Script 'mail_helper' called by obssrc Hello community, here is the log from the commit of package hauler for openSUSE:Factory checked in at 2026-04-28 11:57:41 ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Comparing /work/SRC/openSUSE:Factory/hauler (Old) and /work/SRC/openSUSE:Factory/.hauler.new.11940 (New) ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Package is "hauler" Tue Apr 28 11:57:41 2026 rev:14 rq:1349540 version:1.4.2 Changes: -------- --- /work/SRC/openSUSE:Factory/hauler/hauler.changes 2026-01-19 18:43:09.910620502 +0100 +++ /work/SRC/openSUSE:Factory/.hauler.new.11940/hauler.changes 2026-04-28 12:01:43.366851458 +0200 @@ -1,0 +2,26 @@ +Mon Apr 27 09:19:16 UTC 2026 - Dirk Müller <[email protected]> + +- update to 1.4.2 (bsc#1258614, CVE-2026-24122): + * Bump github.com/theupdateframework/go-tuf/v2 from 2.3.0 to + 2.3.1 in the go_modules group across 1 directory + * fix for new helm chart features + * Bump github.com/sigstore/rekor from 1.4.3 to 1.5.0 in the + go_modules group across 1 directory + * Bump github.com/sigstore/sigstore from 1.10.3 to 1.10.4 in + the go_modules group across 1 directory + * Bump github.com/theupdateframework/go-tuf/v2 from 2.3.1 to + 2.4.1 in the go_modules group across 1 directory + * update cosign fork to 3.0.4 plus dep tidy + * fix: Fix file:// dependency chart path resolution + * update github.com/olekukonko/tablewriter to v1.1.2 + * keep registry on image rewrite if not specified + * Bump github.com/theupdateframework/go-tuf/v2 from 2.3.1 to + 2.4.1 in the go_modules group across 1 directory + * fix: handling of file referenced dependencies without + repository field + * Bump go.opentelemetry.io/otel/sdk from 1.39.0 to 1.40.0 in + the go_modules group across 1 directory + * dev.md file + * smaller changes and updates for v1.4.2 release + +------------------------------------------------------------------- Old: ---- _servicedata hauler-1.4.1.tar.zst New: ---- hauler-1.4.2.tar.gz ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Other differences: ------------------ ++++++ hauler.spec ++++++ --- /var/tmp/diff_new_pack.NCd3hQ/_old 2026-04-28 12:01:44.226887086 +0200 +++ /var/tmp/diff_new_pack.NCd3hQ/_new 2026-04-28 12:01:44.226887086 +0200 @@ -17,20 +17,20 @@ Name: hauler -Version: 1.4.1 -%global git_commit 4a2b7b13a7a3e3dab926893c0be1a67dea6d8457 +Version: 1.4.2 +%global git_commit ebf91c122841b7f4fc4eb90b7af28d884dea678b Release: 0 Summary: Airgap Swiss Army Knife License: Apache-2.0 Group: System/Management -URL: https://github.com/rancherfederal/hauler -Source: %{name}-%{version}.tar.zst +URL: https://github.com/hauler-dev/hauler +Source: https://github.com/hauler-dev/hauler/archive/refs/tags/v%{version}.tar.gz#/hauler-%{version}.tar.gz Source1: vendor.tar.zst ExclusiveArch: x86_64 aarch64 BuildRequires: cosign BuildRequires: golang-packaging BuildRequires: zstd -BuildRequires: golang(API) = 1.25 +BuildRequires: golang(API) = 1.26 %description Rancher Government Hauler simplifies the airgap experience without requiring ++++++ _service ++++++ --- /var/tmp/diff_new_pack.NCd3hQ/_old 2026-04-28 12:01:44.258888411 +0200 +++ /var/tmp/diff_new_pack.NCd3hQ/_new 2026-04-28 12:01:44.262888577 +0200 @@ -1,19 +1,5 @@ <services> - <service name="tar_scm" mode="manual"> - <param name="url">https://github.com/rancherfederal/hauler</param> - <param name="scm">git</param> - <param name="revision">v1.4.1</param> - <param name="versionformat">@PARENT_TAG@</param> - <param name="versionrewrite-pattern">v(.*)</param> - <param name="changesgenerate">enable</param> - </service> - <service name="recompress" mode="manual"> - <param name="file">hauler-*.tar</param> - <param name="compression">zst</param> - </service> - <service name="set_version" mode="manual"> - <param name="basename">hauler</param> - </service> + <service name="download_files" mode="manual"/> <service name="go_modules" mode="manual"> <param name="compression">zst</param> </service> ++++++ vendor.tar.zst ++++++ /work/SRC/openSUSE:Factory/hauler/vendor.tar.zst /work/SRC/openSUSE:Factory/.hauler.new.11940/vendor.tar.zst differ: char 7, line 1
