Script 'mail_helper' called by obssrc
Hello community,

here is the log from the commit of package bubblewrap for openSUSE:Factory 
checked in at 2026-09-08 16:53:10
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Comparing /work/SRC/openSUSE:Factory/bubblewrap (Old)
 and      /work/SRC/openSUSE:Factory/.bubblewrap.new.1265 (New)
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Package is "bubblewrap"

Tue Sep  8 16:53:10 2026 rev:25 rq:1376120 version:0.12.0

Changes:
--------
--- /work/SRC/openSUSE:Factory/bubblewrap/bubblewrap.changes    2026-05-04 
12:48:55.810148207 +0200
+++ /work/SRC/openSUSE:Factory/.bubblewrap.new.1265/bubblewrap.changes  
2026-09-08 16:53:40.891868413 +0200
@@ -1,0 +2,24 @@
+Mon Aug 31 07:39:37 UTC 2026 - Kyle Scheuing <[email protected]>
+
+- update to 0.12.0:
+  * The flag --not-a-security-boundary was added. If this is enabled
+    then failure of some sandbox setup steps (like remounting a
+    submount) are not fatal.
+  * The license has been updated from LGPL 2.0 (or later) to LGPL 2.1
+    (or later).
+  * This version removes the support for building a setuid
+    bubblewrap. Changes in this version made it difficult to support
+    and basically all modern linux distributions now support
+    unprivileged user namespaces to some extent.
+  * The assume_kernel build option was added, if specified no backwards
+    compatiblity for kernels older than this is built in (and will result
+    in hard failures at runtime). Currently specifying 5.6.0 or
+    later will disable the fallback implementation of
+    openat2(RESOLVE_IN_ROOT).
+  * Bubblewrap now correctly resolves absolute symlinks during the
+    sandbox setup by using openat2 with RESOLVE_IN_ROOT (or a fallback
+    implementation). This fixes a security issue (GHSA-pxhw-h44j-8pfx)
+    where file or directories created during sandbox setup could
+    follow parent symlinks out of the sandbox.
+
+-------------------------------------------------------------------

Old:
----
  bubblewrap-0.11.2.tar.xz
  bubblewrap-0.11.2.tar.xz.sha256sum

New:
----
  bubblewrap-0.12.0.tar.xz
  bubblewrap-0.12.0.tar.xz.sha256sum

++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Other differences:
------------------
++++++ bubblewrap.spec ++++++
--- /var/tmp/diff_new_pack.D27hUV/_old  2026-09-08 16:53:41.568896817 +0200
+++ /var/tmp/diff_new_pack.D27hUV/_new  2026-09-08 16:53:41.570896901 +0200
@@ -18,10 +18,10 @@
 
 
 Name:           bubblewrap
-Version:        0.11.2
+Version:        0.12.0
 Release:        0
 Summary:        Core execution tool for unprivileged containers
-License:        LGPL-2.0-or-later
+License:        LGPL-2.1-or-later
 Group:          Productivity/Security
 URL:            https://github.com/containers/bubblewrap
 Source0:        %{url}/releases/download/v%{version}/%{name}-%{version}.tar.xz

++++++ bubblewrap-0.11.2.tar.xz -> bubblewrap-0.12.0.tar.xz ++++++
++++ 4493 lines of diff (skipped)

++++++ bubblewrap-0.11.2.tar.xz.sha256sum -> bubblewrap-0.12.0.tar.xz.sha256sum 
++++++
--- /work/SRC/openSUSE:Factory/bubblewrap/bubblewrap-0.11.2.tar.xz.sha256sum    
2026-05-04 12:48:55.802147877 +0200
+++ 
/work/SRC/openSUSE:Factory/.bubblewrap.new.1265/bubblewrap-0.12.0.tar.xz.sha256sum
  2026-09-08 16:53:40.882868036 +0200
@@ -1 +1 @@
-69abc30005d2186baf7737feacd8da35633b93cf5af38838ecff17c5f8e924f6 
*bubblewrap-0.11.2.tar.xz
+9760d007363e3abba7c747489910f9f82d9fca53ba3bd3282e396fa3c97a3314 
*bubblewrap-0.12.0.tar.xz

Reply via email to