Script 'mail_helper' called by obssrc Hello community, here is the log from the commit of package yt-dlp for openSUSE:Factory checked in at 2026-06-12 19:28:33 ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Comparing /work/SRC/openSUSE:Factory/yt-dlp (Old) and /work/SRC/openSUSE:Factory/.yt-dlp.new.1981 (New) ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Package is "yt-dlp" Fri Jun 12 19:28:33 2026 rev:91 rq:1358945 version:2026.06.09 Changes: -------- --- /work/SRC/openSUSE:Factory/yt-dlp/yt-dlp.changes 2026-03-18 16:51:51.968441302 +0100 +++ /work/SRC/openSUSE:Factory/.yt-dlp.new.1981/yt-dlp.changes 2026-06-12 19:29:48.407889076 +0200 @@ -1,0 +2,26 @@ +Fri Jun 12 09:06:35 UTC 2026 - Luigi Baldoni <[email protected]> + +- Update to version 2026.06.09 + * Fixed [CVE-2026-50019]: File Downloader cookie leak with curl + * Fixed [CVE-2026-50023]: Dangerous file type creation via + insufficient filename sanitization + * Fixed [CVE-2026-50574]: Arbitrary code execution via manifest + downloads with aria2c + * Added lockfile and pinned extras + * Removed url, desktop and webloc from safe extensions + * Extract supplemental codecs from DASH manifests + * abematv: Extract subtitles + * ard: Support new ardsounds domain + * monstercat: Support older URLs + * pornhub: Support browser impersonation + * reddit: Fix unauthenticated extraction + * rtp: Support multi-part episodes and --no-playlist + * s4c: Extract more metadata + * soop: Adapt extractors to new domain + * soundcloud: Support --extractor-retries for original formats + * twitch: Remove dead rechat subtitles + * twitter: Fix view_count extraction + * external: aria2c: Remove support for m3u8/dash protocols + * ffmpegmetadata: Avoid erroneous ISO 639 conversions + +------------------------------------------------------------------- ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Other differences: ------------------ ++++++ yt-dlp.spec ++++++ --- /var/tmp/diff_new_pack.Lrq07r/_old 2026-06-12 19:29:49.227922630 +0200 +++ /var/tmp/diff_new_pack.Lrq07r/_new 2026-06-12 19:29:49.231922794 +0200 @@ -27,7 +27,7 @@ %endif Name: yt-dlp -Version: 2026.03.17 +Version: 2026.06.09 %define ejsver 0.8.0 Release: 0 Summary: Enhanced fork of youtube-dl, a video site downloader for offline watching @@ -72,7 +72,7 @@ Summary: yt-dlp Python library Group: Development/Languages/Python Requires: ffmpeg -Recommends: (deno or nodejs >= 20 or quickjs >= 20250913) +Recommends: (deno >= 2.3.0 or nodejs >= 22 or quickjs >= 20250913) Suggests: python-Brotli Suggests: python-certifi Suggests: python-mutagen ++++++ _scmsync.obsinfo ++++++ --- /var/tmp/diff_new_pack.Lrq07r/_old 2026-06-12 19:29:49.267924267 +0200 +++ /var/tmp/diff_new_pack.Lrq07r/_new 2026-06-12 19:29:49.275924594 +0200 @@ -1,5 +1,5 @@ -mtime: 1773796113 -commit: d7051c00cd3ab6e41c8a6a8c63f651a5a526b1e7a05f0cf4a5f6c501fc25dadb +mtime: 1781257688 +commit: 62a1411978dbe73ec113bdd53dc444103474a24019f973a2e1d179094d98e45b url: https://src.opensuse.org/jengelh/yt-dlp revision: master ++++++ build.specials.obscpio ++++++ ++++++ build.specials.obscpio ++++++ diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/.gitignore new/.gitignore --- old/.gitignore 1970-01-01 01:00:00.000000000 +0100 +++ new/.gitignore 2026-06-12 11:48:08.000000000 +0200 @@ -0,0 +1 @@ +.osc ++++++ yt-dlp.tar.gz ++++++ ++++ 19361 lines of diff (skipped)
