Script 'mail_helper' called by obssrc
Hello community,

here is the log from the commit of package plexus-archiver for openSUSE:Factory 
checked in at 2026-09-29 17:49:24
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Comparing /work/SRC/openSUSE:Factory/plexus-archiver (Old)
 and      /work/SRC/openSUSE:Factory/.plexus-archiver.new.383539 (New)
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Package is "plexus-archiver"

Tue Sep 29 17:49:24 2026 rev:15 rq:1381209 version:4.14.0

Changes:
--------
--- /work/SRC/openSUSE:Factory/plexus-archiver/plexus-archiver.changes  
2026-06-18 18:45:21.544897948 +0200
+++ 
/work/SRC/openSUSE:Factory/.plexus-archiver.new.383539/plexus-archiver.changes  
    2026-09-29 17:50:45.313651025 +0200
@@ -1,0 +2,26 @@
+Mon Sep 28 11:32:02 UTC 2026 - Fridrich Strba <[email protected]>
+
+- Upgrade to upsteam version 4.14.0
+  * New features and improvements
+    + Let a FileSet follow symbolic links
+  * Documentation updates
+    + Describe the artifact in the POM
+  * Dependency updates
+    + Pin Guava on the test classpath
+    + Bump com.github.luben:zstd-jni from 1.5.7-14 to 1.5.7-15
+- Changes of version 4.13.0
+  * New features and improvements
+    + Establish an automatic module name
+  * Dependency updates
+    + Bump plexus-io to 3.7.0
+    + Bump plexus-utils to 3.6.2
+    + Update parent to plexus 27, from 25
+    + Bump com.github.luben:zstd-jni from 1.5.7-9 to 1.5.7-14
+    + Bump org.eclipse.sisu:org.eclipse.sisu.inject from 1.0.0 to
+      1.1.0
+    + Revert "Bump slf4jVersion from 1.7.36 to 2.0.18"
+  * Build
+    + Name the sisu property after what it versions
+    + Keep the 4.x release drafter config on the 4.x branch
+
+-------------------------------------------------------------------

Old:
----
  plexus-archiver-4.12.0.tar.gz

New:
----
  plexus-archiver-4.14.0.tar.gz

++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Other differences:
------------------
++++++ plexus-archiver.spec ++++++
--- /var/tmp/diff_new_pack.i76u6B/_old  2026-09-29 17:50:46.175687021 +0200
+++ /var/tmp/diff_new_pack.i76u6B/_new  2026-09-29 17:50:46.177687105 +0200
@@ -17,7 +17,7 @@
 
 
 Name:           plexus-archiver
-Version:        4.12.0
+Version:        4.14.0
 Release:        0
 Summary:        Plexus Archiver Component
 License:        Apache-2.0

++++++ _scmsync.obsinfo ++++++
--- /var/tmp/diff_new_pack.i76u6B/_old  2026-09-29 17:50:46.214688650 +0200
+++ /var/tmp/diff_new_pack.i76u6B/_new  2026-09-29 17:50:46.220688900 +0200
@@ -1,6 +1,6 @@
-mtime: 1781781760
-commit: 08295ac0206d846ab3f2650b63407aa1f00c486ead0a6d19b5f694628fbbc58d
+mtime: 1790595406
+commit: 0ecb4dec4a28449892c938960637f3e0cdcfbabcda3db3c6c06a8fad3f4f537c
 url: https://src.opensuse.org/java-packages/plexus-archiver
-revision: 08295ac0206d846ab3f2650b63407aa1f00c486ead0a6d19b5f694628fbbc58d
+revision: 0ecb4dec4a28449892c938960637f3e0cdcfbabcda3db3c6c06a8fad3f4f537c
 projectscmsync: https://src.opensuse.org/java-packages/_ObsPrj
 

++++++ build.specials.obscpio ++++++

++++++ build.specials.obscpio ++++++
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/.gitignore new/.gitignore
--- old/.gitignore      1970-01-01 01:00:00.000000000 +0100
+++ new/.gitignore      2026-09-28 13:36:46.000000000 +0200
@@ -0,0 +1 @@
+.osc

++++++ plexus-archiver-4.12.0.tar.gz -> plexus-archiver-4.14.0.tar.gz ++++++
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' 
old/plexus-archiver-plexus-archiver-4.12.0/.github/release-drafter-4.x.yml 
new/plexus-archiver-plexus-archiver-4.14.0/.github/release-drafter-4.x.yml
--- old/plexus-archiver-plexus-archiver-4.12.0/.github/release-drafter-4.x.yml  
1970-01-01 01:00:00.000000000 +0100
+++ new/plexus-archiver-plexus-archiver-4.14.0/.github/release-drafter-4.x.yml  
2026-08-23 14:43:30.000000000 +0200
@@ -0,0 +1,10 @@
+_extends: .github:.github/release-drafter.yml
+
+# tag-prefix is what lets the drafter parse the version out of the last tag.
+# Without it the drafter reads what it can from the tag string, and plexus-i18n
+# once drafted 18.0.1 by finding the 18 in its own name.
+tag-prefix: plexus-archiver-
+tag-template: plexus-archiver-$RESOLVED_VERSION
+version-template: 4.$MINOR.$PATCH
+commitish: 4.x
+filter-by-commitish: true
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' 
old/plexus-archiver-plexus-archiver-4.12.0/.github/workflows/release-drafter.yml
 
new/plexus-archiver-plexus-archiver-4.14.0/.github/workflows/release-drafter.yml
--- 
old/plexus-archiver-plexus-archiver-4.12.0/.github/workflows/release-drafter.yml
    2026-06-08 22:12:22.000000000 +0200
+++ 
new/plexus-archiver-plexus-archiver-4.14.0/.github/workflows/release-drafter.yml
    2026-08-23 14:43:30.000000000 +0200
@@ -1,12 +1,15 @@
-name: Release Drafter
+name: Release Drafter 4.x
 on:
   push:
     branches:
-      - master
+      - 4.x
 jobs:
   update_release_draft:
     runs-on: ubuntu-latest
     steps:
-      - uses: release-drafter/release-drafter@v7
+      - uses: release-drafter/[email protected]
+        with:
+          # Resolved against .github/ on the branch this workflow runs on, not 
on the default branch.
+          config-name: 'release-drafter-4.x.yml'
         env:
           GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/plexus-archiver-plexus-archiver-4.12.0/pom.xml 
new/plexus-archiver-plexus-archiver-4.14.0/pom.xml
--- old/plexus-archiver-plexus-archiver-4.12.0/pom.xml  2026-06-08 
22:12:22.000000000 +0200
+++ new/plexus-archiver-plexus-archiver-4.14.0/pom.xml  2026-08-23 
14:43:30.000000000 +0200
@@ -5,12 +5,14 @@
   <parent>
     <groupId>org.codehaus.plexus</groupId>
     <artifactId>plexus</artifactId>
-    <version>25</version>
+    <version>27</version>
   </parent>
 
   <artifactId>plexus-archiver</artifactId>
-  <version>4.12.0</version>
+  <version>4.14.0</version>
   <name>Plexus Archiver Component</name>
+  <description>One API for creating and extracting archives - zip, jar, tar 
and their compressed
+    variants - regardless of format.</description>
 
   <url>https://codehaus-plexus.github.io/plexus-archiver/</url>
 
@@ -30,7 +32,7 @@
   <scm>
     
<connection>scm:git:https://github.com/codehaus-plexus/plexus-archiver.git</connection>
     
<developerConnection>scm:git:https://github.com/codehaus-plexus/plexus-archiver.git</developerConnection>
-    <tag>plexus-archiver-4.12.0</tag>
+    <tag>plexus-archiver-4.14.0</tag>
     
<url>https://github.com/codehaus-plexus/plexus-archiver/tree/${project.scm.tag}/</url>
   </scm>
   <issueManagement>
@@ -46,8 +48,8 @@
 
   <properties>
     <slf4jVersion>1.7.36</slf4jVersion>
-    <sisuMavenPluginVersion>1.0.0</sisuMavenPluginVersion>
-    
<project.build.outputTimestamp>2026-06-08T20:12:00Z</project.build.outputTimestamp>
+    <version.sisu>1.1.0</version.sisu>
+    
<project.build.outputTimestamp>2026-08-23T12:40:45Z</project.build.outputTimestamp>
   </properties>
 
   <dependencies>
@@ -61,12 +63,12 @@
     <dependency>
       <groupId>org.codehaus.plexus</groupId>
       <artifactId>plexus-utils</artifactId>
-      <version>3.6.1</version>
+      <version>3.6.2</version>
     </dependency>
     <dependency>
       <groupId>org.codehaus.plexus</groupId>
       <artifactId>plexus-io</artifactId>
-      <version>3.6.0</version>
+      <version>3.7.0</version>
     </dependency>
     <dependency>
       <groupId>org.apache.commons</groupId>
@@ -92,7 +94,7 @@
     <dependency>
       <groupId>com.github.luben</groupId>
       <artifactId>zstd-jni</artifactId>
-      <version>1.5.7-9</version>
+      <version>1.5.7-15</version>
       <scope>runtime</scope>
     </dependency>
     <dependency>
@@ -122,7 +124,7 @@
     <dependency>
       <groupId>org.eclipse.sisu</groupId>
       <artifactId>org.eclipse.sisu.inject</artifactId>
-      <version>${sisuMavenPluginVersion}</version>
+      <version>${version.sisu}</version>
       <scope>test</scope>
     </dependency>
     <dependency>
@@ -131,6 +133,16 @@
       <version>5.1.0</version>
       <scope>test</scope>
     </dependency>
+    <!-- Guice 5.1.0 drags in Guava 30.1-jre, which CVE-2023-2976 and
+         CVE-2020-8908 cover. Nothing here uses Guava; the pin only keeps
+         the flagged version off the test classpath. 33.7.1-jre is still
+         Java 8 bytecode, so it holds on this line. -->
+    <dependency>
+      <groupId>com.google.guava</groupId>
+      <artifactId>guava</artifactId>
+      <version>33.7.1-jre</version>
+      <scope>test</scope>
+    </dependency>
     <dependency>
       <groupId>org.assertj</groupId>
       <artifactId>assertj-core</artifactId>
@@ -143,6 +155,17 @@
     <plugins>
       <plugin>
         <groupId>org.apache.maven.plugins</groupId>
+        <artifactId>maven-jar-plugin</artifactId>
+        <configuration>
+          <archive>
+            <manifestEntries>
+              
<Automatic-Module-Name>org.codehaus.plexus.archiver</Automatic-Module-Name>
+            </manifestEntries>
+          </archive>
+        </configuration>
+      </plugin>
+      <plugin>
+        <groupId>org.apache.maven.plugins</groupId>
         <artifactId>maven-release-plugin</artifactId>
         <configuration>
           <!-- olamy: exclude files with strange names as failed here on osx 
-->
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' 
old/plexus-archiver-plexus-archiver-4.12.0/src/main/java/org/codehaus/plexus/archiver/AbstractArchiver.java
 
new/plexus-archiver-plexus-archiver-4.14.0/src/main/java/org/codehaus/plexus/archiver/AbstractArchiver.java
--- 
old/plexus-archiver-plexus-archiver-4.12.0/src/main/java/org/codehaus/plexus/archiver/AbstractArchiver.java
 2026-06-08 22:12:22.000000000 +0200
+++ 
new/plexus-archiver-plexus-archiver-4.14.0/src/main/java/org/codehaus/plexus/archiver/AbstractArchiver.java
 2026-08-23 14:43:30.000000000 +0200
@@ -331,7 +331,7 @@
         // The PlexusIoFileResourceCollection contains platform-specific 
File.separatorChar which
         // is an interesting cause of grief, see PLXCOMP-192
         final PlexusIoFileResourceCollection collection = new 
PlexusIoFileResourceCollection();
-        collection.setFollowingSymLinks(false);
+        collection.setFollowingSymLinks(fileSet.isFollowingSymLinks());
 
         collection.setIncludes(fileSet.getIncludes());
         collection.setExcludes(fileSet.getExcludes());
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' 
old/plexus-archiver-plexus-archiver-4.12.0/src/main/java/org/codehaus/plexus/archiver/FileSet.java
 
new/plexus-archiver-plexus-archiver-4.14.0/src/main/java/org/codehaus/plexus/archiver/FileSet.java
--- 
old/plexus-archiver-plexus-archiver-4.12.0/src/main/java/org/codehaus/plexus/archiver/FileSet.java
  2026-06-08 22:12:22.000000000 +0200
+++ 
new/plexus-archiver-plexus-archiver-4.14.0/src/main/java/org/codehaus/plexus/archiver/FileSet.java
  2026-08-23 14:43:30.000000000 +0200
@@ -14,4 +14,20 @@
      * Returns the file sets base directory.
      */
     File getDirectory();
+
+    /**
+     * Returns whether symbolic links below the base directory are followed.
+     * <p>
+     * When {@code false} (the default), a symbolic link is added to the 
archive as a link and the
+     * contents of a linked directory are not scanned. When {@code true}, 
links are resolved: a
+     * linked directory is added as a directory and its target's contents are 
included.
+     * <p>
+     * Following links means the scan can descend into a directory that links 
back to one of its own
+     * ancestors, so only enable it for trees known not to contain such cycles.
+     *
+     * @since 4.14.0
+     */
+    default boolean isFollowingSymLinks() {
+        return false;
+    }
 }
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' 
old/plexus-archiver-plexus-archiver-4.12.0/src/main/java/org/codehaus/plexus/archiver/util/DefaultFileSet.java
 
new/plexus-archiver-plexus-archiver-4.14.0/src/main/java/org/codehaus/plexus/archiver/util/DefaultFileSet.java
--- 
old/plexus-archiver-plexus-archiver-4.12.0/src/main/java/org/codehaus/plexus/archiver/util/DefaultFileSet.java
      2026-06-08 22:12:22.000000000 +0200
+++ 
new/plexus-archiver-plexus-archiver-4.14.0/src/main/java/org/codehaus/plexus/archiver/util/DefaultFileSet.java
      2026-08-23 14:43:30.000000000 +0200
@@ -15,6 +15,8 @@
 
     private File directory;
 
+    private boolean followingSymLinks;
+
     public DefaultFileSet(File directory) {
         this.directory = directory;
     }
@@ -33,6 +35,28 @@
         return directory;
     }
 
+    /**
+     * Sets whether symbolic links below the base directory are followed. 
Defaults to false.
+     *
+     * @since 4.14.0
+     */
+    public void setFollowingSymLinks(boolean followingSymLinks) {
+        this.followingSymLinks = followingSymLinks;
+    }
+
+    @Override
+    public boolean isFollowingSymLinks() {
+        return followingSymLinks;
+    }
+
+    /**
+     * @since 4.14.0
+     */
+    public DefaultFileSet followingSymLinks(boolean followingSymLinks) {
+        setFollowingSymLinks(followingSymLinks);
+        return this;
+    }
+
     public static DefaultFileSet fileSet(File directory) {
         final DefaultFileSet defaultFileSet = new DefaultFileSet(directory);
         return defaultFileSet;
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' 
old/plexus-archiver-plexus-archiver-4.12.0/src/test/java/org/codehaus/plexus/archiver/SymlinkTest.java
 
new/plexus-archiver-plexus-archiver-4.14.0/src/test/java/org/codehaus/plexus/archiver/SymlinkTest.java
--- 
old/plexus-archiver-plexus-archiver-4.12.0/src/test/java/org/codehaus/plexus/archiver/SymlinkTest.java
      2026-06-08 22:12:22.000000000 +0200
+++ 
new/plexus-archiver-plexus-archiver-4.14.0/src/test/java/org/codehaus/plexus/archiver/SymlinkTest.java
      2026-08-23 14:43:30.000000000 +0200
@@ -7,6 +7,7 @@
 import org.codehaus.plexus.archiver.tar.TarArchiver;
 import org.codehaus.plexus.archiver.tar.TarLongFileMode;
 import org.codehaus.plexus.archiver.tar.TarUnArchiver;
+import org.codehaus.plexus.archiver.util.DefaultFileSet;
 import org.codehaus.plexus.archiver.zip.ZipArchiver;
 import org.codehaus.plexus.archiver.zip.ZipUnArchiver;
 import org.junit.jupiter.api.Test;
@@ -106,4 +107,37 @@
         symbolicLink = new 
File("target/output/dirarchiver-symlink/aDirWithALink/backOutsideToFileX");
         assertTrue(Files.isSymbolicLink(symbolicLink.toPath()));
     }
+
+    @Test
+    void fileSetDoesNotFollowSymLinksByDefault() {
+        assertFalse(new 
DefaultFileSet(getTestFile("src/test/resources/symlinks/src")).isFollowingSymLinks());
+    }
+
+    @Test
+    @DisabledOnOs(OS.WINDOWS)
+    void followingSymLinksResolvesLinkedDirectories() throws Exception {
+        DirectoryArchiver archiver = (DirectoryArchiver) 
lookup(Archiver.class, "dir");
+
+        File dummyContent = getTestFile("src/test/resources/symlinks/src");
+        archiver.addFileSet(new 
DefaultFileSet(dummyContent).followingSymLinks(true));
+        final File archiveFile = new 
File("target/output/dirarchiver-followed-symlink");
+        archiveFile.mkdirs();
+        archiver.setDestFile(archiveFile);
+
+        archiver.createArchive();
+
+        // a link to a directory becomes the directory, and its target's 
contents are included
+        File linkedDir = new File(archiveFile, "symDir");
+        assertFalse(Files.isSymbolicLink(linkedDir.toPath()));
+        assertTrue(linkedDir.isDirectory());
+        assertTrue(new File(linkedDir, "targetFile.txt").isFile());
+
+        // including when the target lies outside the base directory
+        assertTrue(new File(archiveFile, 
"symLinkToDirOnTheOutside/FileInDirOnTheOutside.txt").isFile());
+
+        // a link to a file becomes the file
+        File linkedFile = new File(archiveFile, "symR");
+        assertFalse(Files.isSymbolicLink(linkedFile.toPath()));
+        assertTrue(linkedFile.isFile());
+    }
 }

++++++ plexus-archiver-build.xml ++++++
--- /var/tmp/diff_new_pack.i76u6B/_old  2026-09-29 17:50:46.691708569 +0200
+++ /var/tmp/diff_new_pack.i76u6B/_new  2026-09-29 17:50:46.700708945 +0200
@@ -10,7 +10,7 @@
 
   <property name="project.groupId" value="org.codehaus.plexus"/>
   <property name="project.artifactId" value="plexus-archiver"/>
-  <property name="project.version" value="4.12.0"/>
+  <property name="project.version" value="4.14.0"/>
 
   <property name="compiler.release" value="8"/>
   <property name="compiler.source" value="1.${compiler.release}"/>
@@ -126,6 +126,7 @@
          basedir="${build.outputDir}"
          excludes="**/package.html">
       <manifest>
+        <attribute name="Automatic-Module-Name" 
value="org.codehaus.plexus.archiver"/>
         <attribute name="JavaPackages-ArtifactId" 
value="${project.artifactId}"/>
         <attribute name="JavaPackages-GroupId" value="${project.groupId}"/>
         <attribute name="JavaPackages-Version" value="${project.version}"/>

Reply via email to