Script 'mail_helper' called by obssrc Hello community, here is the log from the commit of package grype for openSUSE:Factory checked in at 2025-06-11 16:24:33 ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Comparing /work/SRC/openSUSE:Factory/grype (Old) and /work/SRC/openSUSE:Factory/.grype.new.19631 (New) ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Package is "grype" Wed Jun 11 16:24:33 2025 rev:92 rq:1284591 version:0.93.0 Changes: -------- --- /work/SRC/openSUSE:Factory/grype/grype.changes 2025-05-22 16:55:56.923574522 +0200 +++ /work/SRC/openSUSE:Factory/.grype.new.19631/grype.changes 2025-06-11 16:26:32.812525762 +0200 @@ -1,0 +2,44 @@ +Wed Jun 11 04:33:31 UTC 2025 - Johannes Kastl <opensuse_buildserv...@ojkastl.de> + +- Update to version 0.93.0: + * Added Features + - Add support for MinimOS [#2627 @Daniel-Wachter] + - Use the upstream Bitmani vulndb data for matching [#1609 + #2538 @juan131] + - Support rubygems specific version comparision [#2646 #2712 + @willmurphyscode] + * Bug Fixes + - Harden Container Runtime with Non-Root User [#2716 + @wagoodman] + - valid cpes in db search output [#2706 @westonsteimel] + - Always show results with json output for db search commands + [#2692 @wagoodman] + - False positive: CVE-2025-5702 reported with High severity on + glibc 2.34 (wrong severity and affected version) [#2718] + * Dependencies + - chore(deps): update anchore dependencies (#2719) + - chore(deps): update tools to latest versions (#2717) + - chore(deps): bump golang.org/x/tools from 0.33.0 to 0.34.0 + (#2713) + - chore(deps): bump github.com/sergi/go-diff (#2714) + - chore(deps): bump github.com/gkampitakis/go-snaps from 0.5.12 + to 0.5.13 (#2708) + - chore(deps): bump golang.org/x/time from 0.11.0 to 0.12.0 + (#2709) + - chore(deps): bump github/codeql-action from 3.28.18 to + 3.28.19 (#2704) + - chore(deps): update tools to latest versions (#2696) + - chore(deps): bump ossf/scorecard-action from 2.4.1 to 2.4.2 + (#2703) + - chore(deps): bump github.com/docker/docker (#2702) + - chore(deps): bump github.com/gkampitakis/go-snaps from 0.5.11 + to 0.5.12 (#2693) + - chore(deps): bump github.com/docker/docker (#2694) + - chore(deps): update tools to latest versions (#2679) + - chore(deps): bump github.com/google/go-containerregistry + (#2681) + - chore(deps): bump gorm.io/gorm from 1.26.1 to 1.30.0 (#2687) + - chore(deps): bump github.com/anchore/syft from 1.26.0 to + 1.26.1 (#2678) + +------------------------------------------------------------------- Old: ---- grype-0.92.2.obscpio New: ---- grype-0.93.0.obscpio ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Other differences: ------------------ ++++++ grype.spec ++++++ --- /var/tmp/diff_new_pack.pVNHi2/_old 2025-06-11 16:26:35.576641066 +0200 +++ /var/tmp/diff_new_pack.pVNHi2/_new 2025-06-11 16:26:35.576641066 +0200 @@ -17,7 +17,7 @@ Name: grype -Version: 0.92.2 +Version: 0.93.0 Release: 0 Summary: A vulnerability scanner for container images and filesystems License: Apache-2.0 ++++++ _service ++++++ --- /var/tmp/diff_new_pack.pVNHi2/_old 2025-06-11 16:26:35.608642401 +0200 +++ /var/tmp/diff_new_pack.pVNHi2/_new 2025-06-11 16:26:35.612642568 +0200 @@ -3,7 +3,7 @@ <param name="url">https://github.com/anchore/grype</param> <param name="scm">git</param> <param name="exclude">.git</param> - <param name="revision">v0.92.2</param> + <param name="revision">v0.93.0</param> <param name="match-tag">v*</param> <param name="versionformat">@PARENT_TAG@</param> <param name="versionrewrite-pattern">v(.*)</param> ++++++ _servicedata ++++++ --- /var/tmp/diff_new_pack.pVNHi2/_old 2025-06-11 16:26:35.632643402 +0200 +++ /var/tmp/diff_new_pack.pVNHi2/_new 2025-06-11 16:26:35.632643402 +0200 @@ -1,6 +1,6 @@ <servicedata> <service name="tar_scm"> <param name="url">https://github.com/anchore/grype</param> - <param name="changesrevision">3f52c46d440ac17b2924c633826ce8fd30a5e16d</param></service></servicedata> + <param name="changesrevision">c4acc50c1a739140d245cf39a298b1cac7920261</param></service></servicedata> (No newline at EOF) ++++++ grype-0.92.2.obscpio -> grype-0.93.0.obscpio ++++++ ++++ 17926 lines of diff (skipped) ++++++ grype.obsinfo ++++++ --- /var/tmp/diff_new_pack.pVNHi2/_old 2025-06-11 16:26:39.076787073 +0200 +++ /var/tmp/diff_new_pack.pVNHi2/_new 2025-06-11 16:26:39.080787240 +0200 @@ -1,5 +1,5 @@ name: grype -version: 0.92.2 -mtime: 1747779150 -commit: 3f52c46d440ac17b2924c633826ce8fd30a5e16d +version: 0.93.0 +mtime: 1749498183 +commit: c4acc50c1a739140d245cf39a298b1cac7920261 ++++++ vendor.tar.gz ++++++ /work/SRC/openSUSE:Factory/grype/vendor.tar.gz /work/SRC/openSUSE:Factory/.grype.new.19631/vendor.tar.gz differ: char 14, line 1