Script 'mail_helper' called by obssrc
Hello community,

here is the log from the commit of package firefox-esr for openSUSE:Factory 
checked in at 2026-07-22 19:01:53
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Comparing /work/SRC/openSUSE:Factory/firefox-esr (Old)
 and      /work/SRC/openSUSE:Factory/.firefox-esr.new.24530 (New)
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Package is "firefox-esr"

Wed Jul 22 19:01:53 2026 rev:39 rq:1366995 version:140.13.0

Changes:
--------
--- /work/SRC/openSUSE:Factory/firefox-esr/MozillaFirefox.changes       
2026-06-28 21:11:19.627782630 +0200
+++ /work/SRC/openSUSE:Factory/.firefox-esr.new.24530/MozillaFirefox.changes    
2026-07-22 19:02:11.455054280 +0200
@@ -1,0 +2,118 @@
+Tue Jul 21 12:54:27 UTC 2026 - Manfred Hollstein <[email protected]>
+
+- Firefox Extended Support Release 140.13.0 ESR
+  * Fixed: Various security fixes.
+- Mozilla Firefox ESR 140.13.0
+  https://www.mozilla.org/security/advisories/mfsa2026-70
+  MFSA 2026-70 (boo#1271649)
+  * CVE-2026-15718 (bmo#2045443)
+    Invalid pointer in the JavaScript: WebAssembly component
+  * CVE-2026-15719 (bmo#2043820)
+    Site isolation issue in the DOM: Navigation component
+  * CVE-2026-16349 (bmo#2034682)
+    Same-origin policy bypass in the DOM: Navigation component
+  * CVE-2026-16350 (bmo#2042033)
+    Incorrect boundary conditions in the Audio/Video: cubeb
+    component
+  * CVE-2026-16362 (bmo#2043188)
+    Use-after-free in the WebRTC: Audio/Video component
+  * CVE-2026-16351 (bmo#2045468)
+    Sandbox escape due to use-after-free in the DOM: Navigation
+    component
+  * CVE-2026-16352 (bmo#2046416)
+    Sandbox escape due to use-after-free in the Disability Access
+    APIs component
+  * CVE-2026-16363 (bmo#2047689)
+    JIT miscompilation in the JavaScript: WebAssembly component
+  * CVE-2026-16353 (bmo#2049523)
+    Invalid pointer in the DOM: Bindings (WebIDL) component
+  * CVE-2026-16354 (bmo#2050626)
+    Information disclosure in the Graphics: ImageLib component
+  * CVE-2026-16368 (bmo#2051015)
+    Incorrect boundary conditions in the JavaScript: WebAssembly
+    component
+  * CVE-2026-16369 (bmo#2051854)
+    Integer overflow in the JavaScript: WebAssembly component
+  * CVE-2026-16355 (bmo#2052207)
+    JIT miscompilation in the JavaScript Engine: JIT component
+  * CVE-2026-16356 (bmo#2052562)
+    Sandbox escape due to use-after-free in the Disability Access
+    APIs component
+  * CVE-2026-16357 (bmo#2053326)
+    Incorrect boundary conditions in the Graphics component
+  * CVE-2026-16371 (bmo#2008369)
+    Privilege escalation in the DOM: Navigation component
+  * CVE-2026-16374 (bmo#2027519)
+    Information disclosure in the Framework component in DevTools
+  * CVE-2026-16375 (bmo#2032140)
+    Site isolation issue in the Networking: HTTP component
+  * CVE-2026-16377 (bmo#2037770)
+    Mitigation bypass in the PDF Viewer component
+  * CVE-2026-16379 (bmo#2039452)
+    Privilege escalation in the DOM: Content Processes component
+  * CVE-2026-16358 (bmo#2040119)
+    Site isolation issue in the Graphics: WebRender component
+  * CVE-2026-16381 (bmo#2041001)
+    Same-origin policy bypass in the Networking: DNS component
+  * CVE-2026-16383 (bmo#2041902)
+    Mitigation bypass in the DOM: Networking component
+  * CVE-2026-16387 (bmo#2043200)
+    Site isolation issue in the Networking component
+  * CVE-2026-16390 (bmo#2044527)
+    Mitigation bypass in the Enterprise Policies component
+  * CVE-2026-16391 (bmo#2044536)
+    Information disclosure in the Storage: IndexedDB component
+  * CVE-2026-16359 (bmo#2045424)
+    Incorrect boundary conditions in the Audio/Video: GMP
+    component
+  * CVE-2026-16396 (bmo#2047240)
+    Privilege escalation in WebExtensions
+  * CVE-2026-16405 (bmo#2036591)
+    Information disclosure in the Networking: WebSockets
+    component
+  * CVE-2026-16412 (bmo#2005113, bmo#2025369, bmo#2026301,
+    bmo#2028663, bmo#2029761, bmo#2042242, bmo#2043035,
+    bmo#2043271, bmo#2043300, bmo#2044612, bmo#2045057,
+    bmo#2045187, bmo#2045378, bmo#2045402, bmo#2045406,
+    bmo#2045407, bmo#2045413, bmo#2045417, bmo#2045482,
+    bmo#2045611, bmo#2045616, bmo#2045618, bmo#2045626,
+    bmo#2045730, bmo#2045732, bmo#2045756, bmo#2045769,
+    bmo#2045771, bmo#2046917, bmo#2047718, bmo#2047957,
+    bmo#2048934, bmo#2049818, bmo#2049822, bmo#2050151,
+    bmo#2050368, bmo#2051653, bmo#2051658, bmo#2053635,
+    bmo#2053637)
+    Memory safety bugs fixed in Firefox ESR 140.13 and Firefox
+    153
+  * CVE-2026-16360 (bmo#2022635, bmo#2028004, bmo#2035756,
+    bmo#2043739, bmo#2045184, bmo#2045185, bmo#2045198,
+    bmo#2045281, bmo#2045392, bmo#2045395, bmo#2045396,
+    bmo#2045397, bmo#2045405, bmo#2045414, bmo#2045415,
+    bmo#2045451, bmo#2045454, bmo#2045508, bmo#2045510,
+    bmo#2045513, bmo#2045515, bmo#2045518, bmo#2045604,
+    bmo#2045607, bmo#2045612, bmo#2045614, bmo#2045617,
+    bmo#2045619, bmo#2045624, bmo#2045625, bmo#2045729,
+    bmo#2045737, bmo#2045741, bmo#2045742, bmo#2045744,
+    bmo#2045763, bmo#2045767, bmo#2045770, bmo#2045772,
+    bmo#2045773, bmo#2045775, bmo#2045783, bmo#2045833,
+    bmo#2045848, bmo#2045865, bmo#2045875, bmo#2045957,
+    bmo#2047719, bmo#2047723, bmo#2047729, bmo#2048795,
+    bmo#2048799, bmo#2048801, bmo#2049392, bmo#2049397,
+    bmo#2049398, bmo#2049399, bmo#2049404, bmo#2049405,
+    bmo#2049407, bmo#2049805, bmo#2049812, bmo#2050657,
+    bmo#2050668, bmo#2050990, bmo#2051666, bmo#2053166,
+    bmo#2053273, bmo#2053576, bmo#2053583, bmo#2053587)
+    Memory safety bugs fixed in Firefox ESR 115.38, Firefox ESR
+    140.13 and Firefox 153
+  * CVE-2026-16361 (bmo#2029734, bmo#2036518)
+    Memory safety bugs fixed in Firefox ESR 115.38 and Firefox
+    ESR 140.13
+- Remove obsolete mozilla-bmo1746799.patch
+- Depend on the new transitional package rust-cbindgen-0_29_2
+
+-------------------------------------------------------------------
+Mon Jul 13 19:17:56 UTC 2026 - Manfred Hollstein <[email protected]>
+
+- Guard the "desktop file" actions to be run only on real Factory,
+  Slowroll or Tumbleweed builds, ie. suse_version >= 1699.
+
+-------------------------------------------------------------------
firefox-esr.changes: same change

Old:
----
  firefox-140.12.0esr.source.tar.xz
  firefox-140.12.0esr.source.tar.xz.asc
  l10n-140.12.0esr.tar.xz
  mozilla-bmo1746799.patch

New:
----
  firefox-140.13.0esr.source.tar.xz
  firefox-140.13.0esr.source.tar.xz.asc
  l10n-140.13.0esr.tar.xz

----------(Old B)----------
  Old:/work/SRC/openSUSE:Factory/.firefox-esr.new.24530/MozillaFirefox.changes- 
   ESR 140.13
/work/SRC/openSUSE:Factory/.firefox-esr.new.24530/MozillaFirefox.changes:- 
Remove obsolete mozilla-bmo1746799.patch
/work/SRC/openSUSE:Factory/.firefox-esr.new.24530/MozillaFirefox.changes-- 
Depend on the new transitional package rust-cbindgen-0_29_2
--
/work/SRC/openSUSE:Factory/.firefox-esr.new.24530/firefox-esr.changes-    ESR 
140.13
/work/SRC/openSUSE:Factory/.firefox-esr.new.24530/firefox-esr.changes:- Remove 
obsolete mozilla-bmo1746799.patch
/work/SRC/openSUSE:Factory/.firefox-esr.new.24530/firefox-esr.changes-- Depend 
on the new transitional package rust-cbindgen-0_29_2
----------(Old E)----------

++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Other differences:
------------------
++++++ firefox-esr.spec ++++++
--- /var/tmp/diff_new_pack.H2Z0u2/_old  2026-07-22 19:02:33.063794090 +0200
+++ /var/tmp/diff_new_pack.H2Z0u2/_new  2026-07-22 19:02:33.067794227 +0200
@@ -17,7 +17,7 @@
 #
 
 # either firefox-esr or MozillaFirefox
-%if 0%{?suse_version} > 1549
+%if 0%{?suse_version} >= 1699
 # On Tumbleweed this package is always called firefox-esr
 %define pkgname  firefox-esr
 %else
@@ -41,8 +41,8 @@
 # major 69
 # mainver %%major.99
 %define major          140
-%define mainver        %major.12.0
-%define orig_version   140.12.0
+%define mainver        %major.13.0
+%define orig_version   140.13.0
 %define orig_suffix    esr
 %define update_channel esr
 %define branding       1
@@ -155,8 +155,8 @@
 BuildRequires:  python3-devel
 %endif
 %endif
-BuildRequires:  rust-cbindgen >= 0.28
-%if 0%{?suse_version} > 1600
+BuildRequires:  rust-cbindgen-0_29_2
+%if 0%{?suse_version} >= 1699
 BuildRequires:  translate-suse-desktop
 %endif
 BuildRequires:  unzip
@@ -248,7 +248,6 @@
 Patch19:        mozilla-bmo531915.patch
 Patch20:        one_swizzle_to_rule_them_all.patch
 Patch21:        svg-rendering.patch
-Patch24:        mozilla-bmo1746799.patch
 Patch26:        mozilla-bmo1999625.patch
 Patch27:        mozilla-bmo2016618.patch
 Patch28:        mozilla-bmo2048250.patch
@@ -361,7 +360,7 @@
 %else
 %setup -q -n %{srcname}-%{orig_version}
 %endif
-%if 0%{?suse_version} > 1600
+%if 0%{?suse_version} >= 1699
 cp %{SOURCE1} %{desktop_file_name}.desktop.in.in
 %else
 cp %{SOURCE5} %{desktop_file_name}.desktop
@@ -372,7 +371,7 @@
 
 %build
 # desktop file
-%if 0%{?suse_version} > 1600
+%if 0%{?suse_version} >= 1699
 sed "s:%%NAME:%{appname}:g
 s:%%EXEC:%{progname}:g
 s:%%ICON:%{progname}:g

++++++ MozillaFirefox.changes.txt ++++++
--- /var/tmp/diff_new_pack.H2Z0u2/_old  2026-07-22 19:02:33.235799979 +0200
+++ /var/tmp/diff_new_pack.H2Z0u2/_new  2026-07-22 19:02:33.243800253 +0200
@@ -1,4 +1,122 @@
 -------------------------------------------------------------------
+Tue Jul 21 12:54:27 UTC 2026 - Manfred Hollstein <[email protected]>
+
+- Firefox Extended Support Release 140.13.0 ESR
+  * Fixed: Various security fixes.
+- Mozilla Firefox ESR 140.13.0
+  https://www.mozilla.org/security/advisories/mfsa2026-70
+  MFSA 2026-70 (boo#1271649)
+  * CVE-2026-15718 (bmo#2045443)
+    Invalid pointer in the JavaScript: WebAssembly component
+  * CVE-2026-15719 (bmo#2043820)
+    Site isolation issue in the DOM: Navigation component
+  * CVE-2026-16349 (bmo#2034682)
+    Same-origin policy bypass in the DOM: Navigation component
+  * CVE-2026-16350 (bmo#2042033)
+    Incorrect boundary conditions in the Audio/Video: cubeb
+    component
+  * CVE-2026-16362 (bmo#2043188)
+    Use-after-free in the WebRTC: Audio/Video component
+  * CVE-2026-16351 (bmo#2045468)
+    Sandbox escape due to use-after-free in the DOM: Navigation
+    component
+  * CVE-2026-16352 (bmo#2046416)
+    Sandbox escape due to use-after-free in the Disability Access
+    APIs component
+  * CVE-2026-16363 (bmo#2047689)
+    JIT miscompilation in the JavaScript: WebAssembly component
+  * CVE-2026-16353 (bmo#2049523)
+    Invalid pointer in the DOM: Bindings (WebIDL) component
+  * CVE-2026-16354 (bmo#2050626)
+    Information disclosure in the Graphics: ImageLib component
+  * CVE-2026-16368 (bmo#2051015)
+    Incorrect boundary conditions in the JavaScript: WebAssembly
+    component
+  * CVE-2026-16369 (bmo#2051854)
+    Integer overflow in the JavaScript: WebAssembly component
+  * CVE-2026-16355 (bmo#2052207)
+    JIT miscompilation in the JavaScript Engine: JIT component
+  * CVE-2026-16356 (bmo#2052562)
+    Sandbox escape due to use-after-free in the Disability Access
+    APIs component
+  * CVE-2026-16357 (bmo#2053326)
+    Incorrect boundary conditions in the Graphics component
+  * CVE-2026-16371 (bmo#2008369)
+    Privilege escalation in the DOM: Navigation component
+  * CVE-2026-16374 (bmo#2027519)
+    Information disclosure in the Framework component in DevTools
+  * CVE-2026-16375 (bmo#2032140)
+    Site isolation issue in the Networking: HTTP component
+  * CVE-2026-16377 (bmo#2037770)
+    Mitigation bypass in the PDF Viewer component
+  * CVE-2026-16379 (bmo#2039452)
+    Privilege escalation in the DOM: Content Processes component
+  * CVE-2026-16358 (bmo#2040119)
+    Site isolation issue in the Graphics: WebRender component
+  * CVE-2026-16381 (bmo#2041001)
+    Same-origin policy bypass in the Networking: DNS component
+  * CVE-2026-16383 (bmo#2041902)
+    Mitigation bypass in the DOM: Networking component
+  * CVE-2026-16387 (bmo#2043200)
+    Site isolation issue in the Networking component
+  * CVE-2026-16390 (bmo#2044527)
+    Mitigation bypass in the Enterprise Policies component
+  * CVE-2026-16391 (bmo#2044536)
+    Information disclosure in the Storage: IndexedDB component
+  * CVE-2026-16359 (bmo#2045424)
+    Incorrect boundary conditions in the Audio/Video: GMP
+    component
+  * CVE-2026-16396 (bmo#2047240)
+    Privilege escalation in WebExtensions
+  * CVE-2026-16405 (bmo#2036591)
+    Information disclosure in the Networking: WebSockets
+    component
+  * CVE-2026-16412 (bmo#2005113, bmo#2025369, bmo#2026301,
+    bmo#2028663, bmo#2029761, bmo#2042242, bmo#2043035,
+    bmo#2043271, bmo#2043300, bmo#2044612, bmo#2045057,
+    bmo#2045187, bmo#2045378, bmo#2045402, bmo#2045406,
+    bmo#2045407, bmo#2045413, bmo#2045417, bmo#2045482,
+    bmo#2045611, bmo#2045616, bmo#2045618, bmo#2045626,
+    bmo#2045730, bmo#2045732, bmo#2045756, bmo#2045769,
+    bmo#2045771, bmo#2046917, bmo#2047718, bmo#2047957,
+    bmo#2048934, bmo#2049818, bmo#2049822, bmo#2050151,
+    bmo#2050368, bmo#2051653, bmo#2051658, bmo#2053635,
+    bmo#2053637)
+    Memory safety bugs fixed in Firefox ESR 140.13 and Firefox
+    153
+  * CVE-2026-16360 (bmo#2022635, bmo#2028004, bmo#2035756,
+    bmo#2043739, bmo#2045184, bmo#2045185, bmo#2045198,
+    bmo#2045281, bmo#2045392, bmo#2045395, bmo#2045396,
+    bmo#2045397, bmo#2045405, bmo#2045414, bmo#2045415,
+    bmo#2045451, bmo#2045454, bmo#2045508, bmo#2045510,
+    bmo#2045513, bmo#2045515, bmo#2045518, bmo#2045604,
+    bmo#2045607, bmo#2045612, bmo#2045614, bmo#2045617,
+    bmo#2045619, bmo#2045624, bmo#2045625, bmo#2045729,
+    bmo#2045737, bmo#2045741, bmo#2045742, bmo#2045744,
+    bmo#2045763, bmo#2045767, bmo#2045770, bmo#2045772,
+    bmo#2045773, bmo#2045775, bmo#2045783, bmo#2045833,
+    bmo#2045848, bmo#2045865, bmo#2045875, bmo#2045957,
+    bmo#2047719, bmo#2047723, bmo#2047729, bmo#2048795,
+    bmo#2048799, bmo#2048801, bmo#2049392, bmo#2049397,
+    bmo#2049398, bmo#2049399, bmo#2049404, bmo#2049405,
+    bmo#2049407, bmo#2049805, bmo#2049812, bmo#2050657,
+    bmo#2050668, bmo#2050990, bmo#2051666, bmo#2053166,
+    bmo#2053273, bmo#2053576, bmo#2053583, bmo#2053587)
+    Memory safety bugs fixed in Firefox ESR 115.38, Firefox ESR
+    140.13 and Firefox 153
+  * CVE-2026-16361 (bmo#2029734, bmo#2036518)
+    Memory safety bugs fixed in Firefox ESR 115.38 and Firefox
+    ESR 140.13
+- Remove obsolete mozilla-bmo1746799.patch
+- Depend on the new transitional package rust-cbindgen-0_29_2
+
+-------------------------------------------------------------------
+Mon Jul 13 19:17:56 UTC 2026 - Manfred Hollstein <[email protected]>
+
+- Guard the "desktop file" actions to be run only on real Factory,
+  Slowroll or Tumbleweed builds, ie. suse_version >= 1699.
+
+-------------------------------------------------------------------
 Sun Jun 28 08:13:29 UTC 2026 - Manfred Hollstein <[email protected]>
 
 - Reformat the patch against current Firefox ESR 140.12.0 and add

++++++ firefox-140.12.0esr.source.tar.xz -> firefox-140.13.0esr.source.tar.xz 
++++++
/work/SRC/openSUSE:Factory/firefox-esr/firefox-140.12.0esr.source.tar.xz 
/work/SRC/openSUSE:Factory/.firefox-esr.new.24530/firefox-140.13.0esr.source.tar.xz
 differ: char 15, line 1

++++++ firefox-esr.changes.txt ++++++
--- /var/tmp/diff_new_pack.H2Z0u2/_old  2026-07-22 19:02:33.403805731 +0200
+++ /var/tmp/diff_new_pack.H2Z0u2/_new  2026-07-22 19:02:33.411806005 +0200
@@ -1,4 +1,122 @@
 -------------------------------------------------------------------
+Tue Jul 21 12:54:27 UTC 2026 - Manfred Hollstein <[email protected]>
+
+- Firefox Extended Support Release 140.13.0 ESR
+  * Fixed: Various security fixes.
+- Mozilla Firefox ESR 140.13.0
+  https://www.mozilla.org/security/advisories/mfsa2026-70
+  MFSA 2026-70 (boo#1271649)
+  * CVE-2026-15718 (bmo#2045443)
+    Invalid pointer in the JavaScript: WebAssembly component
+  * CVE-2026-15719 (bmo#2043820)
+    Site isolation issue in the DOM: Navigation component
+  * CVE-2026-16349 (bmo#2034682)
+    Same-origin policy bypass in the DOM: Navigation component
+  * CVE-2026-16350 (bmo#2042033)
+    Incorrect boundary conditions in the Audio/Video: cubeb
+    component
+  * CVE-2026-16362 (bmo#2043188)
+    Use-after-free in the WebRTC: Audio/Video component
+  * CVE-2026-16351 (bmo#2045468)
+    Sandbox escape due to use-after-free in the DOM: Navigation
+    component
+  * CVE-2026-16352 (bmo#2046416)
+    Sandbox escape due to use-after-free in the Disability Access
+    APIs component
+  * CVE-2026-16363 (bmo#2047689)
+    JIT miscompilation in the JavaScript: WebAssembly component
+  * CVE-2026-16353 (bmo#2049523)
+    Invalid pointer in the DOM: Bindings (WebIDL) component
+  * CVE-2026-16354 (bmo#2050626)
+    Information disclosure in the Graphics: ImageLib component
+  * CVE-2026-16368 (bmo#2051015)
+    Incorrect boundary conditions in the JavaScript: WebAssembly
+    component
+  * CVE-2026-16369 (bmo#2051854)
+    Integer overflow in the JavaScript: WebAssembly component
+  * CVE-2026-16355 (bmo#2052207)
+    JIT miscompilation in the JavaScript Engine: JIT component
+  * CVE-2026-16356 (bmo#2052562)
+    Sandbox escape due to use-after-free in the Disability Access
+    APIs component
+  * CVE-2026-16357 (bmo#2053326)
+    Incorrect boundary conditions in the Graphics component
+  * CVE-2026-16371 (bmo#2008369)
+    Privilege escalation in the DOM: Navigation component
+  * CVE-2026-16374 (bmo#2027519)
+    Information disclosure in the Framework component in DevTools
+  * CVE-2026-16375 (bmo#2032140)
+    Site isolation issue in the Networking: HTTP component
+  * CVE-2026-16377 (bmo#2037770)
+    Mitigation bypass in the PDF Viewer component
+  * CVE-2026-16379 (bmo#2039452)
+    Privilege escalation in the DOM: Content Processes component
+  * CVE-2026-16358 (bmo#2040119)
+    Site isolation issue in the Graphics: WebRender component
+  * CVE-2026-16381 (bmo#2041001)
+    Same-origin policy bypass in the Networking: DNS component
+  * CVE-2026-16383 (bmo#2041902)
+    Mitigation bypass in the DOM: Networking component
+  * CVE-2026-16387 (bmo#2043200)
+    Site isolation issue in the Networking component
+  * CVE-2026-16390 (bmo#2044527)
+    Mitigation bypass in the Enterprise Policies component
+  * CVE-2026-16391 (bmo#2044536)
+    Information disclosure in the Storage: IndexedDB component
+  * CVE-2026-16359 (bmo#2045424)
+    Incorrect boundary conditions in the Audio/Video: GMP
+    component
+  * CVE-2026-16396 (bmo#2047240)
+    Privilege escalation in WebExtensions
+  * CVE-2026-16405 (bmo#2036591)
+    Information disclosure in the Networking: WebSockets
+    component
+  * CVE-2026-16412 (bmo#2005113, bmo#2025369, bmo#2026301,
+    bmo#2028663, bmo#2029761, bmo#2042242, bmo#2043035,
+    bmo#2043271, bmo#2043300, bmo#2044612, bmo#2045057,
+    bmo#2045187, bmo#2045378, bmo#2045402, bmo#2045406,
+    bmo#2045407, bmo#2045413, bmo#2045417, bmo#2045482,
+    bmo#2045611, bmo#2045616, bmo#2045618, bmo#2045626,
+    bmo#2045730, bmo#2045732, bmo#2045756, bmo#2045769,
+    bmo#2045771, bmo#2046917, bmo#2047718, bmo#2047957,
+    bmo#2048934, bmo#2049818, bmo#2049822, bmo#2050151,
+    bmo#2050368, bmo#2051653, bmo#2051658, bmo#2053635,
+    bmo#2053637)
+    Memory safety bugs fixed in Firefox ESR 140.13 and Firefox
+    153
+  * CVE-2026-16360 (bmo#2022635, bmo#2028004, bmo#2035756,
+    bmo#2043739, bmo#2045184, bmo#2045185, bmo#2045198,
+    bmo#2045281, bmo#2045392, bmo#2045395, bmo#2045396,
+    bmo#2045397, bmo#2045405, bmo#2045414, bmo#2045415,
+    bmo#2045451, bmo#2045454, bmo#2045508, bmo#2045510,
+    bmo#2045513, bmo#2045515, bmo#2045518, bmo#2045604,
+    bmo#2045607, bmo#2045612, bmo#2045614, bmo#2045617,
+    bmo#2045619, bmo#2045624, bmo#2045625, bmo#2045729,
+    bmo#2045737, bmo#2045741, bmo#2045742, bmo#2045744,
+    bmo#2045763, bmo#2045767, bmo#2045770, bmo#2045772,
+    bmo#2045773, bmo#2045775, bmo#2045783, bmo#2045833,
+    bmo#2045848, bmo#2045865, bmo#2045875, bmo#2045957,
+    bmo#2047719, bmo#2047723, bmo#2047729, bmo#2048795,
+    bmo#2048799, bmo#2048801, bmo#2049392, bmo#2049397,
+    bmo#2049398, bmo#2049399, bmo#2049404, bmo#2049405,
+    bmo#2049407, bmo#2049805, bmo#2049812, bmo#2050657,
+    bmo#2050668, bmo#2050990, bmo#2051666, bmo#2053166,
+    bmo#2053273, bmo#2053576, bmo#2053583, bmo#2053587)
+    Memory safety bugs fixed in Firefox ESR 115.38, Firefox ESR
+    140.13 and Firefox 153
+  * CVE-2026-16361 (bmo#2029734, bmo#2036518)
+    Memory safety bugs fixed in Firefox ESR 115.38 and Firefox
+    ESR 140.13
+- Remove obsolete mozilla-bmo1746799.patch
+- Depend on the new transitional package rust-cbindgen-0_29_2
+
+-------------------------------------------------------------------
+Mon Jul 13 19:17:56 UTC 2026 - Manfred Hollstein <[email protected]>
+
+- Guard the "desktop file" actions to be run only on real Factory,
+  Slowroll or Tumbleweed builds, ie. suse_version >= 1699.
+
+-------------------------------------------------------------------
 Sun Jun 28 08:13:29 UTC 2026 - Manfred Hollstein <[email protected]>
 
 - Reformat the patch against current Firefox ESR 140.12.0 and add

++++++ l10n-140.12.0esr.tar.xz -> l10n-140.13.0esr.tar.xz ++++++

++++++ tar_stamps ++++++
--- /var/tmp/diff_new_pack.H2Z0u2/_old  2026-07-22 19:02:33.715816413 +0200
+++ /var/tmp/diff_new_pack.H2Z0u2/_new  2026-07-22 19:02:33.719816550 +0200
@@ -1,11 +1,11 @@
 PRODUCT="firefox"
 CHANNEL="esr140"
-VERSION="140.12.0"
+VERSION="140.13.0"
 VERSION_SUFFIX="esr"
-PREV_VERSION="140.11.0"
+PREV_VERSION="140.12.0"
 PREV_VERSION_SUFFIX="esr"
 #SKIP_LOCALES="" # Uncomment to skip l10n and compare-locales-generation
 RELEASE_REPO="https://hg.mozilla.org/releases/mozilla-esr140";
-RELEASE_TAG="7df86525c2c876c7c92320e49c3e0771f7a605c0"
-RELEASE_TIMESTAMP="20260609153453"
+RELEASE_TAG="7ecdab99b603b94d2ed335990200f8b4b20de1d7"
+RELEASE_TIMESTAMP="20260715202519"
 

Reply via email to