Script 'mail_helper' called by obssrc
Hello community,

here is the log from the commit of package maven-resolver for openSUSE:Factory 
checked in at 2026-09-28 10:38:47
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Comparing /work/SRC/openSUSE:Factory/maven-resolver (Old)
 and      /work/SRC/openSUSE:Factory/.maven-resolver.new.383539 (New)
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Package is "maven-resolver"

Mon Sep 28 10:38:47 2026 rev:32 rq:1380275 version:2.0.23

Changes:
--------
--- 
/work/SRC/openSUSE:Factory/maven-resolver/maven-resolver-supplier-mvn3.changes  
    2026-08-26 19:56:45.784182755 +0200
+++ 
/work/SRC/openSUSE:Factory/.maven-resolver.new.383539/maven-resolver-supplier-mvn3.changes
  2026-09-28 10:39:34.384656836 +0200
@@ -1,0 +2,61 @@
+Fri Sep 18 08:11:36 UTC 2026 - Fridrich Strba <[email protected]>
+
+- Update to upstream version 2.0.23
+  * New features and improvements
+    + Finish the repo key story
+    + Fix: log only once the warning in DefRemoteRepoMan
+    + Fix #2058: Add links to configuration page
+    + Eliminate per-node HashSet allocation in PathConflictResolver
+  * Bug Fixes
+    + fix: accept locally cached artifacts via same-id fallback when
+      tracking URL changes
+    + Fix listener error swallowing
+    + MRESOLVER-379: Preserve relocated candidates from version
+      ranges
+    + Create the local repository directory before resolving its
+      real path
+    + Optimize TrackingFileManager unit tests and fix potential lock
+      leaks
+    + Validate the repository key used in checksum summary file
+      names
+    + fix: bound response reads and sanitize remote-derived strings
+    + fix: earn trust labels through verification and bind tracking
+      to URL
+    + fix: bind credentials to origin and reject TLS downgrade
+      redirects
+    + fix: prevent remote signals from weakening operator-configured
+      policy
+    + fix: atomic file publication and authenticated IPC lock daemon
+    + fix: deploy-side integrity must fail closed
+    + fix: harden opt-in transport and lock backends against
+      unauthenticated infrastructure
+    + Compose named lock keys one segment per coordinate field
+    + Resolve file transport locations with path operations instead
+      of substring matching
+    + Validate coordinate components in the Maven 2 layout and local
+      path composer
+  * Documentation updates
+    + docs: Clarify trusted checksum sources
+    + Fix #2058: Add links to configuration page
+  * Maintenance
+    + test: move from minio docker image
+    + Fix listener error swallowing
+    + Fix: tidy up f013
+    + Fix #2096: harden NamedLocksTrackingFileManagerTest against CI
+      load
+    + Carry repository provenance into aggregateRepositories
+    + Validate the repository key used as a local repository path
+      segment
+  * Dependency updates
+    + Bump org.apache.maven.plugin-tools:maven-plugin-tools-api from
+      3.15.2 to 3.16.0
+    + Bump version.slf4j from 2.0.18 to 2.0.19
+    + Bump org.eclipse.jetty:jetty-bom from 12.1.12 to 12.1.13
+    + Bump com.github.siom79.japicmp:japicmp-maven-plugin from
+      0.26.1 to 0.26.2
+    + Deps: bump to BC provider 1.85.2
+    + Bump org.codehaus.plexus:plexus-utils from 3.6.1 to 3.6.2
+    + Bump org.codehaus.plexus:plexus-xml from 4.1.1 to 4.2.0
+    + Stop dependabot from offering guice 7 on the 1.9.x line
+
+-------------------------------------------------------------------
maven-resolver-supplier-mvn4.changes: same change
maven-resolver.changes: same change

Old:
----
  maven-resolver-2.0.22-source-release.zip

New:
----
  maven-resolver-2.0.23-source-release.zip

++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Other differences:
------------------
++++++ maven-resolver-supplier-mvn3.spec ++++++
--- /var/tmp/diff_new_pack.yKlABU/_old  2026-09-28 10:39:35.188690551 +0200
+++ /var/tmp/diff_new_pack.yKlABU/_new  2026-09-28 10:39:35.189690593 +0200
@@ -20,7 +20,7 @@
 %define fragment_name supplier-mvn3
 %define _buildshell /bin/bash
 Name:           %{base_name}-%{fragment_name}
-Version:        2.0.22
+Version:        2.0.23
 Release:        0
 Summary:        Maven Artifact Resolver Instance Supplier Maven3
 License:        Apache-2.0

++++++ maven-resolver-supplier-mvn4.spec ++++++
--- /var/tmp/diff_new_pack.yKlABU/_old  2026-09-28 10:39:35.211691516 +0200
+++ /var/tmp/diff_new_pack.yKlABU/_new  2026-09-28 10:39:35.213691600 +0200
@@ -20,7 +20,7 @@
 %define fragment_name supplier-mvn4
 %define _buildshell /bin/bash
 Name:           %{base_name}-%{fragment_name}
-Version:        2.0.22
+Version:        2.0.23
 Release:        0
 Summary:        Maven Artifact Resolver Instance Supplier Maven3
 License:        Apache-2.0

++++++ maven-resolver.spec ++++++
--- /var/tmp/diff_new_pack.yKlABU/_old  2026-09-28 10:39:35.237692606 +0200
+++ /var/tmp/diff_new_pack.yKlABU/_new  2026-09-28 10:39:35.239692690 +0200
@@ -18,7 +18,7 @@
 
 %define _buildshell /bin/bash
 Name:           maven-resolver
-Version:        2.0.22
+Version:        2.0.23
 Release:        0
 Summary:        Apache Maven Artifact Resolver library
 License:        Apache-2.0

++++++ _scmsync.obsinfo ++++++
--- /var/tmp/diff_new_pack.yKlABU/_old  2026-09-28 10:39:35.280694409 +0200
+++ /var/tmp/diff_new_pack.yKlABU/_new  2026-09-28 10:39:35.284694577 +0200
@@ -1,6 +1,6 @@
-mtime: 1787642269
-commit: dce6d907835566c431ac72d74e53abab2f8e968581ec65c25d7cf82a98f64a8c
+mtime: 1789720143
+commit: 7dfdda28729c762307a8392abc85523708f2ff8a7972104398e7cf16e618e1f4
 url: https://src.opensuse.org/java-packages/maven-resolver
-revision: dce6d907835566c431ac72d74e53abab2f8e968581ec65c25d7cf82a98f64a8c
+revision: 7dfdda28729c762307a8392abc85523708f2ff8a7972104398e7cf16e618e1f4
 projectscmsync: https://src.opensuse.org/java-packages/_ObsPrj
 

++++++ build.specials.obscpio ++++++

++++++ build.specials.obscpio ++++++
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/.gitignore new/.gitignore
--- old/.gitignore      1970-01-01 01:00:00.000000000 +0100
+++ new/.gitignore      2026-09-18 10:29:03.000000000 +0200
@@ -0,0 +1 @@
+.osc

++++++ maven-resolver-2.0.22-source-release.zip -> 
maven-resolver-2.0.23-source-release.zip ++++++
++++ 12747 lines of diff (skipped)

++++++ maven-resolver-build.tar.xz ++++++
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/common.xml new/common.xml
--- old/common.xml      2026-08-25 08:59:13.208102376 +0200
+++ new/common.xml      2026-09-16 08:19:44.552363627 +0200
@@ -3,7 +3,7 @@
 <project name="common" basedir=".">
 
   <property file="build.properties"/>
-  <property name="project.version" value="2.0.22"/>
+  <property name="project.version" value="2.0.23"/>
   <property name="project.groupId" value="org.apache.maven.resolver"/>
   <property name="project.url" value="https://maven.apache.org/resolver/"/>
 

Reply via email to