Script 'mail_helper' called by obssrc Hello community, here is the log from the commit of package forgejo for openSUSE:Factory checked in at 2024-04-21 20:27:41 ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Comparing /work/SRC/openSUSE:Factory/forgejo (Old) and /work/SRC/openSUSE:Factory/.forgejo.new.26366 (New) ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Package is "forgejo" Sun Apr 21 20:27:41 2024 rev:3 rq:1169377 version:1.21.11+1 Changes: -------- --- /work/SRC/openSUSE:Factory/forgejo/forgejo.changes 2024-04-08 17:50:33.889905019 +0200 +++ /work/SRC/openSUSE:Factory/.forgejo.new.26366/forgejo.changes 2024-04-21 20:29:17.250339364 +0200 @@ -1,0 +2,21 @@ +Sat Apr 20 12:39:56 UTC 2024 - Richard Rahl <[email protected]> + +- update to 1.21.11-1: + * error 500 on tag creation when a workflow exists + +- update to 1.21.11-0: + * Fixed a privilege escalation through git push options that + allows any user to change the visibility of any repository they can see, + regardless of their level of access. + * Fixed a bug that allows user-supplied, non-sandboxed JavaScript to be run + from the same domain as the forge, via + /{owner}/{repo}/render/branch/{branch}/{filename} URLs. + * Close file in upload function + * Prevent registering runners for deleted repositories. + Prevents 500 Internal Server Error in admin interface. + * More reliable pagination support when migrating from gitbucket + * Fix automerge when used with actions + +- fix apparmor profile + +------------------------------------------------------------------- Old: ---- forgejo-src-1.21.10-0.tar.gz forgejo-src-1.21.10-0.tar.gz.asc New: ---- forgejo-src-1.21.11-1.tar.gz forgejo-src-1.21.11-1.tar.gz.asc ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Other differences: ------------------ ++++++ forgejo.spec ++++++ --- /var/tmp/diff_new_pack.8z3Sv1/_old 2024-04-21 20:29:19.794432763 +0200 +++ /var/tmp/diff_new_pack.8z3Sv1/_new 2024-04-21 20:29:19.794432763 +0200 @@ -16,8 +16,8 @@ # -%define gitea_version 1.21.10 -%define forgejo_version 0 +%define gitea_version 1.21.11 +%define forgejo_version 1 %if 0%{?suse_version} > 1600 # TW %bcond_without selinux @@ -180,10 +180,10 @@ %{_bindir}/%{name} %{_bindir}/gitea %defattr(0660,root,forgejo,770) -%config(noreplace) %{_sysconfdir}/%{name}/conf/app.ini -%{_sysconfdir}/%{name} %{_localstatedir}/log/%{name} %defattr(0660,forgejo,forgejo,750) +%config(noreplace) %{_sysconfdir}/%{name}/conf/app.ini +%{_sysconfdir}/%{name} %{_datadir}/%{name} %{_sharedstatedir}/%{name} %{_sysusersdir}/%{name}.conf ++++++ apparmor-usr.bin.forgejo ++++++ --- /var/tmp/diff_new_pack.8z3Sv1/_old 2024-04-21 20:29:19.834434231 +0200 +++ /var/tmp/diff_new_pack.8z3Sv1/_new 2024-04-21 20:29:19.838434378 +0200 @@ -73,9 +73,9 @@ # Ugly! /usr/share/forgejo/.gitconfig rw, /usr/share/forgejo/.gitconfig.lock rw, - /usr/share/forgejo/.ssh/ rw, - /usr/share/forgejo/.ssh/* rw, - /usr/share/forgejo/.local/** rw, + /var/lib/forgejo/.ssh/ rw, + /var/lib/forgejo/.ssh/* rw, + /var/lib/forgejo/.local/** rw, # for writing access log file /var/log/forgejo/ rw, ++++++ forgejo-src-1.21.10-0.tar.gz -> forgejo-src-1.21.11-1.tar.gz ++++++ /work/SRC/openSUSE:Factory/forgejo/forgejo-src-1.21.10-0.tar.gz /work/SRC/openSUSE:Factory/.forgejo.new.26366/forgejo-src-1.21.11-1.tar.gz differ: char 111, line 1 ++++++ get-sources.sh ++++++ --- /var/tmp/diff_new_pack.8z3Sv1/_old 2024-04-21 20:29:19.942438196 +0200 +++ /var/tmp/diff_new_pack.8z3Sv1/_new 2024-04-21 20:29:19.946438343 +0200 @@ -20,8 +20,8 @@ echo "extracting package-lock.json" echo "++++++++++++++++++++++++++++++++++++++++++++++" -tar xf forgejo-src-${VERSION}-0.tar.gz forgejo-src-${VERSION}-0/package-lock.json -cp forgejo-src-${VERSION}-0/package-lock.json . +tar xf forgejo-src-${VERSION}-1.tar.gz forgejo-src-${VERSION}-1/package-lock.json +cp forgejo-src-${VERSION}-1/package-lock.json . echo "++++++++++++++++++++++++++++++++++++++++++++++" echo "Downloading node_modules" @@ -33,7 +33,7 @@ echo "Cleanup Step" echo "++++++++++++++++++++++++++++++++++++++++++++++" -rm -r forgejo-src-${VERSION}-0 +rm -r forgejo-src-${VERSION}-1 rm node_modules.sums echo "++++++++++++++++++++++++++++++++++++++++++++++"
