Script 'mail_helper' called by obssrc
Hello community,
here is the log from the commit of package golang-github-prometheus-prometheus
for openSUSE:Factory checked in at 2026-08-02 23:13:34
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Comparing /work/SRC/openSUSE:Factory/golang-github-prometheus-prometheus (Old)
and
/work/SRC/openSUSE:Factory/.golang-github-prometheus-prometheus.new.16738 (New)
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Package is "golang-github-prometheus-prometheus"
Sun Aug 2 23:13:34 2026 rev:74 rq:1368856 version:3.13.2
Changes:
--------
---
/work/SRC/openSUSE:Factory/golang-github-prometheus-prometheus/golang-github-prometheus-prometheus.changes
2026-06-11 17:26:27.624064131 +0200
+++
/work/SRC/openSUSE:Factory/.golang-github-prometheus-prometheus.new.16738/golang-github-prometheus-prometheus.changes
2026-08-02 23:13:59.963399773 +0200
@@ -1,0 +2,153 @@
+Fri Jul 31 10:36:25 UTC 2026 - Johannes Kastl
<[email protected]>
+
+- update to 3.13.2:
+ * [SECURITY] Bump golang.org/x/text to v0.39.0 (CVE-2026-56852) and
+ google.golang.org/grpc to v1.82.1 (GHSA-hrxh-6v49-42gf). #19290 by
+ @krajorama
+ * [BUGFIX] PromQL: Preallocate the active query tracker file to
+ avoid SIGBUS crashes when the data disk is full. #19289 by
+ @akshajrawat
+
+-------------------------------------------------------------------
+Fri Jul 31 10:15:57 UTC 2026 - Johannes Kastl
<[email protected]>
+
+- update to 3.13.1:
+ * [BUGFIX] TSDB: Fix the head-chunk cache returning samples from the
+ wrong chunk, or spurious not-found errors, to range queries after
+ head-chunk truncation. #19134
+
+-------------------------------------------------------------------
+Fri Jul 31 08:37:32 UTC 2026 - Johannes Kastl
<[email protected]>
+
+- update to 3.13.0
+ This is a Long Term Support LTS release.
+ * [SECURITY] UI: Bump sanitize-html to fix a cross-site scripting
+ vulnerability (CVE-2026-44990). #18697
+ * [CHANGE] UI: Third-party npm dependency licenses are now
+ embedded in the Prometheus binary and served at
+ /assets/third-party-licenses.txt, replacing the
+ npm_licenses.tar.bz2 archive previously shipped in release
+ tarballs and container images. #18997
+ * [CHANGE] API: Use SHA-256 instead of SHA-1 to generate rule
+ group pagination tokens. #18927
+ * [CHANGE] HTTP clients: Credentials (Authorization header, basic
+ auth, bearer token, OAuth2, configured headers) are no longer
+ forwarded when following a redirect to a different host;
+ affects scraping, remote read/write, alerting, and service
+ discovery. Via prometheus/common v0.69.0 (CVE-2025-4673
+ CVE-2023-45289). #18949
+ * [CHANGE] promtool: Relative file paths in the file passed to
+ --http.config.file are now resolved relative to that config
+ file's directory instead of its parent directory. Via
+ prometheus/common v0.69.0. #18949
+ * [CHANGE] PromQL: Rename the min() and max() duration-expression
+ functions (experimental feature flag
+ experimental-duration-expr) to min_of() and max_of() to avoid
+ confusion with the min and max aggregate operators. #18687
+ * [FEATURE] API: Add experimental search endpoints to search
+ metric names, label names, and label values. #18573
+ * [FEATURE] Discovery/AWS: Add ability to filter RDS instances.
+ #18859
+ * [FEATURE] PromQL: Add min_of(a, b) and max_of(a, b) scalar
+ experimental functions, returning the smaller or larger of two
+ scalar values. #18687
+ * [FEATURE] PromQL: Add support for smoothed/anchored rate with
+ native histograms. #18564
+ * [FEATURE] PromQL: Expose per-query samplesRead (and
+ samplesReadPerStep with stats=all and the promql-per-step-stats
+ feature flag) in the query stats response, and add the
+ prometheus_engine_query_samples_read_total engine counter.
+ samplesRead reflects storage I/O distinct from
+ totalQueryableSamples, which counts samples loaded into the
+ evaluator (and so over-counts when a sample is reused across
+ multiple range-vector windows). #18081
+ * [FEATURE] Scrape: Add __convert_classic_histograms_to_nhcb__
+ internal label to allow per-target override of
+ convert_classic_histograms_to_nhcb scrape configuration via
+ relabeling. #18840
+ * [FEATURE] TSDB: Add storage.tsdb.chunk_encoding.floats
+ configuration field to select float chunk encoding (xor or
+ xor2) at runtime, independently of the
+ --enable-feature=xor2-encoding flag. #18769
+ * [FEATURE] remote_write: Add Certificate support for ingesting
+ data into an Azure Monitor Workspace. #18217
+ * [FEATURE] Scrape: Add __always_scrape_classic_histograms__ and
+ __scrape_native_histograms__ internal labels to allow
+ per-target override of the always_scrape_classic_histograms and
+ scrape_native_histograms scrape configuration via relabeling.
+ #18929
+ * [ENHANCEMENT] Release: Container images are now also published
+ to the GitHub Container Registry (ghcr.io). #18791
+ * [ENHANCEMENT] PromQL: Prettify fill_left(x) fill_right(x) as
+ fill(x) when both fill values are equal. #18851
+ * [ENHANCEMENT] UI: Improve autocompletion after closing a
+ function bracket. #18894
+ * [PERF] Labels: Add case-insensitive prefix matching to speed up
+ evaluation of long case-insensitive regular expressions (up to
+ ~2x faster). #18540
+ * [PERF] TSDB: Reduce per-sample overhead in chunk population,
+ speeding up affected queries by ~12-15% in benchmarks. #18699
+ * [PERF] TSDB: Eliminate unnecessary heap allocations in the V2
+ histogram WAL decoder, reducing allocations by up to 50% and
+ memory by up to 10% for deployments using native histograms
+ with created-timestamp storage enabled
+ (--enable-feature=created-timestamp-zero-ingestion). #18813
+ * [BUGFIX] Discovery/AWS: Fix failure when processing an AWS RDS
+ cluster without instances. #18845
+ * [BUGFIX] Fix race condition in initTime that could cause
+ ErrOutOfBounds. #18629
+ * [BUGFIX] PromQL: A range query whose end was not aligned to
+ step caused subqueries inside it to evaluate past the parent's
+ last actual step, inflating peakSamples in the query stats and
+ against the query.max-samples limit, and wasting storage I/O
+ reading samples that were never used in the result. #18081
+ * [BUGFIX] PromQL: A range query containing an at-modifier-unsafe
+ function over a range-vector with an @ modifier (e.g.
+ predict_linear(metric[60s] @ T, X)) silently under-counted
+ totalQueryableSamples for steps after step 0. #18081
+ * [BUGFIX] PromQL: Fix fill_left/fill_right producing missing
+ samples in range queries when using group_left/group_right.
+ #18850
+ * [BUGFIX] PromQL: Fix for resets() and changes() in anchored
+ range extenders with histograms. #18906
+ * [BUGFIX] PromQL: Fix panic on 1[5m] smoothed and similar
+ expressions when extended range selectors are enabled. #18764
+ * [BUGFIX] PromQL: Fix panic when a smoothed instant vector
+ selector produces no samples for a series. #18943
+ * [BUGFIX] PromQL: Fix panic when using a parenthesised plain
+ number as an offset (e.g. foo offset -(5)). #18768
+ * [BUGFIX] promtool: Fix panic when parsing exposition text
+ containing empty braces {}. Via prometheus/common v0.69.0.
+ #18949
+ * [BUGFIX] Promtool: Fix check healthy and check ready when --url
+ ends with a trailing slash. #18854
+ * [BUGFIX] Rules: Close PromQL query after each rule evaluation
+ to ensure resources are released. #18733
+ * [BUGFIX] Scaleway SD: Resolve VPC/IPAM-only instances that have
+ no legacy private_ip or public_ip field, but do have private
+ NICs attached. #18772
+ * [BUGFIX] TSDB: Do not leak head series when an integer
+ histogram append is rejected (e.g. out-of-order). #18838
+ * [BUGFIX] UI: Escape label values offered by PromQL
+ autocomplete. #18658
+ * [BUGFIX] TSDB: Fix chunk snapshot encoding for EncXOR2 chunks,
+ preventing corruption on TSDB restart when EncXOR2-encoded
+ series were present. #18739
+ * [BUGFIX] TSDB: Store a millisecond timestamp (not a WAL segment
+ number) in walExpiries when a series is evicted via
+ CompactStaleHead/CompactSelectedSeries, so the series's label
+ record is correctly retained in the next WAL checkpoint and
+ replays cleanly. #18847
+ * [BUGFIX] TSDB: Prevent loss of samples at the chunk-range
+ boundary when CompactSelectedSeries (and CompactStaleHead)
+ evict the series — the per-slice compaction loop now runs one
+ more iteration so the boundary timestamp is captured in a block
+ before the in-memory copy is removed. #18849
+- as 3.13.x uses pnpm instead of npm, the packaging was refactored.
+ * refactor Makefile
+ * replace create_package-lock_json.sh with prepare_webassets.sh
+ script
+ * remove node_modules service
+ * adjusted PACKAGING_README.md
+
+-------------------------------------------------------------------
Old:
----
create_package-lock_json.sh
node_modules.obscpio
node_modules.spec.inc
package-lock.json
prometheus-3.12.0.obscpio
New:
----
prepare_webassets.sh
prometheus-3.13.2.obscpio
web-3.13.2.tar.gz
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Other differences:
------------------
++++++ golang-github-prometheus-prometheus.spec ++++++
--- /var/tmp/diff_new_pack.42XQpm/_old 2026-08-02 23:14:04.019538997 +0200
+++ /var/tmp/diff_new_pack.42XQpm/_new 2026-08-02 23:14:04.019538997 +0200
@@ -27,7 +27,7 @@
%endif
Name: golang-github-prometheus-prometheus
-Version: 3.12.0
+Version: 3.13.2
Release: 0
Summary: The Prometheus monitoring system and time series database
License: Apache-2.0
@@ -35,19 +35,17 @@
URL: https://prometheus.io/
Source: prometheus-%{version}.tar.gz
Source1: vendor.tar.gz
+Source2: web-%{version}.tar.gz
+
Source3: prometheus.service
Source4: prometheus.yml
Source5: prometheus.sysconfig
Source6: prometheus.firewall.xml
Source7: prometheus.tmpfiles
#
-Source10: package-lock.json
-Source11: node_modules.spec.inc
-%include %{_sourcedir}/node_modules.spec.inc
-#
Source21: Makefile
Source22: PACKAGING_README.md
-Source23: create_package-lock_json.sh
+Source23: prepare_webassets.sh
#
Patch1: 0001-Do-not-force-the-pure-Go-name-resolver.patch
# Lifted from Debian's prometheus package
@@ -62,7 +60,6 @@
# with -buildmode=pie
BuildRequires: glibc-devel-static
BuildRequires: golang-github-prometheus-promu >= 0.14.0
-BuildRequires: local-npm-registry
BuildRequires: golang(API) >= 1.25
BuildRoot: %{_tmppath}/%{name}-%{version}-build
%if 0%{?suse_version} >= 1500
@@ -90,15 +87,15 @@
- multiple modes of graphing and dashboarding support
%prep
-%autosetup -a1 -p1 -n prometheus-%{version}
-pushd web/ui
-local-npm-registry %{_sourcedir} install --include=dev
-popd
+# As the 0003-Remove-build-react-app.patch patch was already applied
+# during the webassets generation, it would fail to apply now.
+# Hence we are using setup and autopatch instead of autosetup
+# to omit this patch during the build
+%setup -q -a1 -n prometheus-%{version}
+%autopatch -p1 -M 2
+tar xf %{SOURCE2}
%build
-pushd web/ui
-npm run build
-popd
rm -f npm_licenses.tar.bz2 npm_licenses
ln -s . npm_licenses
find npm_licenses/web/ui/node_modules -iname "license*" | tar cfj
npm_licenses.tar.bz2 --files-from=-
++++++ Makefile ++++++
--- /var/tmp/diff_new_pack.42XQpm/_old 2026-08-02 23:14:04.083541194 +0200
+++ /var/tmp/diff_new_pack.42XQpm/_new 2026-08-02 23:14:04.087541332 +0200
@@ -1,33 +1,25 @@
.ONESHELL:
+.SILENT: obsservices prepare_webassets
NAME = prometheus
SPEC = golang-github-prometheus-prometheus.spec
-default: clean obs_scm go_modules package_lock_json node_modules
+default: clean obsservices prepare_webassets
clean:
- rm -rf prometheus $(NAME)-*.tar $(NAME)-*.tar.gz $(NAME)-*.obscpio
vendor.tar.gz package-lock.json *[0-9].tgz
+ rm -rf $(NAME) $(NAME)-*.tar $(NAME)-*.tar.gz $(NAME)-*.obscpio
web-*.tar.gz vendor.tar.gz
-.SILENT: obs_scm
-obs_scm:
- osc service manualrun obs_scm
-
-.SILENT: go_modules
-go_modules:
- osc service manualrun go_modules
+obsservices:
+ echo "##########"
+ echo "Running OBS services"
+ osc service manualrun
-.SILENT: package_lock_json
-package_lock_json:
+prepare_webassets:
podman run \
-ti \
--rm \
--pull=always \
-v .:/data/ \
registry.opensuse.org/opensuse/leap:16.0 \
- bash /data/create_package-lock_json.sh $(SPEC) nodejs24
-
-.SILENT: node_modules
-node_modules:
- osc service manualrun node_modules
- rm -f *tgz
+ bash /data/prepare_webassets.sh
++++++ PACKAGING_README.md ++++++
--- /var/tmp/diff_new_pack.42XQpm/_old 2026-08-02 23:14:04.115542292 +0200
+++ /var/tmp/diff_new_pack.42XQpm/_new 2026-08-02 23:14:04.119542430 +0200
@@ -1,14 +1,10 @@
# Packaging prometheus
-In addition to the source code in the tarball, this package also
-needs the assets for the web UI. These can be generated during the
-build at the build server using the node modules service. The
-required dependencies definition can be generated by the `Makefile`
-which is present in this package.
-To do that, you need to have `make` and `podman` installed locally.
-For the OBS workflow you also need `obs-service-go_modules`,
-`obs-service-node_modules` as well as `obs-service-tar_scm` and
-`obs-service-recompress`.
+In addition to the source code in the tarball, this package also needs the
+assets for the web UI. These can be generated by the `Makefile` that is present
+in this package. To do that, you need to have `make` and `podman` installed
+locally. For the OBS workflow you also need `obs-service-go_modules` as well
as
+`obs-service-tar_scm` and `obs-service-recompress`.
1. Change the version in the `_service` file
2. Change the version in the spec file
++++++ _service ++++++
--- /var/tmp/diff_new_pack.42XQpm/_old 2026-08-02 23:14:04.143543254 +0200
+++ /var/tmp/diff_new_pack.42XQpm/_new 2026-08-02 23:14:04.147543391 +0200
@@ -6,18 +6,13 @@
<param name="exclude">go.work</param>
<param name="exclude">go.work.sum</param>
<param name="versionformat">@PARENT_TAG@</param>
- <param name="revision">v3.12.0</param>
+ <param name="revision">refs/tags/v3.13.2</param>
<param name="versionrewrite-pattern">v(.*)</param>
<param name="match-tag">v3*</param>
</service>
<service name="go_modules" mode="manual">
<param name="archive">prometheus-*.obscpio</param>
</service>
- <service name="node_modules" mode="manual">
- <param name="cpio">node_modules.obscpio</param>
- <param name="output">node_modules.spec.inc</param>
- <param name="source-offset">10000</param>
- </service>
<!-- services below are running at buildtime -->
<service name="tar" mode="buildtime">
</service>
++++++ prepare_webassets.sh ++++++
#!/bin/bash
set -o pipefail
[[ "$#" == "0" ]] || {
echo "This script accepts no arguments"
exit 1
}
spec_file_name=golang-github-prometheus-prometheus.spec
package_name=prometheus
cd /data || exit 11
zypper -n install \
cpio \
gawk \
make \
git-core \
patch \
pnpm || exit 13
version="$( awk '/^Version:/ {print $2;exit;}' "${spec_file_name}" )"
[[ -z "${version}" ]] && {
echo "version variable is empty..."
exit 14
}
echo "##########"
echo "Package version is ${version}"
basename="${package_name}-${version}"
obscpio="${basename}.obscpio"
webassets_tarball="web-${version}.tar.gz"
working_directory="$(pwd)"
tmpdir="$(mktemp -d -p /tmp)"
echo "Changing into tmpdir ${tmpdir}"
cd "${tmpdir}" || exit 15
echo "##########"
echo "Extracting obscpio archive"
cpio -id < "${working_directory}/${obscpio}" || exit 21
cd "${basename}" || exit 23
patch -p1 < 0003-Remove-build-react-app.patch
echo "##########"
cd web/ui/ || exit 25
rm -rf node_modules || exit 27
pnpm install --frozen-lockfile
# cd react-app || exit 25
# rm -rf node_modules || exit 27
# pnpm install --frozen-lockfile
# cd .. || exit 25
CI="true" pnpm run build:mantine-ui
cd ../../ || exit 29
echo "Creating web assets tarball"
tar -czf "${working_directory}/${webassets_tarball}" web/ui/
echo "##########"
echo "Cleaning up..."
cd "${working_directory}" || exit 31
rm -rf "$tmpdir"
echo "DONE preparing the webassets"
exit 0
++++++ prometheus-3.12.0.obscpio -> prometheus-3.13.2.obscpio ++++++
++++ 78757 lines of diff (skipped)
++++++ prometheus.obsinfo ++++++
--- /var/tmp/diff_new_pack.42XQpm/_old 2026-08-02 23:14:08.359687970 +0200
+++ /var/tmp/diff_new_pack.42XQpm/_new 2026-08-02 23:14:08.411689755 +0200
@@ -1,5 +1,5 @@
name: prometheus
-version: 3.12.0
-mtime: 1779982292
-commit: 9f27dffc1f93ca23287972f632025879f2d1c658
+version: 3.13.2
+mtime: 1785409485
+commit: bb5dff00cf8fdfbf5c65e0531aa835fa238a43a2
++++++ vendor.tar.gz ++++++
/work/SRC/openSUSE:Factory/golang-github-prometheus-prometheus/vendor.tar.gz
/work/SRC/openSUSE:Factory/.golang-github-prometheus-prometheus.new.16738/vendor.tar.gz
differ: char 17, line 1