Script 'mail_helper' called by obssrc Hello community, here is the log from the commit of package mcphost for openSUSE:Factory checked in at 2026-09-02 17:00:17 ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Comparing /work/SRC/openSUSE:Factory/mcphost (Old) and /work/SRC/openSUSE:Factory/.mcphost.new.1265 (New) ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Package is "mcphost" Wed Sep 2 17:00:17 2026 rev:13 rq:1375281 version:0.34.0 Changes: -------- --- /work/SRC/openSUSE:Factory/mcphost/mcphost.changes 2026-07-24 22:07:18.605831358 +0200 +++ /work/SRC/openSUSE:Factory/.mcphost.new.1265/mcphost.changes 2026-09-02 17:00:19.625313106 +0200 @@ -1,0 +2,19 @@ +Wed Sep 2 06:03:05 UTC 2026 - Egbert Eich <[email protected]> + +- Update github.com/mark3labs/mcp-go/server to v0.56.0 to fix + CVE-2026-81092: Missing Host Header Validation Enables DNS + Rebinding (bsc#1278013). + Above change removes a dependency on + github.com/buger/jsonparser=github.com/buger/jsonparser. + +------------------------------------------------------------------- +Tue Sep 1 16:16:06 UTC 2026 - Egbert Eich <[email protected]> + +- Update go.opentelemetry.io/otel to 1.44.0 to fix CVE-2026-41178 + (bsc#1276612). + It caused `Parse` to process arbitrarily large/invalid baggage + headers and log errors, enabling DoS via oversized inputs. +- Remove go module replacements which were downgrading + dependencies. + +------------------------------------------------------------------- ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Other differences: ------------------ ++++++ _scmsync.obsinfo ++++++ --- /var/tmp/diff_new_pack.DIxkcX/_old 2026-09-02 17:00:21.026361811 +0200 +++ /var/tmp/diff_new_pack.DIxkcX/_new 2026-09-02 17:00:21.030361950 +0200 @@ -1,5 +1,5 @@ -mtime: 1784881731 -commit: 260cd3e00b58c1db87f86bfe1a9a5b9c67a916ddd267c269fc4f6a7011bdd3ed +mtime: 1788329544 +commit: 90f730571fb2df37f64f2b0f52985d3377a17bc070029dfa295522108bf7066a url: https://src.opensuse.org/AI/mcphost revision: main ++++++ _service ++++++ --- /var/tmp/diff_new_pack.DIxkcX/_old 2026-09-02 17:00:21.053362750 +0200 +++ /var/tmp/diff_new_pack.DIxkcX/_new 2026-09-02 17:00:21.056362854 +0200 @@ -4,22 +4,19 @@ google.golang.org/grpc=google.golang.org/[email protected] </param> <param name="replace"> - github.com/buger/jsonparser=github.com/buger/[email protected] - </param> - <param name="replace"> golang.org/x/net=golang.org/x/[email protected] </param> <param name="replace"> - golang.org/x/crypto=golang.org/x/[email protected] - </param> - <param name="replace"> github.com/aws/aws-sdk-go-v2/aws/protocol/eventstream=github.com/aws/aws-sdk-go-v2/aws/protocol/[email protected] </param> <param name="replace"> github.com/yuin/goldmark=github.com/yuin/[email protected] </param> <param name="replace"> - golang.org/x/text=golang.org/x/[email protected] + go.opentelemetry.io/otel=go.opentelemetry.io/[email protected] + </param> + <param name="replace"> + github.com/mark3labs/mcp-go=github.com/mark3labs/[email protected] </param> </service> </services> ++++++ build.specials.obscpio ++++++ ++++++ build.specials.obscpio ++++++ diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/.gitignore new/.gitignore --- old/.gitignore 1970-01-01 01:00:00.000000000 +0100 +++ new/.gitignore 2026-09-02 08:12:24.000000000 +0200 @@ -0,0 +1,4 @@ +*.obscpio +*.osc +_build.* +.pbuild ++++++ vendor.tar.gz ++++++ /work/SRC/openSUSE:Factory/mcphost/vendor.tar.gz /work/SRC/openSUSE:Factory/.mcphost.new.1265/vendor.tar.gz differ: char 39, line 1
