Script 'mail_helper' called by obssrc
Hello community,
here is the log from the commit of package plexus-archiver for openSUSE:Factory
checked in at 2026-09-29 17:49:24
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Comparing /work/SRC/openSUSE:Factory/plexus-archiver (Old)
and /work/SRC/openSUSE:Factory/.plexus-archiver.new.383539 (New)
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Package is "plexus-archiver"
Tue Sep 29 17:49:24 2026 rev:15 rq:1381209 version:4.14.0
Changes:
--------
--- /work/SRC/openSUSE:Factory/plexus-archiver/plexus-archiver.changes
2026-06-18 18:45:21.544897948 +0200
+++
/work/SRC/openSUSE:Factory/.plexus-archiver.new.383539/plexus-archiver.changes
2026-09-29 17:50:45.313651025 +0200
@@ -1,0 +2,26 @@
+Mon Sep 28 11:32:02 UTC 2026 - Fridrich Strba <[email protected]>
+
+- Upgrade to upsteam version 4.14.0
+ * New features and improvements
+ + Let a FileSet follow symbolic links
+ * Documentation updates
+ + Describe the artifact in the POM
+ * Dependency updates
+ + Pin Guava on the test classpath
+ + Bump com.github.luben:zstd-jni from 1.5.7-14 to 1.5.7-15
+- Changes of version 4.13.0
+ * New features and improvements
+ + Establish an automatic module name
+ * Dependency updates
+ + Bump plexus-io to 3.7.0
+ + Bump plexus-utils to 3.6.2
+ + Update parent to plexus 27, from 25
+ + Bump com.github.luben:zstd-jni from 1.5.7-9 to 1.5.7-14
+ + Bump org.eclipse.sisu:org.eclipse.sisu.inject from 1.0.0 to
+ 1.1.0
+ + Revert "Bump slf4jVersion from 1.7.36 to 2.0.18"
+ * Build
+ + Name the sisu property after what it versions
+ + Keep the 4.x release drafter config on the 4.x branch
+
+-------------------------------------------------------------------
Old:
----
plexus-archiver-4.12.0.tar.gz
New:
----
plexus-archiver-4.14.0.tar.gz
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Other differences:
------------------
++++++ plexus-archiver.spec ++++++
--- /var/tmp/diff_new_pack.i76u6B/_old 2026-09-29 17:50:46.175687021 +0200
+++ /var/tmp/diff_new_pack.i76u6B/_new 2026-09-29 17:50:46.177687105 +0200
@@ -17,7 +17,7 @@
Name: plexus-archiver
-Version: 4.12.0
+Version: 4.14.0
Release: 0
Summary: Plexus Archiver Component
License: Apache-2.0
++++++ _scmsync.obsinfo ++++++
--- /var/tmp/diff_new_pack.i76u6B/_old 2026-09-29 17:50:46.214688650 +0200
+++ /var/tmp/diff_new_pack.i76u6B/_new 2026-09-29 17:50:46.220688900 +0200
@@ -1,6 +1,6 @@
-mtime: 1781781760
-commit: 08295ac0206d846ab3f2650b63407aa1f00c486ead0a6d19b5f694628fbbc58d
+mtime: 1790595406
+commit: 0ecb4dec4a28449892c938960637f3e0cdcfbabcda3db3c6c06a8fad3f4f537c
url: https://src.opensuse.org/java-packages/plexus-archiver
-revision: 08295ac0206d846ab3f2650b63407aa1f00c486ead0a6d19b5f694628fbbc58d
+revision: 0ecb4dec4a28449892c938960637f3e0cdcfbabcda3db3c6c06a8fad3f4f537c
projectscmsync: https://src.opensuse.org/java-packages/_ObsPrj
++++++ build.specials.obscpio ++++++
++++++ build.specials.obscpio ++++++
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn'
'--exclude=.svnignore' old/.gitignore new/.gitignore
--- old/.gitignore 1970-01-01 01:00:00.000000000 +0100
+++ new/.gitignore 2026-09-28 13:36:46.000000000 +0200
@@ -0,0 +1 @@
+.osc
++++++ plexus-archiver-4.12.0.tar.gz -> plexus-archiver-4.14.0.tar.gz ++++++
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn'
'--exclude=.svnignore'
old/plexus-archiver-plexus-archiver-4.12.0/.github/release-drafter-4.x.yml
new/plexus-archiver-plexus-archiver-4.14.0/.github/release-drafter-4.x.yml
--- old/plexus-archiver-plexus-archiver-4.12.0/.github/release-drafter-4.x.yml
1970-01-01 01:00:00.000000000 +0100
+++ new/plexus-archiver-plexus-archiver-4.14.0/.github/release-drafter-4.x.yml
2026-08-23 14:43:30.000000000 +0200
@@ -0,0 +1,10 @@
+_extends: .github:.github/release-drafter.yml
+
+# tag-prefix is what lets the drafter parse the version out of the last tag.
+# Without it the drafter reads what it can from the tag string, and plexus-i18n
+# once drafted 18.0.1 by finding the 18 in its own name.
+tag-prefix: plexus-archiver-
+tag-template: plexus-archiver-$RESOLVED_VERSION
+version-template: 4.$MINOR.$PATCH
+commitish: 4.x
+filter-by-commitish: true
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn'
'--exclude=.svnignore'
old/plexus-archiver-plexus-archiver-4.12.0/.github/workflows/release-drafter.yml
new/plexus-archiver-plexus-archiver-4.14.0/.github/workflows/release-drafter.yml
---
old/plexus-archiver-plexus-archiver-4.12.0/.github/workflows/release-drafter.yml
2026-06-08 22:12:22.000000000 +0200
+++
new/plexus-archiver-plexus-archiver-4.14.0/.github/workflows/release-drafter.yml
2026-08-23 14:43:30.000000000 +0200
@@ -1,12 +1,15 @@
-name: Release Drafter
+name: Release Drafter 4.x
on:
push:
branches:
- - master
+ - 4.x
jobs:
update_release_draft:
runs-on: ubuntu-latest
steps:
- - uses: release-drafter/release-drafter@v7
+ - uses: release-drafter/[email protected]
+ with:
+ # Resolved against .github/ on the branch this workflow runs on, not
on the default branch.
+ config-name: 'release-drafter-4.x.yml'
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn'
'--exclude=.svnignore' old/plexus-archiver-plexus-archiver-4.12.0/pom.xml
new/plexus-archiver-plexus-archiver-4.14.0/pom.xml
--- old/plexus-archiver-plexus-archiver-4.12.0/pom.xml 2026-06-08
22:12:22.000000000 +0200
+++ new/plexus-archiver-plexus-archiver-4.14.0/pom.xml 2026-08-23
14:43:30.000000000 +0200
@@ -5,12 +5,14 @@
<parent>
<groupId>org.codehaus.plexus</groupId>
<artifactId>plexus</artifactId>
- <version>25</version>
+ <version>27</version>
</parent>
<artifactId>plexus-archiver</artifactId>
- <version>4.12.0</version>
+ <version>4.14.0</version>
<name>Plexus Archiver Component</name>
+ <description>One API for creating and extracting archives - zip, jar, tar
and their compressed
+ variants - regardless of format.</description>
<url>https://codehaus-plexus.github.io/plexus-archiver/</url>
@@ -30,7 +32,7 @@
<scm>
<connection>scm:git:https://github.com/codehaus-plexus/plexus-archiver.git</connection>
<developerConnection>scm:git:https://github.com/codehaus-plexus/plexus-archiver.git</developerConnection>
- <tag>plexus-archiver-4.12.0</tag>
+ <tag>plexus-archiver-4.14.0</tag>
<url>https://github.com/codehaus-plexus/plexus-archiver/tree/${project.scm.tag}/</url>
</scm>
<issueManagement>
@@ -46,8 +48,8 @@
<properties>
<slf4jVersion>1.7.36</slf4jVersion>
- <sisuMavenPluginVersion>1.0.0</sisuMavenPluginVersion>
-
<project.build.outputTimestamp>2026-06-08T20:12:00Z</project.build.outputTimestamp>
+ <version.sisu>1.1.0</version.sisu>
+
<project.build.outputTimestamp>2026-08-23T12:40:45Z</project.build.outputTimestamp>
</properties>
<dependencies>
@@ -61,12 +63,12 @@
<dependency>
<groupId>org.codehaus.plexus</groupId>
<artifactId>plexus-utils</artifactId>
- <version>3.6.1</version>
+ <version>3.6.2</version>
</dependency>
<dependency>
<groupId>org.codehaus.plexus</groupId>
<artifactId>plexus-io</artifactId>
- <version>3.6.0</version>
+ <version>3.7.0</version>
</dependency>
<dependency>
<groupId>org.apache.commons</groupId>
@@ -92,7 +94,7 @@
<dependency>
<groupId>com.github.luben</groupId>
<artifactId>zstd-jni</artifactId>
- <version>1.5.7-9</version>
+ <version>1.5.7-15</version>
<scope>runtime</scope>
</dependency>
<dependency>
@@ -122,7 +124,7 @@
<dependency>
<groupId>org.eclipse.sisu</groupId>
<artifactId>org.eclipse.sisu.inject</artifactId>
- <version>${sisuMavenPluginVersion}</version>
+ <version>${version.sisu}</version>
<scope>test</scope>
</dependency>
<dependency>
@@ -131,6 +133,16 @@
<version>5.1.0</version>
<scope>test</scope>
</dependency>
+ <!-- Guice 5.1.0 drags in Guava 30.1-jre, which CVE-2023-2976 and
+ CVE-2020-8908 cover. Nothing here uses Guava; the pin only keeps
+ the flagged version off the test classpath. 33.7.1-jre is still
+ Java 8 bytecode, so it holds on this line. -->
+ <dependency>
+ <groupId>com.google.guava</groupId>
+ <artifactId>guava</artifactId>
+ <version>33.7.1-jre</version>
+ <scope>test</scope>
+ </dependency>
<dependency>
<groupId>org.assertj</groupId>
<artifactId>assertj-core</artifactId>
@@ -143,6 +155,17 @@
<plugins>
<plugin>
<groupId>org.apache.maven.plugins</groupId>
+ <artifactId>maven-jar-plugin</artifactId>
+ <configuration>
+ <archive>
+ <manifestEntries>
+
<Automatic-Module-Name>org.codehaus.plexus.archiver</Automatic-Module-Name>
+ </manifestEntries>
+ </archive>
+ </configuration>
+ </plugin>
+ <plugin>
+ <groupId>org.apache.maven.plugins</groupId>
<artifactId>maven-release-plugin</artifactId>
<configuration>
<!-- olamy: exclude files with strange names as failed here on osx
-->
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn'
'--exclude=.svnignore'
old/plexus-archiver-plexus-archiver-4.12.0/src/main/java/org/codehaus/plexus/archiver/AbstractArchiver.java
new/plexus-archiver-plexus-archiver-4.14.0/src/main/java/org/codehaus/plexus/archiver/AbstractArchiver.java
---
old/plexus-archiver-plexus-archiver-4.12.0/src/main/java/org/codehaus/plexus/archiver/AbstractArchiver.java
2026-06-08 22:12:22.000000000 +0200
+++
new/plexus-archiver-plexus-archiver-4.14.0/src/main/java/org/codehaus/plexus/archiver/AbstractArchiver.java
2026-08-23 14:43:30.000000000 +0200
@@ -331,7 +331,7 @@
// The PlexusIoFileResourceCollection contains platform-specific
File.separatorChar which
// is an interesting cause of grief, see PLXCOMP-192
final PlexusIoFileResourceCollection collection = new
PlexusIoFileResourceCollection();
- collection.setFollowingSymLinks(false);
+ collection.setFollowingSymLinks(fileSet.isFollowingSymLinks());
collection.setIncludes(fileSet.getIncludes());
collection.setExcludes(fileSet.getExcludes());
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn'
'--exclude=.svnignore'
old/plexus-archiver-plexus-archiver-4.12.0/src/main/java/org/codehaus/plexus/archiver/FileSet.java
new/plexus-archiver-plexus-archiver-4.14.0/src/main/java/org/codehaus/plexus/archiver/FileSet.java
---
old/plexus-archiver-plexus-archiver-4.12.0/src/main/java/org/codehaus/plexus/archiver/FileSet.java
2026-06-08 22:12:22.000000000 +0200
+++
new/plexus-archiver-plexus-archiver-4.14.0/src/main/java/org/codehaus/plexus/archiver/FileSet.java
2026-08-23 14:43:30.000000000 +0200
@@ -14,4 +14,20 @@
* Returns the file sets base directory.
*/
File getDirectory();
+
+ /**
+ * Returns whether symbolic links below the base directory are followed.
+ * <p>
+ * When {@code false} (the default), a symbolic link is added to the
archive as a link and the
+ * contents of a linked directory are not scanned. When {@code true},
links are resolved: a
+ * linked directory is added as a directory and its target's contents are
included.
+ * <p>
+ * Following links means the scan can descend into a directory that links
back to one of its own
+ * ancestors, so only enable it for trees known not to contain such cycles.
+ *
+ * @since 4.14.0
+ */
+ default boolean isFollowingSymLinks() {
+ return false;
+ }
}
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn'
'--exclude=.svnignore'
old/plexus-archiver-plexus-archiver-4.12.0/src/main/java/org/codehaus/plexus/archiver/util/DefaultFileSet.java
new/plexus-archiver-plexus-archiver-4.14.0/src/main/java/org/codehaus/plexus/archiver/util/DefaultFileSet.java
---
old/plexus-archiver-plexus-archiver-4.12.0/src/main/java/org/codehaus/plexus/archiver/util/DefaultFileSet.java
2026-06-08 22:12:22.000000000 +0200
+++
new/plexus-archiver-plexus-archiver-4.14.0/src/main/java/org/codehaus/plexus/archiver/util/DefaultFileSet.java
2026-08-23 14:43:30.000000000 +0200
@@ -15,6 +15,8 @@
private File directory;
+ private boolean followingSymLinks;
+
public DefaultFileSet(File directory) {
this.directory = directory;
}
@@ -33,6 +35,28 @@
return directory;
}
+ /**
+ * Sets whether symbolic links below the base directory are followed.
Defaults to false.
+ *
+ * @since 4.14.0
+ */
+ public void setFollowingSymLinks(boolean followingSymLinks) {
+ this.followingSymLinks = followingSymLinks;
+ }
+
+ @Override
+ public boolean isFollowingSymLinks() {
+ return followingSymLinks;
+ }
+
+ /**
+ * @since 4.14.0
+ */
+ public DefaultFileSet followingSymLinks(boolean followingSymLinks) {
+ setFollowingSymLinks(followingSymLinks);
+ return this;
+ }
+
public static DefaultFileSet fileSet(File directory) {
final DefaultFileSet defaultFileSet = new DefaultFileSet(directory);
return defaultFileSet;
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn'
'--exclude=.svnignore'
old/plexus-archiver-plexus-archiver-4.12.0/src/test/java/org/codehaus/plexus/archiver/SymlinkTest.java
new/plexus-archiver-plexus-archiver-4.14.0/src/test/java/org/codehaus/plexus/archiver/SymlinkTest.java
---
old/plexus-archiver-plexus-archiver-4.12.0/src/test/java/org/codehaus/plexus/archiver/SymlinkTest.java
2026-06-08 22:12:22.000000000 +0200
+++
new/plexus-archiver-plexus-archiver-4.14.0/src/test/java/org/codehaus/plexus/archiver/SymlinkTest.java
2026-08-23 14:43:30.000000000 +0200
@@ -7,6 +7,7 @@
import org.codehaus.plexus.archiver.tar.TarArchiver;
import org.codehaus.plexus.archiver.tar.TarLongFileMode;
import org.codehaus.plexus.archiver.tar.TarUnArchiver;
+import org.codehaus.plexus.archiver.util.DefaultFileSet;
import org.codehaus.plexus.archiver.zip.ZipArchiver;
import org.codehaus.plexus.archiver.zip.ZipUnArchiver;
import org.junit.jupiter.api.Test;
@@ -106,4 +107,37 @@
symbolicLink = new
File("target/output/dirarchiver-symlink/aDirWithALink/backOutsideToFileX");
assertTrue(Files.isSymbolicLink(symbolicLink.toPath()));
}
+
+ @Test
+ void fileSetDoesNotFollowSymLinksByDefault() {
+ assertFalse(new
DefaultFileSet(getTestFile("src/test/resources/symlinks/src")).isFollowingSymLinks());
+ }
+
+ @Test
+ @DisabledOnOs(OS.WINDOWS)
+ void followingSymLinksResolvesLinkedDirectories() throws Exception {
+ DirectoryArchiver archiver = (DirectoryArchiver)
lookup(Archiver.class, "dir");
+
+ File dummyContent = getTestFile("src/test/resources/symlinks/src");
+ archiver.addFileSet(new
DefaultFileSet(dummyContent).followingSymLinks(true));
+ final File archiveFile = new
File("target/output/dirarchiver-followed-symlink");
+ archiveFile.mkdirs();
+ archiver.setDestFile(archiveFile);
+
+ archiver.createArchive();
+
+ // a link to a directory becomes the directory, and its target's
contents are included
+ File linkedDir = new File(archiveFile, "symDir");
+ assertFalse(Files.isSymbolicLink(linkedDir.toPath()));
+ assertTrue(linkedDir.isDirectory());
+ assertTrue(new File(linkedDir, "targetFile.txt").isFile());
+
+ // including when the target lies outside the base directory
+ assertTrue(new File(archiveFile,
"symLinkToDirOnTheOutside/FileInDirOnTheOutside.txt").isFile());
+
+ // a link to a file becomes the file
+ File linkedFile = new File(archiveFile, "symR");
+ assertFalse(Files.isSymbolicLink(linkedFile.toPath()));
+ assertTrue(linkedFile.isFile());
+ }
}
++++++ plexus-archiver-build.xml ++++++
--- /var/tmp/diff_new_pack.i76u6B/_old 2026-09-29 17:50:46.691708569 +0200
+++ /var/tmp/diff_new_pack.i76u6B/_new 2026-09-29 17:50:46.700708945 +0200
@@ -10,7 +10,7 @@
<property name="project.groupId" value="org.codehaus.plexus"/>
<property name="project.artifactId" value="plexus-archiver"/>
- <property name="project.version" value="4.12.0"/>
+ <property name="project.version" value="4.14.0"/>
<property name="compiler.release" value="8"/>
<property name="compiler.source" value="1.${compiler.release}"/>
@@ -126,6 +126,7 @@
basedir="${build.outputDir}"
excludes="**/package.html">
<manifest>
+ <attribute name="Automatic-Module-Name"
value="org.codehaus.plexus.archiver"/>
<attribute name="JavaPackages-ArtifactId"
value="${project.artifactId}"/>
<attribute name="JavaPackages-GroupId" value="${project.groupId}"/>
<attribute name="JavaPackages-Version" value="${project.version}"/>