Script 'mail_helper' called by obssrc
Hello community,

here is the log from the commit of package golang-github-prometheus-prometheus 
for openSUSE:Factory checked in at 2026-08-02 23:13:34
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Comparing /work/SRC/openSUSE:Factory/golang-github-prometheus-prometheus (Old)
 and      
/work/SRC/openSUSE:Factory/.golang-github-prometheus-prometheus.new.16738 (New)
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Package is "golang-github-prometheus-prometheus"

Sun Aug  2 23:13:34 2026 rev:74 rq:1368856 version:3.13.2

Changes:
--------
--- 
/work/SRC/openSUSE:Factory/golang-github-prometheus-prometheus/golang-github-prometheus-prometheus.changes
  2026-06-11 17:26:27.624064131 +0200
+++ 
/work/SRC/openSUSE:Factory/.golang-github-prometheus-prometheus.new.16738/golang-github-prometheus-prometheus.changes
       2026-08-02 23:13:59.963399773 +0200
@@ -1,0 +2,153 @@
+Fri Jul 31 10:36:25 UTC 2026 - Johannes Kastl 
<[email protected]>
+
+- update to 3.13.2:
+  * [SECURITY] Bump golang.org/x/text to v0.39.0 (CVE-2026-56852) and
+    google.golang.org/grpc to v1.82.1 (GHSA-hrxh-6v49-42gf). #19290 by
+    @krajorama
+  * [BUGFIX] PromQL: Preallocate the active query tracker file to
+    avoid SIGBUS crashes when the data disk is full. #19289 by
+    @akshajrawat
+
+-------------------------------------------------------------------
+Fri Jul 31 10:15:57 UTC 2026 - Johannes Kastl 
<[email protected]>
+
+- update to 3.13.1:
+  * [BUGFIX] TSDB: Fix the head-chunk cache returning samples from the
+    wrong chunk, or spurious not-found errors, to range queries after
+    head-chunk truncation. #19134
+
+-------------------------------------------------------------------
+Fri Jul 31 08:37:32 UTC 2026 - Johannes Kastl 
<[email protected]>
+
+- update to 3.13.0
+  This is a Long Term Support LTS release.
+  * [SECURITY] UI: Bump sanitize-html to fix a cross-site scripting
+    vulnerability (CVE-2026-44990). #18697
+  * [CHANGE] UI: Third-party npm dependency licenses are now
+    embedded in the Prometheus binary and served at
+    /assets/third-party-licenses.txt, replacing the
+    npm_licenses.tar.bz2 archive previously shipped in release
+    tarballs and container images. #18997
+  * [CHANGE] API: Use SHA-256 instead of SHA-1 to generate rule
+    group pagination tokens. #18927
+  * [CHANGE] HTTP clients: Credentials (Authorization header, basic
+    auth, bearer token, OAuth2, configured headers) are no longer
+    forwarded when following a redirect to a different host;
+    affects scraping, remote read/write, alerting, and service
+    discovery. Via prometheus/common v0.69.0 (CVE-2025-4673
+    CVE-2023-45289). #18949
+  * [CHANGE] promtool: Relative file paths in the file passed to
+    --http.config.file are now resolved relative to that config
+    file's directory instead of its parent directory. Via
+    prometheus/common v0.69.0. #18949
+  * [CHANGE] PromQL: Rename the min() and max() duration-expression
+    functions (experimental feature flag
+    experimental-duration-expr) to min_of() and max_of() to avoid
+    confusion with the min and max aggregate operators. #18687
+  * [FEATURE] API: Add experimental search endpoints to search
+    metric names, label names, and label values. #18573
+  * [FEATURE] Discovery/AWS: Add ability to filter RDS instances.
+    #18859
+  * [FEATURE] PromQL: Add min_of(a, b) and max_of(a, b) scalar
+    experimental functions, returning the smaller or larger of two
+    scalar values. #18687
+  * [FEATURE] PromQL: Add support for smoothed/anchored rate with
+    native histograms. #18564
+  * [FEATURE] PromQL: Expose per-query samplesRead (and
+    samplesReadPerStep with stats=all and the promql-per-step-stats
+    feature flag) in the query stats response, and add the
+    prometheus_engine_query_samples_read_total engine counter.
+    samplesRead reflects storage I/O distinct from
+    totalQueryableSamples, which counts samples loaded into the
+    evaluator (and so over-counts when a sample is reused across
+    multiple range-vector windows). #18081
+  * [FEATURE] Scrape: Add __convert_classic_histograms_to_nhcb__
+    internal label to allow per-target override of
+    convert_classic_histograms_to_nhcb scrape configuration via
+    relabeling. #18840
+  * [FEATURE] TSDB: Add storage.tsdb.chunk_encoding.floats
+    configuration field to select float chunk encoding (xor or
+    xor2) at runtime, independently of the
+    --enable-feature=xor2-encoding flag. #18769
+  * [FEATURE] remote_write: Add Certificate support for ingesting
+    data into an Azure Monitor Workspace. #18217
+  * [FEATURE] Scrape: Add __always_scrape_classic_histograms__ and
+    __scrape_native_histograms__ internal labels to allow
+    per-target override of the always_scrape_classic_histograms and
+    scrape_native_histograms scrape configuration via relabeling.
+    #18929
+  * [ENHANCEMENT] Release: Container images are now also published
+    to the GitHub Container Registry (ghcr.io). #18791
+  * [ENHANCEMENT] PromQL: Prettify fill_left(x) fill_right(x) as
+    fill(x) when both fill values are equal. #18851
+  * [ENHANCEMENT] UI: Improve autocompletion after closing a
+    function bracket. #18894
+  * [PERF] Labels: Add case-insensitive prefix matching to speed up
+    evaluation of long case-insensitive regular expressions (up to
+    ~2x faster). #18540
+  * [PERF] TSDB: Reduce per-sample overhead in chunk population,
+    speeding up affected queries by ~12-15% in benchmarks. #18699
+  * [PERF] TSDB: Eliminate unnecessary heap allocations in the V2
+    histogram WAL decoder, reducing allocations by up to 50% and
+    memory by up to 10% for deployments using native histograms
+    with created-timestamp storage enabled
+    (--enable-feature=created-timestamp-zero-ingestion). #18813
+  * [BUGFIX] Discovery/AWS: Fix failure when processing an AWS RDS
+    cluster without instances. #18845
+  * [BUGFIX] Fix race condition in initTime that could cause
+    ErrOutOfBounds. #18629
+  * [BUGFIX] PromQL: A range query whose end was not aligned to
+    step caused subqueries inside it to evaluate past the parent's
+    last actual step, inflating peakSamples in the query stats and
+    against the query.max-samples limit, and wasting storage I/O
+    reading samples that were never used in the result. #18081
+  * [BUGFIX] PromQL: A range query containing an at-modifier-unsafe
+    function over a range-vector with an @ modifier (e.g.
+    predict_linear(metric[60s] @ T, X)) silently under-counted
+    totalQueryableSamples for steps after step 0. #18081
+  * [BUGFIX] PromQL: Fix fill_left/fill_right producing missing
+    samples in range queries when using group_left/group_right.
+    #18850
+  * [BUGFIX] PromQL: Fix for resets() and changes() in anchored
+    range extenders with histograms. #18906
+  * [BUGFIX] PromQL: Fix panic on 1[5m] smoothed and similar
+    expressions when extended range selectors are enabled. #18764
+  * [BUGFIX] PromQL: Fix panic when a smoothed instant vector
+    selector produces no samples for a series. #18943
+  * [BUGFIX] PromQL: Fix panic when using a parenthesised plain
+    number as an offset (e.g. foo offset -(5)). #18768
+  * [BUGFIX] promtool: Fix panic when parsing exposition text
+    containing empty braces {}. Via prometheus/common v0.69.0.
+    #18949
+  * [BUGFIX] Promtool: Fix check healthy and check ready when --url
+    ends with a trailing slash. #18854
+  * [BUGFIX] Rules: Close PromQL query after each rule evaluation
+    to ensure resources are released. #18733
+  * [BUGFIX] Scaleway SD: Resolve VPC/IPAM-only instances that have
+    no legacy private_ip or public_ip field, but do have private
+    NICs attached. #18772
+  * [BUGFIX] TSDB: Do not leak head series when an integer
+    histogram append is rejected (e.g. out-of-order). #18838
+  * [BUGFIX] UI: Escape label values offered by PromQL
+    autocomplete. #18658
+  * [BUGFIX] TSDB: Fix chunk snapshot encoding for EncXOR2 chunks,
+    preventing corruption on TSDB restart when EncXOR2-encoded
+    series were present. #18739
+  * [BUGFIX] TSDB: Store a millisecond timestamp (not a WAL segment
+    number) in walExpiries when a series is evicted via
+    CompactStaleHead/CompactSelectedSeries, so the series's label
+    record is correctly retained in the next WAL checkpoint and
+    replays cleanly. #18847
+  * [BUGFIX] TSDB: Prevent loss of samples at the chunk-range
+    boundary when CompactSelectedSeries (and CompactStaleHead)
+    evict the series — the per-slice compaction loop now runs one
+    more iteration so the boundary timestamp is captured in a block
+    before the in-memory copy is removed. #18849
+- as 3.13.x uses pnpm instead of npm, the packaging was refactored.
+  * refactor Makefile
+  * replace create_package-lock_json.sh with prepare_webassets.sh
+    script
+  * remove node_modules service
+  * adjusted PACKAGING_README.md
+
+-------------------------------------------------------------------

Old:
----
  create_package-lock_json.sh
  node_modules.obscpio
  node_modules.spec.inc
  package-lock.json
  prometheus-3.12.0.obscpio

New:
----
  prepare_webassets.sh
  prometheus-3.13.2.obscpio
  web-3.13.2.tar.gz

++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Other differences:
------------------
++++++ golang-github-prometheus-prometheus.spec ++++++
--- /var/tmp/diff_new_pack.42XQpm/_old  2026-08-02 23:14:04.019538997 +0200
+++ /var/tmp/diff_new_pack.42XQpm/_new  2026-08-02 23:14:04.019538997 +0200
@@ -27,7 +27,7 @@
 %endif
 
 Name:           golang-github-prometheus-prometheus
-Version:        3.12.0
+Version:        3.13.2
 Release:        0
 Summary:        The Prometheus monitoring system and time series database
 License:        Apache-2.0
@@ -35,19 +35,17 @@
 URL:            https://prometheus.io/
 Source:         prometheus-%{version}.tar.gz
 Source1:        vendor.tar.gz
+Source2:        web-%{version}.tar.gz
+
 Source3:        prometheus.service
 Source4:        prometheus.yml
 Source5:        prometheus.sysconfig
 Source6:        prometheus.firewall.xml
 Source7:        prometheus.tmpfiles
 #
-Source10:       package-lock.json
-Source11:       node_modules.spec.inc
-%include        %{_sourcedir}/node_modules.spec.inc
-#
 Source21:       Makefile
 Source22:       PACKAGING_README.md
-Source23:       create_package-lock_json.sh
+Source23:       prepare_webassets.sh
 #
 Patch1:         0001-Do-not-force-the-pure-Go-name-resolver.patch
 # Lifted from Debian's prometheus package
@@ -62,7 +60,6 @@
 # with -buildmode=pie
 BuildRequires:  glibc-devel-static
 BuildRequires:  golang-github-prometheus-promu >= 0.14.0
-BuildRequires:  local-npm-registry
 BuildRequires:  golang(API) >= 1.25
 BuildRoot:      %{_tmppath}/%{name}-%{version}-build
 %if 0%{?suse_version} >= 1500
@@ -90,15 +87,15 @@
  - multiple modes of graphing and dashboarding support
 
 %prep
-%autosetup -a1 -p1 -n prometheus-%{version}
-pushd web/ui
-local-npm-registry %{_sourcedir} install --include=dev
-popd
+# As the 0003-Remove-build-react-app.patch patch was already applied
+# during the webassets generation, it would fail to apply now.
+# Hence we are using setup and autopatch instead of autosetup
+# to omit this patch during the build
+%setup -q -a1 -n prometheus-%{version}
+%autopatch -p1 -M 2
+tar xf %{SOURCE2}
 
 %build
-pushd web/ui
-npm run build
-popd
 rm -f npm_licenses.tar.bz2 npm_licenses
 ln -s . npm_licenses
 find npm_licenses/web/ui/node_modules -iname "license*" | tar cfj 
npm_licenses.tar.bz2 --files-from=-

++++++ Makefile ++++++
--- /var/tmp/diff_new_pack.42XQpm/_old  2026-08-02 23:14:04.083541194 +0200
+++ /var/tmp/diff_new_pack.42XQpm/_new  2026-08-02 23:14:04.087541332 +0200
@@ -1,33 +1,25 @@
 .ONESHELL:
+.SILENT: obsservices prepare_webassets
 
 NAME = prometheus
 SPEC = golang-github-prometheus-prometheus.spec
 
-default: clean obs_scm go_modules package_lock_json node_modules
+default: clean obsservices prepare_webassets
 
 clean:
-       rm -rf prometheus $(NAME)-*.tar $(NAME)-*.tar.gz $(NAME)-*.obscpio 
vendor.tar.gz package-lock.json  *[0-9].tgz
+       rm -rf $(NAME) $(NAME)-*.tar $(NAME)-*.tar.gz $(NAME)-*.obscpio 
web-*.tar.gz vendor.tar.gz
 
-.SILENT: obs_scm
-obs_scm:
-       osc service manualrun obs_scm
-
-.SILENT: go_modules
-go_modules:
-       osc service manualrun go_modules
+obsservices:
+       echo "##########"
+       echo "Running OBS services"
+       osc service manualrun
 
-.SILENT: package_lock_json
-package_lock_json:
+prepare_webassets:
        podman run \
                -ti \
                --rm \
                --pull=always \
                -v .:/data/ \
                registry.opensuse.org/opensuse/leap:16.0 \
-               bash /data/create_package-lock_json.sh $(SPEC) nodejs24
-
-.SILENT: node_modules
-node_modules:
-       osc service manualrun node_modules
-       rm -f *tgz
+               bash /data/prepare_webassets.sh
 

++++++ PACKAGING_README.md ++++++
--- /var/tmp/diff_new_pack.42XQpm/_old  2026-08-02 23:14:04.115542292 +0200
+++ /var/tmp/diff_new_pack.42XQpm/_new  2026-08-02 23:14:04.119542430 +0200
@@ -1,14 +1,10 @@
 # Packaging prometheus
 
-In addition to the source code in the tarball, this package also
-needs the assets for the web UI. These can be generated during the
-build at the build server using the node modules service. The
-required dependencies definition can be generated by the `Makefile`
-which is present in this package.
-To do that, you need to have `make` and `podman` installed locally.
-For the OBS workflow you also need `obs-service-go_modules`,
-`obs-service-node_modules` as well as `obs-service-tar_scm` and
-`obs-service-recompress`.
+In addition to the source code in the tarball, this package also needs the
+assets for the web UI. These can be generated by the `Makefile` that is present
+in this package.  To do that, you need to have `make` and `podman` installed
+locally.  For the OBS workflow you also need `obs-service-go_modules` as well 
as
+`obs-service-tar_scm` and `obs-service-recompress`.
 
 1. Change the version in the `_service` file
 2. Change the version in the spec file

++++++ _service ++++++
--- /var/tmp/diff_new_pack.42XQpm/_old  2026-08-02 23:14:04.143543254 +0200
+++ /var/tmp/diff_new_pack.42XQpm/_new  2026-08-02 23:14:04.147543391 +0200
@@ -6,18 +6,13 @@
     <param name="exclude">go.work</param>
     <param name="exclude">go.work.sum</param>
     <param name="versionformat">@PARENT_TAG@</param>
-    <param name="revision">v3.12.0</param>
+    <param name="revision">refs/tags/v3.13.2</param>
     <param name="versionrewrite-pattern">v(.*)</param>
     <param name="match-tag">v3*</param>
   </service>
   <service name="go_modules" mode="manual">
     <param name="archive">prometheus-*.obscpio</param>
   </service>
-  <service name="node_modules" mode="manual">
-    <param name="cpio">node_modules.obscpio</param>
-    <param name="output">node_modules.spec.inc</param>
-    <param name="source-offset">10000</param>
-  </service>
   <!-- services below are running at buildtime -->
   <service name="tar" mode="buildtime">
   </service>

++++++ prepare_webassets.sh ++++++
#!/bin/bash

set -o pipefail

[[ "$#" == "0" ]] || {
        echo "This script accepts no arguments"
        exit 1
}

spec_file_name=golang-github-prometheus-prometheus.spec
package_name=prometheus

cd /data || exit 11

zypper -n install \
    cpio \
    gawk \
    make \
    git-core \
    patch \
    pnpm || exit 13

version="$( awk '/^Version:/ {print $2;exit;}' "${spec_file_name}" )"

[[ -z "${version}" ]] && {
        echo "version variable is empty..."
        exit 14
}

echo "##########"
echo "Package version is ${version}"
basename="${package_name}-${version}"
obscpio="${basename}.obscpio"
webassets_tarball="web-${version}.tar.gz"
working_directory="$(pwd)"
tmpdir="$(mktemp -d -p /tmp)"
echo "Changing into tmpdir ${tmpdir}"
cd "${tmpdir}" || exit 15

echo "##########"
echo "Extracting obscpio archive"
cpio -id < "${working_directory}/${obscpio}" || exit 21
cd "${basename}" || exit 23

patch -p1 < 0003-Remove-build-react-app.patch

echo "##########"
cd web/ui/ || exit 25
rm -rf node_modules || exit 27
pnpm install --frozen-lockfile

# cd react-app || exit 25
# rm -rf node_modules || exit 27
# pnpm install --frozen-lockfile
# cd .. || exit 25

CI="true" pnpm run build:mantine-ui

cd ../../ || exit 29
echo "Creating web assets tarball"
tar -czf "${working_directory}/${webassets_tarball}" web/ui/

echo "##########"
echo "Cleaning up..."
cd "${working_directory}" || exit 31
rm -rf "$tmpdir"

echo "DONE preparing the webassets"

exit 0

++++++ prometheus-3.12.0.obscpio -> prometheus-3.13.2.obscpio ++++++
++++ 78757 lines of diff (skipped)

++++++ prometheus.obsinfo ++++++
--- /var/tmp/diff_new_pack.42XQpm/_old  2026-08-02 23:14:08.359687970 +0200
+++ /var/tmp/diff_new_pack.42XQpm/_new  2026-08-02 23:14:08.411689755 +0200
@@ -1,5 +1,5 @@
 name: prometheus
-version: 3.12.0
-mtime: 1779982292
-commit: 9f27dffc1f93ca23287972f632025879f2d1c658
+version: 3.13.2
+mtime: 1785409485
+commit: bb5dff00cf8fdfbf5c65e0531aa835fa238a43a2
 

++++++ vendor.tar.gz ++++++
/work/SRC/openSUSE:Factory/golang-github-prometheus-prometheus/vendor.tar.gz 
/work/SRC/openSUSE:Factory/.golang-github-prometheus-prometheus.new.16738/vendor.tar.gz
 differ: char 17, line 1

Reply via email to