Script 'mail_helper' called by obssrc Hello community, here is the log from the commit of package apptainer for openSUSE:Factory checked in at 2026-02-11 18:49:26 ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Comparing /work/SRC/openSUSE:Factory/apptainer (Old) and /work/SRC/openSUSE:Factory/.apptainer.new.1670 (New) ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Package is "apptainer" Wed Feb 11 18:49:26 2026 rev:39 rq:1332454 version:1.4.5 Changes: -------- --- /work/SRC/openSUSE:Factory/apptainer/apptainer.changes 2026-01-07 16:03:12.819609744 +0100 +++ /work/SRC/openSUSE:Factory/.apptainer.new.1670/apptainer.changes 2026-02-11 18:51:16.499493862 +0100 @@ -1,0 +2,9 @@ +Tue Feb 10 10:04:31 UTC 2026 - Egbert Eich <[email protected]> + +- Fix HTML parser misimplementation of a part of the HTML + specification for table related tags (CVE-2025-58190, + GO-2026-4441, bsc#1258047). +- Fix issue where the HTML parser takes a very long time or + even never returns (CVE-2025-47911, GO-2026-4440, bsc#1258048). + +------------------------------------------------------------------- @@ -31 +40 @@ - * GO-2025-4134 - CVE-2025-58181 + * GO-2025-4134 - CVE-2025-58181 - bsc#1253924 ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Other differences: ------------------ ++++++ apptainer.spec ++++++ --- /var/tmp/diff_new_pack.zBCCyx/_old 2026-02-11 18:51:17.867551479 +0100 +++ /var/tmp/diff_new_pack.zBCCyx/_new 2026-02-11 18:51:17.875551816 +0100 @@ -46,6 +46,10 @@ BuildRequires: gcc BuildRequires: git BuildRequires: go >= 1.19 +%if 0%{?install_vulncheck:1} +BuildRequires: govulncheck +BuildRequires: govulncheck-vulndb +%endif BuildRequires: libseccomp-devel BuildRequires: libuuid-devel BuildRequires: make ++++++ _service ++++++ --- /var/tmp/diff_new_pack.zBCCyx/_old 2026-02-11 18:51:18.107561587 +0100 +++ /var/tmp/diff_new_pack.zBCCyx/_new 2026-02-11 18:51:18.123562262 +0100 @@ -4,7 +4,7 @@ golang.org/x/crypto=golang.org/x/[email protected] </param> <param name="replace"> - golang.org/x/net=golang.org/x/[email protected] + golang.org/x/net=golang.org/x/[email protected] </param> <param name="replace"> github.com/go-jose/go-jose/v4=github.com/go-jose/go-jose/[email protected] ++++++ vendor.tar.gz ++++++ /work/SRC/openSUSE:Factory/apptainer/vendor.tar.gz /work/SRC/openSUSE:Factory/.apptainer.new.1670/vendor.tar.gz differ: char 13, line 1
