vp4-9847) - boo#1263868 + CVE-2026-39858 (Advisory GHSA-5m6w-wvh7-57vm) - boo#1263867 + CVE-2026-35051 (Advisory GHSA-6384-m2mw-rf54) - boo#1263866 + CVE-2026-41263 (Advisory GHSA-6x2q-h3cr-8j2h) - boo#1263870 + CVE-2026-41174 (Advisory GHSA-xhjw-95fp-8vgq) - boo#1263869 + +- Updated go-jose to v4.1.4 which fixes CVE-2026-34986 - boo#1262982 + +- Bug fixes: + * acme + - Bump github.com/go-acme/lego/v4 to v4.34.0 + * docker + - Downgrade log level for missing container on inspect + * k8s/crd, k8s + - Honor allowCrossNamespace with chain middleware CRD + * middleware, authentication + - Cleanup and make ForwardAuth logs consistent + - Fix trustForwardHeader on forward auth middleware + - Remove map lookup making the basic auth notFoundSecret empty + * middleware + - Deprecate ForwardAuth.TrustForwardHeader option + - Remove untrusted X headers with underscores + - Sanitize the request URL after stripping the prefix + * sticky-session, k8s/crd + - Make SameSite cookie value case-insensitive + * webui + - Upgrade form-data to 2.5.4, 3.0.4, 4.0.4 + +- Version 3.6.13 +- Bug fixes: + * middleware + - Bump github.com/klauspost/compress v1.18.4 and fix TestNegotiation + +------------------------------------------------------------------- @@ -5 +54 @@ -- Bugs fixes: +- Bug fixes: @@ -30 +79 @@ -- Bugs fixes: +- Bug fixes: @@ -82 +131 @@ -- Bugs fixes: +- Bug fixes: Old: ---- traefik-v3.6.12.src.tar.gz New: ---- traefik-v3.6.15.src.tar.gz ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Other differences: ------------------ ++++++ traefik.spec ++++++ --- /var/tmp/diff_new_pack.wEjeAM/_old 2026-05-05 15:16:43.446508982 +0200 +++ /var/tmp/diff_new_pack.wEjeAM/_new 2026-05-05 15:16:43.450509148 +0200 @@ -23,7 +23,7 @@ %define buildmode pie %endif Name: traefik -Version: 3.6.12 +Version: 3.6.15 Release: 0 Summary: The Cloud Native Application Proxy License: MIT ++++++ traefik-v3.6.12.src.tar.gz -> traefik-v3.6.15.src.tar.gz ++++++ /work/SRC/openSUSE:Factory/traefik/traefik-v3.6.12.src.tar.gz /work/SRC/openSUSE:Factory/.traefik.new.30200/traefik-v3.6.15.src.tar.gz differ: char 13, line 1 ++++++ vendor.tar.gz ++++++ /work/SRC/openSUSE:Factory/traefik/vendor.tar.gz /work/SRC/openSUSE:Factory/.traefik.new.30200/vendor.tar.gz differ: char 14, line 1
