Script 'mail_helper' called by obssrc
Hello community,
here is the log from the commit of package google-guest-agent for
openSUSE:Factory checked in at 2026-09-22 15:50:30
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Comparing /work/SRC/openSUSE:Factory/google-guest-agent (Old)
and /work/SRC/openSUSE:Factory/.google-guest-agent.new.383539 (New)
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Package is "google-guest-agent"
Tue Sep 22 15:50:30 2026 rev:71 rq:1379663 version:20260917.00
Changes:
--------
--- /work/SRC/openSUSE:Factory/google-guest-agent/google-guest-agent.changes
2026-09-10 17:58:22.624473969 +0200
+++
/work/SRC/openSUSE:Factory/.google-guest-agent.new.383539/google-guest-agent.changes
2026-09-22 15:50:40.541891619 +0200
@@ -1,0 +2,36 @@
+Mon Sep 21 14:35:08 UTC 2026 - John Paul Adrian Glaubitz
<[email protected]>
+
+- Update to version 20260917.00
+ * Validate username using unicode.IsSpace to reject
+ all Unicode whitespace characters (#637)
+ * Update dependencies to latest (#636)
+ * fix octal digit comparison in morePermissive (#631)
+ * Remove KillMode from google-guest-agent-manager (#629)
+ * Fix SUSE Linux Micro 6+ (#628) (bsc#1253357)
+ * Exclude irrelevant tests on FreeBSD (#625)
+ * Replace abandoned serial dependency (#624)
+ * Add build rules for MWLID extension
+
+-------------------------------------------------------------------
+Wed Sep 16 11:09:19 UTC 2026 - Robert Schweikert <[email protected]>
+
+- Undo changes for the -fallback package creation
+ + After additional conversations with Google it was agreed to keep the
+ "old sources", i.e. guest-agent in the google-guest-agent RPM package
+ and not create a -fallback package. The "new sources", i.e.
+ google-guest-agent, will be added via a new google-guest-agent-manager
+ package
+
+-------------------------------------------------------------------
+Wed Sep 16 09:06:43 UTC 2026 - John Paul Adrian Glaubitz
<[email protected]>
+
+- Update golang.org/x/crypto to v0.57.0 (bsc#1278597,
+ CVE-2026-56854, CVE-2026-56855, CVE-2026-78662)
+
+--------------------------------------------------------------------
+Mon Sep 14 12:49:29 UTC 2026 - Robert Schweikert <[email protected]>
+
+- Introduce -fallback package using the guest-agent sources (#jsc-PED-15389)
+- Ship gce-workload-cert-refresh.timer (bsc#1273192)
+
+-------------------------------------------------------------------
@@ -65,0 +102,8 @@
+- CVE-2026-56852: golang.org/x/text/unicode/norm: infinite loop on
+ truncated/invalid UTF-8 input (bsc#1272118)
+ * CVE-2026-56852.patch
+
+-------------------------------------------------------------------
+Wed Jun 17 10:09:52 UTC 2026 - John Paul Adrian Glaubitz
<[email protected]>
+
+- Drop CVE-2026-33186.patch, merged upstream
@@ -115,0 +160,6 @@
+Wed May 13 10:17:57 UTC 2026 - John Paul Adrian Glaubitz
<[email protected]>
+
+- Add CVE-2026-33186.patch to fix authorization bypass in grpc-go due to
improper
+ validation of the HTTP/2 :path pseudo-header (bsc#1260264, CVE-2026-33186)
+
+-------------------------------------------------------------------
@@ -1276,0 +1327,5 @@
+
+-------------------------------------------------------------------
+Fri May 23 08:32:58 UTC 2025 - John Paul Adrian Glaubitz
<[email protected]>
+
+- Update to version 20250506.01 (bsc#1243254, bsc#1243505)
Old:
----
guest-agent-20260903.01.tar.gz
New:
----
guest-agent-20260917.00.tar.gz
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Other differences:
------------------
++++++ google-guest-agent.spec ++++++
--- /var/tmp/diff_new_pack.xfMAL7/_old 2026-09-22 15:50:41.504931796 +0200
+++ /var/tmp/diff_new_pack.xfMAL7/_new 2026-09-22 15:50:41.505931838 +0200
@@ -19,7 +19,7 @@
%define shortname guest-agent
Name: google-guest-agent
-Version: 20260903.01
+Version: 20260917.00
Release: 0
Summary: Google Cloud Guest Agent
License: Apache-2.0
++++++ _service ++++++
--- /var/tmp/diff_new_pack.xfMAL7/_old 2026-09-22 15:50:41.543933423 +0200
+++ /var/tmp/diff_new_pack.xfMAL7/_new 2026-09-22 15:50:41.546933549 +0200
@@ -3,8 +3,8 @@
<param
name="url">https://github.com/GoogleCloudPlatform/guest-agent/</param>
<param name="scm">git</param>
<param name="exclude">.git</param>
- <param name="versionformat">20260903.01</param>
- <param name="revision">20260903.01</param>
+ <param name="versionformat">20260917.00</param>
+ <param name="revision">20260917.00</param>
<param name="changesgenerate">enable</param>
</service>
<service name="recompress" mode="disabled">
@@ -15,8 +15,8 @@
<param name="basename">guest-agent</param>
</service>
<service name="go_modules" mode="disabled">
- <param name="archive">guest-agent-20260903.01.tar.gz</param>
- <param
name="replace">golang.org/x/crypto=golang.org/x/[email protected]</param>
+ <param name="archive">guest-agent-20260917.00.tar.gz</param>
+ <param
name="replace">golang.org/x/crypto=golang.org/x/[email protected]</param>
</service>
</services>
++++++ _servicedata ++++++
--- /var/tmp/diff_new_pack.xfMAL7/_old 2026-09-22 15:50:41.569934508 +0200
+++ /var/tmp/diff_new_pack.xfMAL7/_new 2026-09-22 15:50:41.572934633 +0200
@@ -1,6 +1,6 @@
<servicedata>
<service name="tar_scm">
<param
name="url">https://github.com/GoogleCloudPlatform/guest-agent/</param>
- <param
name="changesrevision">3852c03a09c6eb8fb44e0ea3bdd5d7677c5bf87a</param></service></servicedata>
+ <param
name="changesrevision">9c6ad8833a3ac64f49b735844b29f5ea1f9357c5</param></service></servicedata>
(No newline at EOF)
++++++ guest-agent-20260903.01.tar.gz -> guest-agent-20260917.00.tar.gz ++++++
++++ 2580 lines of diff (skipped)
++++++ vendor.tar.gz ++++++
/work/SRC/openSUSE:Factory/google-guest-agent/vendor.tar.gz
/work/SRC/openSUSE:Factory/.google-guest-agent.new.383539/vendor.tar.gz differ:
char 22, line 1