Script 'mail_helper' called by obssrc
Hello community,
here is the log from the commit of package python-comfyui-frontend-package for
openSUSE:Factory checked in at 2026-09-08 16:54:23
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Comparing /work/SRC/openSUSE:Factory/python-comfyui-frontend-package (Old)
and /work/SRC/openSUSE:Factory/.python-comfyui-frontend-package.new.1265
(New)
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Package is "python-comfyui-frontend-package"
Tue Sep 8 16:54:23 2026 rev:4 rq:1376109 version:1.52.7
Changes:
--------
---
/work/SRC/openSUSE:Factory/python-comfyui-frontend-package/python-comfyui-frontend-package.changes
2026-08-27 18:56:02.159386583 +0200
+++
/work/SRC/openSUSE:Factory/.python-comfyui-frontend-package.new.1265/python-comfyui-frontend-package.changes
2026-09-08 16:55:28.219352583 +0200
@@ -1,0 +2,27 @@
+Mon Sep 7 06:38:03 UTC 2026 - Martin Pluskal <[email protected]>
+
+- Update to 1.52.7:
+ * Moves to the 1.52 line, which is ahead of the version ComfyUI's
+ own requirements.txt names; read as static data, and upstream's
+ version check only warns when below the pin
+ * Node display names, widget labels, output names and tooltips now
+ resolved from the backend at read time -- extensions must key on
+ widget.name, not widget.label
+ * Client-side video metadata extraction via mediabunny; 3D camera
+ widget for CreateCameraInfo; RESOLUTION_PREVIEW readout widget
+ * Non-UUID workflow ids lazily migrated to a fresh UUID
+ * Static v-html sinks removed
+ * Ctrl/Cmd shortcuts no longer fall through to the browser; hidden
+ ARIA dialogs no longer block global shortcuts
+ * API key user authentication restored
+ * Comfy Cloud partner nodes branded on canvas and in the registry
+- Bundled DOMPurify 3.4.7 -> 3.4.13, which fixes:
+ * CVE-2026-65898: permanent ALLOWED_ATTR pollution via setConfig()
+ * CVE-2026-65899: Trusted Types policy survives clearConfig()
+ * CVE-2026-65900: SAFE_FOR_TEMPLATES bypass inside <template>
+ * GHSA-55q2-fjhq-7xh7: XSS, IN_PLACE hook removal leaves a
+ detached subtree executable
+ * GHSA-c2j3-45gr-mqc4: CUSTOM_ELEMENT_HANDLING bypasses
+ afterSanitizeElements
+
+-------------------------------------------------------------------
Old:
----
comfyui_frontend_package-1.51.9.tar.gz
New:
----
comfyui_frontend_package-1.52.7.tar.gz
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Other differences:
------------------
++++++ python-comfyui-frontend-package.spec ++++++
--- /var/tmp/diff_new_pack.gEteIh/_old 2026-09-08 16:55:29.825418813 +0200
+++ /var/tmp/diff_new_pack.gEteIh/_new 2026-09-08 16:55:29.827418896 +0200
@@ -16,12 +16,15 @@
#
Name: python-comfyui-frontend-package
-Version: 1.51.9
+Version: 1.52.7
Release: 0
Summary: Official ComfyUI frontend as a Python package
# Legal-Review-Notice: sdist ships no LICENSE file; upstream
# Comfy-Org/ComfyUI_frontend declares GPL-3.0-only in package.json
License: GPL-3.0-only
+# The static/ tree is a prebuilt browser bundle and vendors DOMPurify
+# (3.4.13 here, grep DOMPurify.version in static/assets). Check its
+# advisories on every bump -- they do not show up as ComfyUI_frontend CVEs.
URL: https://github.com/Comfy-Org/ComfyUI_frontend
Source0:
https://files.pythonhosted.org/packages/source/c/comfyui_frontend_package/comfyui_frontend_package-%{version}.tar.gz
BuildRequires: %{python_module pip}
++++++ comfyui_frontend_package-1.51.9.tar.gz ->
comfyui_frontend_package-1.52.7.tar.gz ++++++
/work/SRC/openSUSE:Factory/python-comfyui-frontend-package/comfyui_frontend_package-1.51.9.tar.gz
/work/SRC/openSUSE:Factory/.python-comfyui-frontend-package.new.1265/comfyui_frontend_package-1.52.7.tar.gz
differ: char 5, line 1