Script 'mail_helper' called by obssrc Hello community, here is the log from the commit of package vexctl for openSUSE:Factory checked in at 2026-09-10 11:48:13 ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Comparing /work/SRC/openSUSE:Factory/vexctl (Old) and /work/SRC/openSUSE:Factory/.vexctl.new.1265 (New) ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Package is "vexctl" Thu Sep 10 11:48:13 2026 rev:14 rq:1376661 version:0.4.4+git70.36f6f3a Changes: -------- --- /work/SRC/openSUSE:Factory/vexctl/vexctl.changes 2026-07-26 11:32:03.214111829 +0200 +++ /work/SRC/openSUSE:Factory/.vexctl.new.1265/vexctl.changes 2026-09-10 11:51:25.099658611 +0200 @@ -1,0 +2,41 @@ +Wed Sep 09 15:30:10 UTC 2026 - Jeff Kowalczyk <[email protected]> + +- Update to version 0.4.4+git70.36f6f3a: + * Fix Windows failures found by the OS test matrix + * Add race detector to tests in CI + * Modernize the release SBOM + * Test on the stable Go release across operating systems + * Drop the snapshot workflow + * Update readme + * Add e2e registry test + * Fix image reference resolution + * Attach attestations as OCI referrers and read both layouts + * Move signing to sigstore bundles + * Bump dep versions + * Compute Go versions and run matrix tests + * build(deps): Bump github.com/google/go-containerregistry + * build(deps): Bump the all group across 1 directory with 2 updates + * build(deps): Bump github.com/sirupsen/logrus + * build(deps): Bump github.com/google/go-containerregistry + * Do not dereference a missing document timestamp in ApplySingleVEX +- Packaging improvements: + * Update to BuildRequires: golang(API) >= 1.27 matching go.mod + +------------------------------------------------------------------- +Tue Sep 08 02:17:54 UTC 2026 - Jeff Kowalczyk <[email protected]> + +- Update to version 0.4.4+git44.d69ce1a: + * build(deps): Bump google.golang.org/grpc from 1.82.1 to 1.83.1 + * build(deps): Bump the all group across 1 directory with 5 updates + * Add OWNERS and aliases with new maintainers + * build(deps): Bump the all group with 2 updates + * build(deps): Bump github.com/stretchr/testify from 1.11.1 to 1.12.0 + * build(deps): Bump github.com/sirupsen/logrus from 1.9.4 to 1.10.0 + * build(deps): Bump chainguard-dev/actions/boilerplate in the all group + * build(deps): Bump the all group with 2 updates + * fix: append package name to repository_url when normalizing oci purls + * build(deps): Bump chainguard-dev/actions/boilerplate in the all group + * build(deps): Bump the all group with 2 updates + * build(deps): Bump chainguard-dev/actions/boilerplate in the all group + +------------------------------------------------------------------- Old: ---- vexctl-0.4.4+git20.5d61136.tar.gz New: ---- vexctl-0.4.4+git70.36f6f3a.tar.gz ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Other differences: ------------------ ++++++ vexctl.spec ++++++ --- /var/tmp/diff_new_pack.bLKX8p/_old 2026-09-10 11:51:25.927693338 +0200 +++ /var/tmp/diff_new_pack.bLKX8p/_new 2026-09-10 11:51:25.930693463 +0200 @@ -17,7 +17,7 @@ Name: vexctl -Version: 0.4.4+git20.5d61136 +Version: 0.4.4+git70.36f6f3a Release: 0 Summary: CLI tool to create, transform and attest VEX metadata License: Apache-2.0 @@ -25,7 +25,7 @@ URL: https://github.com/openvex/vexctl Source: %{name}-%{version}.tar.gz Source1: vendor.tar.gz -BuildRequires: golang(API) >= 1.25 +BuildRequires: golang(API) >= 1.27 %description vexctl is a CLI tool to create, apply, and attest VEX (Vulnerability ++++++ _servicedata ++++++ --- /var/tmp/diff_new_pack.bLKX8p/_old 2026-09-10 11:51:25.998696315 +0200 +++ /var/tmp/diff_new_pack.bLKX8p/_new 2026-09-10 11:51:26.005696609 +0200 @@ -1,6 +1,6 @@ <servicedata> <service name="tar_scm"> <param name="url">https://github.com/openvex/vexctl.git</param> - <param name="changesrevision">5d61136c68c4749bbaf3fdc18f5da38c35fefca2</param></service></servicedata> + <param name="changesrevision">36f6f3a36438e3e514e3ec13394fb7a0c8f0e986</param></service></servicedata> (No newline at EOF) ++++++ vendor.tar.gz ++++++ /work/SRC/openSUSE:Factory/vexctl/vendor.tar.gz /work/SRC/openSUSE:Factory/.vexctl.new.1265/vendor.tar.gz differ: char 24, line 1 ++++++ vexctl-0.4.4+git20.5d61136.tar.gz -> vexctl-0.4.4+git70.36f6f3a.tar.gz ++++++ /work/SRC/openSUSE:Factory/vexctl/vexctl-0.4.4+git20.5d61136.tar.gz /work/SRC/openSUSE:Factory/.vexctl.new.1265/vexctl-0.4.4+git70.36f6f3a.tar.gz differ: char 12, line 1
