Script 'mail_helper' called by obssrc
Hello community,

here is the log from the commit of package python-comfyui-frontend-package for 
openSUSE:Factory checked in at 2026-09-08 16:54:23
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Comparing /work/SRC/openSUSE:Factory/python-comfyui-frontend-package (Old)
 and      /work/SRC/openSUSE:Factory/.python-comfyui-frontend-package.new.1265 
(New)
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Package is "python-comfyui-frontend-package"

Tue Sep  8 16:54:23 2026 rev:4 rq:1376109 version:1.52.7

Changes:
--------
--- 
/work/SRC/openSUSE:Factory/python-comfyui-frontend-package/python-comfyui-frontend-package.changes
  2026-08-27 18:56:02.159386583 +0200
+++ 
/work/SRC/openSUSE:Factory/.python-comfyui-frontend-package.new.1265/python-comfyui-frontend-package.changes
        2026-09-08 16:55:28.219352583 +0200
@@ -1,0 +2,27 @@
+Mon Sep  7 06:38:03 UTC 2026 - Martin Pluskal <[email protected]>
+
+- Update to 1.52.7:
+  * Moves to the 1.52 line, which is ahead of the version ComfyUI's
+    own requirements.txt names; read as static data, and upstream's
+    version check only warns when below the pin
+  * Node display names, widget labels, output names and tooltips now
+    resolved from the backend at read time -- extensions must key on
+    widget.name, not widget.label
+  * Client-side video metadata extraction via mediabunny; 3D camera
+    widget for CreateCameraInfo; RESOLUTION_PREVIEW readout widget
+  * Non-UUID workflow ids lazily migrated to a fresh UUID
+  * Static v-html sinks removed
+  * Ctrl/Cmd shortcuts no longer fall through to the browser; hidden
+    ARIA dialogs no longer block global shortcuts
+  * API key user authentication restored
+  * Comfy Cloud partner nodes branded on canvas and in the registry
+- Bundled DOMPurify 3.4.7 -> 3.4.13, which fixes:
+  * CVE-2026-65898: permanent ALLOWED_ATTR pollution via setConfig()
+  * CVE-2026-65899: Trusted Types policy survives clearConfig()
+  * CVE-2026-65900: SAFE_FOR_TEMPLATES bypass inside <template>
+  * GHSA-55q2-fjhq-7xh7: XSS, IN_PLACE hook removal leaves a
+    detached subtree executable
+  * GHSA-c2j3-45gr-mqc4: CUSTOM_ELEMENT_HANDLING bypasses
+    afterSanitizeElements
+
+-------------------------------------------------------------------

Old:
----
  comfyui_frontend_package-1.51.9.tar.gz

New:
----
  comfyui_frontend_package-1.52.7.tar.gz

++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Other differences:
------------------
++++++ python-comfyui-frontend-package.spec ++++++
--- /var/tmp/diff_new_pack.gEteIh/_old  2026-09-08 16:55:29.825418813 +0200
+++ /var/tmp/diff_new_pack.gEteIh/_new  2026-09-08 16:55:29.827418896 +0200
@@ -16,12 +16,15 @@
 #
 
 Name:           python-comfyui-frontend-package
-Version:        1.51.9
+Version:        1.52.7
 Release:        0
 Summary:        Official ComfyUI frontend as a Python package
 # Legal-Review-Notice: sdist ships no LICENSE file; upstream
 # Comfy-Org/ComfyUI_frontend declares GPL-3.0-only in package.json
 License:        GPL-3.0-only
+# The static/ tree is a prebuilt browser bundle and vendors DOMPurify
+# (3.4.13 here, grep DOMPurify.version in static/assets). Check its
+# advisories on every bump -- they do not show up as ComfyUI_frontend CVEs.
 URL:            https://github.com/Comfy-Org/ComfyUI_frontend
 Source0:        
https://files.pythonhosted.org/packages/source/c/comfyui_frontend_package/comfyui_frontend_package-%{version}.tar.gz
 BuildRequires:  %{python_module pip}

++++++ comfyui_frontend_package-1.51.9.tar.gz -> 
comfyui_frontend_package-1.52.7.tar.gz ++++++
/work/SRC/openSUSE:Factory/python-comfyui-frontend-package/comfyui_frontend_package-1.51.9.tar.gz
 
/work/SRC/openSUSE:Factory/.python-comfyui-frontend-package.new.1265/comfyui_frontend_package-1.52.7.tar.gz
 differ: char 5, line 1

Reply via email to