Script 'mail_helper' called by obssrc
Hello community,

here is the log from the commit of package flatpak for openSUSE:Factory checked 
in at 2026-09-29 17:48:09
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Comparing /work/SRC/openSUSE:Factory/flatpak (Old)
 and      /work/SRC/openSUSE:Factory/.flatpak.new.383539 (New)
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Package is "flatpak"

Tue Sep 29 17:48:09 2026 rev:105 rq:1381311 version:1.18.4

Changes:
--------
--- /work/SRC/openSUSE:Factory/flatpak/flatpak.changes  2026-09-24 
22:55:32.153386026 +0200
+++ /work/SRC/openSUSE:Factory/.flatpak.new.383539/flatpak.changes      
2026-09-29 17:48:50.409859536 +0200
@@ -1,0 +2,37 @@
+Mon Sep 28 13:20:12 UTC 2026 - Bjørn Lie <[email protected]>
+
+- Update to version 1.18.4:
+  + Security fixes:
+    - Prevent privileged overwrite of arbitrary files with an empty
+      file or a symlink to /run/host/monitor/resolv.conf when a
+      malicious app is installed (CVE-2026-97024,
+      GHSA-8xgq-v545-vgv)
+    - Prevent privileged deletion of arbitrary files when a
+      malicious app is installed (CVE-2026-97023,
+      GHSA-5p67-xh8x-rq54)
+    - When downloading apps or runtimes from an OCI repository that
+      requires authentication, don't make the authentication token
+      visible to other users (CVE-2026-97025, GHSA-7rvf-rqr3-43j4)
+    - Restrict permissions on temporary repository directories in
+      /var/tmp/flatpak-cache-* (CVE-2026-97026,
+      GHSA-r9w3-qx54-qvc8)
+    - Filter .desktop and D-Bus .service files against an allowlist
+      of fields, preventing denial of service and unintended
+      interactions with host services (CVE-2026-97027,
+      GHSA-v64f-hrwr-j4vh)
+    - Prevent apps from sending signals to a process group that
+      includes a parent process outside the app, causing denial of
+      service by killing the desktop environment (CVE-2026-97029,
+      GHSA-f3p8-vr7v-gxf2)
+  + Bug fixes:
+    - Update Meson wrap subprojects for projects that are normally
+      taken from the host system:
+    - xdg-dbus-proxy 0.1.9 (CVE-2026-93676, CVE-2026-94422)
+    - Improve hardening against symlink traversal, related to
+      CVE-2026-97023 and CVE-2026-97024
+  + Internal changes:
+    - Add CVE IDs and reporter credits to 1.18.1's NEWS entry
+    - Remove unnecessary U+200E LEFT-TO-RIGHT MARK from some older
+      NEWS entries
+
+-------------------------------------------------------------------

Old:
----
  flatpak-1.18.3.tar.xz

New:
----
  flatpak-1.18.4.tar.xz

++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Other differences:
------------------
++++++ flatpak.spec ++++++
--- /var/tmp/diff_new_pack.yffmFg/_old  2026-09-29 17:48:51.784916701 +0200
+++ /var/tmp/diff_new_pack.yffmFg/_new  2026-09-29 17:48:51.786916784 +0200
@@ -30,7 +30,7 @@
 %define support_environment_generators 1
 %endif
 Name:           flatpak
-Version:        1.18.3
+Version:        1.18.4
 Release:        0
 Summary:        OSTree based application bundles management
 License:        LGPL-2.1-or-later

++++++ _scmsync.obsinfo ++++++
--- /var/tmp/diff_new_pack.yffmFg/_old  2026-09-29 17:48:51.829918572 +0200
+++ /var/tmp/diff_new_pack.yffmFg/_new  2026-09-29 17:48:51.832918697 +0200
@@ -1,7 +1,7 @@
-mtime: 1790082496
-commit: 0c7cd60df39677412ead851e00b8844053c8cb2733a40a3a1f568782d210a7f6
+mtime: 1790601883
+commit: 93ce337ea8c1338b89b623aad542dd9c903355e95f4c1898fcff631cc0d88c53
 url: https://src.opensuse.org/GNOME/flatpak
-revision: 0c7cd60df39677412ead851e00b8844053c8cb2733a40a3a1f568782d210a7f6
+revision: 93ce337ea8c1338b89b623aad542dd9c903355e95f4c1898fcff631cc0d88c53
 trackingbranch: factory
 projectscmsync: https://src.opensuse.org/GNOME/_ObsPrj
 

++++++ _service ++++++
--- /var/tmp/diff_new_pack.yffmFg/_old  2026-09-29 17:48:51.852919528 +0200
+++ /var/tmp/diff_new_pack.yffmFg/_new  2026-09-29 17:48:51.856919695 +0200
@@ -3,7 +3,7 @@
   <service name="obs_scm" mode="manual">
     <param name="scm">git</param>
     <param name="url">https://github.com/flatpak/flatpak.git</param>
-    <param name="revision">1.18.3</param>
+    <param name="revision">1.18.4</param>
     <param name="versionformat">@PARENT_TAG@+@TAG_OFFSET@</param>
     <param name="versionrewrite-pattern">(.*)\+0</param>
     <param name="versionrewrite-replacement">\1</param>

++++++ build.specials.obscpio ++++++

++++++ build.specials.obscpio ++++++
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/.gitignore new/.gitignore
--- old/.gitignore      1970-01-01 01:00:00.000000000 +0100
+++ new/.gitignore      2026-09-28 15:24:43.000000000 +0200
@@ -0,0 +1,5 @@
+*.obscpio
+*.osc
+_build.*
+.pbuild
+osc-collab.*

++++++ flatpak-1.18.3.tar.xz -> flatpak-1.18.4.tar.xz ++++++
++++ 26334 lines of diff (skipped)

++++++ flatpak.obsinfo ++++++
--- /var/tmp/diff_new_pack.yffmFg/_old  2026-09-29 17:48:52.499946427 +0200
+++ /var/tmp/diff_new_pack.yffmFg/_new  2026-09-29 17:48:52.503946594 +0200
@@ -1,5 +1,5 @@
 name: flatpak
-version: 1.18.3
-mtime: 1790074774
-commit: 346b41f2e91bff14de940704302625c517d856b2
+version: 1.18.4
+mtime: 1790596213
+commit: a02d0ba48abe9aacc377de15699e5d8c024b5669
 

Reply via email to