Script 'mail_helper' called by obssrc Hello community, here is the log from the commit of package python-pillow-heif for openSUSE:Factory checked in at 2026-03-04 21:05:34 ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Comparing /work/SRC/openSUSE:Factory/python-pillow-heif (Old) and /work/SRC/openSUSE:Factory/.python-pillow-heif.new.561 (New) ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Package is "python-pillow-heif" Wed Mar 4 21:05:34 2026 rev:11 rq:1336314 version:1.3.0 Changes: -------- --- /work/SRC/openSUSE:Factory/python-pillow-heif/python-pillow-heif.changes 2026-01-30 18:34:00.687057304 +0100 +++ /work/SRC/openSUSE:Factory/.python-pillow-heif.new.561/python-pillow-heif.changes 2026-03-04 21:05:44.341725952 +0100 @@ -1,0 +2,10 @@ +Tue Mar 3 18:51:20 UTC 2026 - Dirk Müller <[email protected]> + +- update to 1.3.0 (bsc#1259172, CVE-2026-28231): + * Pixel aspect ratio (pasp) read/write support. #408 + * No-GIL (free-threaded Python) support. #405 + * Integer overflow in encode path buffer validation leading to + heap out-of-bounds read. (CVE-2026-28231, + GHSA-5gjj-6r7v-ph3x) + +------------------------------------------------------------------- Old: ---- python-pillow-heif-1.2.0.tar.gz New: ---- python-pillow-heif-1.3.0.tar.gz ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Other differences: ------------------ ++++++ python-pillow-heif.spec ++++++ --- /var/tmp/diff_new_pack.jUbLyE/_old 2026-03-04 21:05:44.977752231 +0100 +++ /var/tmp/diff_new_pack.jUbLyE/_new 2026-03-04 21:05:44.977752231 +0100 @@ -18,7 +18,7 @@ %define _name pillow_heif Name: python-pillow-heif -Version: 1.2.0 +Version: 1.3.0 Release: 0 Summary: Python interface for libheif library License: BSD-3-Clause ++++++ python-pillow-heif-1.2.0.tar.gz -> python-pillow-heif-1.3.0.tar.gz ++++++ /work/SRC/openSUSE:Factory/python-pillow-heif/python-pillow-heif-1.2.0.tar.gz /work/SRC/openSUSE:Factory/.python-pillow-heif.new.561/python-pillow-heif-1.3.0.tar.gz differ: char 13, line 1
