Script 'mail_helper' called by obssrc Hello community, here is the log from the commit of package alloy for openSUSE:Factory checked in at 2026-01-21 14:15:51 ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Comparing /work/SRC/openSUSE:Factory/alloy (Old) and /work/SRC/openSUSE:Factory/.alloy.new.1928 (New) ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Package is "alloy" Wed Jan 21 14:15:51 2026 rev:29 rq:1328321 version:1.12.2 Changes: -------- --- /work/SRC/openSUSE:Factory/alloy/alloy.changes 2026-01-19 18:42:20.528577264 +0100 +++ /work/SRC/openSUSE:Factory/.alloy.new.1928/alloy.changes 2026-01-21 14:16:01.463548991 +0100 @@ -1,0 +2,7 @@ +Mon Jan 19 14:55:10 UTC 2026 - Witek Bedyk <[email protected]> + +- CVE-2025-68156: Fix potential DoS via unbounded recursion in + builtin functions (bsc#1255333): + * Bump github.com/expr-lang/expr to version 1.17.7 + +------------------------------------------------------------------- @@ -55,0 +63,4 @@ + - CVE-2025-31133, CVE-2025-52565, and CVE-2025-52881: Update + github.com/opencontainers/runc to fix container breakouts by + bypassing runc's restrictions for writing to arbitrary /proc + files (bsc#1255074) ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Other differences: ------------------ ++++++ _service ++++++ --- /var/tmp/diff_new_pack.ykRCGw/_old 2026-01-21 14:16:05.779729585 +0100 +++ /var/tmp/diff_new_pack.ykRCGw/_new 2026-01-21 14:16:05.783729752 +0100 @@ -11,6 +11,7 @@ <service name="set_version" mode="manual"> </service> <service name="go_modules" mode="manual"> + <param name="replace">github.com/expr-lang/expr=github.com/expr-lang/[email protected]</param> </service> <!-- services below are running at buildtime --> <service name="tar" mode="buildtime"> ++++++ alloy-1.12.2.obscpio ++++++ ++++++ ui-1.12.2.tar.gz ++++++ /work/SRC/openSUSE:Factory/alloy/ui-1.12.2.tar.gz /work/SRC/openSUSE:Factory/.alloy.new.1928/ui-1.12.2.tar.gz differ: char 5, line 1 ++++++ vendor.tar.gz ++++++ /work/SRC/openSUSE:Factory/alloy/vendor.tar.gz /work/SRC/openSUSE:Factory/.alloy.new.1928/vendor.tar.gz differ: char 13, line 1
