Script 'mail_helper' called by obssrc
Hello community,

here is the log from the commit of package grafana for openSUSE:Factory checked 
in at 2026-09-04 12:41:29
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Comparing /work/SRC/openSUSE:Factory/grafana (Old)
 and      /work/SRC/openSUSE:Factory/.grafana.new.1265 (New)
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Package is "grafana"

Fri Sep  4 12:41:29 2026 rev:96 rq:1375608 version:12.4.10

Changes:
--------
--- /work/SRC/openSUSE:Factory/grafana/grafana.changes  2026-09-01 
15:52:08.504679612 +0200
+++ /work/SRC/openSUSE:Factory/.grafana.new.1265/grafana.changes        
2026-09-04 12:42:20.558656529 +0200
@@ -1,0 +2,62 @@
+Wed Sep  2 10:24:13 UTC 2026 - Witek Bedyk <[email protected]>
+
+- Update to version 12.4.10:
+  * Security:
+    CVE-2026-17183: Fix exposing data accessible through Grafana's
+                    configured datasource credentials (bsc#1275934)
+    CVE-2026-2303: Drop dependency on vulnerable
+                   go.mongodb.org/mongo-driver (bsc#1269841)
+    CVE-2026-17033: Fix stored XSS via external Alertmanager
+                    generatorURL (bsc#1276426)
+    CVE-2026-73501: Fix fail-open authentication bypass in
+                    github.com/getkin/kin-openapi (bsc#1276973)
+    CVE-2026-19475: Fix DoS in PostgreSQL Datasource (bsc#1278307)
+    CVE-2026-14199: Fix session takeover via Auth Proxy cache key
+                    collision (bsc#1278322)
+  * Bug fixes:
+    Dashboards: Fix adhoc and groupby variable datasource on UI
+                import
+    Dashboards: Fix version dates and user display names in the
+                legacy version history page
+
+- Update to version 12.4.9:
+  * Features and enhancements:
+    Dashboard Import: Labels in v2 schema
+  * Bug fixes:
+    Azure Monitor: fix migration for dimension filters
+
+- Update to version 12.4.8:
+  * Security:
+    CVE-2026-19197: Fix access control in dashboard snapshots
+                    (bsc#1277025)
+
+- Update to version 12.4.7:
+  * Security:
+    CVE-2026-56852: Fix infinite loop on truncated/invalid UTF-8
+                    input in golang.org/x/text/unicode/norm
+                    (bsc#1272008)
+  * Features and enhancements:
+    Dashboards: Get annotations and dashboard endpoint performance
+                improvements
+  * Bug fixes:
+    DashboardDS: Fix Mixed panels with a time override stuck in
+                 permanent loading
+
+- Update to version 12.4.6:
+  * Security:
+    CVE-2026-41178: Fix opentelemetry-go's baggage parsing
+                    (bsc#1276658)
+  * Features and enhancements:
+    Alerting: Add protected fields authorization check to
+              provisioning API
+    Alerting: Return 403 instead of 500 on contact point provenance
+              mismatch
+  * Bug fixes:
+    Jaeger: Handle gzip, deflate, and brotli compressed API
+            responses
+    Alerting: fix ORM table mapping bug causing SELECT alert_rule
+              columns FROM user on PostgreSQL
+
+- Drop 0005-Bump-edwards25519.patch
+
+-------------------------------------------------------------------

Old:
----
  0005-Bump-edwards25519.patch
  grafana-12.4.5.tar.gz
  ui-12.4.5.tar.gz

New:
----
  grafana-12.4.10.tar.gz
  ui-12.4.10.tar.gz

----------(Old B)----------
  Old:
- Drop 0005-Bump-edwards25519.patch
----------(Old E)----------

++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Other differences:
------------------
++++++ grafana.spec ++++++
--- /var/tmp/diff_new_pack.NP40Mi/_old  2026-09-04 12:42:24.578797713 +0200
+++ /var/tmp/diff_new_pack.NP40Mi/_new  2026-09-04 12:42:24.581797818 +0200
@@ -22,7 +22,7 @@
 %endif
 
 Name:           grafana
-Version:        12.4.5
+Version:        12.4.10
 Release:        0
 Summary:        The open-source platform for monitoring and observability
 License:        AGPL-3.0-only
@@ -39,7 +39,6 @@
 Source5:        Makefile
 Source6:        0001-Add-source-code-reference.patch
 Patch3:         0003-Use-bash-instead-of-env.patch
-Patch5:         0005-Bump-edwards25519.patch
 BuildRequires:  fdupes
 BuildRequires:  git-core
 BuildRequires:  golang(API) >= 1.26

++++++ Makefile ++++++
--- /var/tmp/diff_new_pack.NP40Mi/_old  2026-09-04 12:42:24.622799258 +0200
+++ /var/tmp/diff_new_pack.NP40Mi/_new  2026-09-04 12:42:24.625799363 +0200
@@ -38,7 +38,6 @@
        patch --no-backup-if-mismatch -p1 -i 
../../0001-Add-source-code-reference.patch; \
        # End patches section \
        # Patches for Go modules go after here \
-       patch --no-backup-if-mismatch -p1 -i 
../../0005-Bump-edwards25519.patch; \
        # End of Go modules patches section \
        go mod download; \
        go mod verify; \

++++++ grafana-12.4.5.tar.gz -> grafana-12.4.10.tar.gz ++++++
/work/SRC/openSUSE:Factory/grafana/grafana-12.4.5.tar.gz 
/work/SRC/openSUSE:Factory/.grafana.new.1265/grafana-12.4.10.tar.gz differ: 
char 15, line 1

++++++ ui-12.4.5.tar.gz -> ui-12.4.10.tar.gz ++++++
/work/SRC/openSUSE:Factory/grafana/ui-12.4.5.tar.gz 
/work/SRC/openSUSE:Factory/.grafana.new.1265/ui-12.4.10.tar.gz differ: char 32, 
line 1

++++++ vendor.tar.gz ++++++
/work/SRC/openSUSE:Factory/grafana/vendor.tar.gz 
/work/SRC/openSUSE:Factory/.grafana.new.1265/vendor.tar.gz differ: char 5, line 
1

Reply via email to