Script 'mail_helper' called by obssrc
Hello community,

here is the log from the commit of package trivy for openSUSE:Factory checked 
in at 2026-10-02 23:05:34
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Comparing /work/SRC/openSUSE:Factory/trivy (Old)
 and      /work/SRC/openSUSE:Factory/.trivy.new.1631729 (New)
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Package is "trivy"

Fri Oct  2 23:05:34 2026 rev:104 rq:1382112 version:0.75.0

Changes:
--------
--- /work/SRC/openSUSE:Factory/trivy/trivy.changes      2026-09-07 
11:35:00.910945920 +0200
+++ /work/SRC/openSUSE:Factory/.trivy.new.1631729/trivy.changes 2026-10-02 
23:07:57.165889418 +0200
@@ -1,0 +2,95 @@
+Fri Oct 02 13:26:24 UTC 2026 - Dirk Müller <[email protected]>
+
+- Update to version 0.75.0:
+  * release: v0.75.0 [main] (#11110)
+  * feat(crypto): add the crypto scanner to the image command (#11144)
+  * fix(os): keep the fullest OS version when merging analyzer results (#11039)
+  * feat(echo): add vulnerability detection for Echo-patched Python packages 
(#10555)
+  * fix(crypto): read RSA private keys without validating their math (#11319)
+  * feat(crypto): transfer cryptographic assets in client/server mode (#11141)
+  * chore: bump SPDX license IDs and exceptions to `v3.29.0` (#11284)
+  * fix(python): support uv workspace lockfiles (#10553)
+  * fix(purl): classify julia, bottlerocket and centos stream packages (#11326)
+  * chore(deps): bump alpine to 3.24.2 (#11309)
+  * chore(alpine): add EOL date for Alpine 3.24 and fix 3.21/3.22 dates 
(#11308)
+  * feat(crypto): output cryptographic assets in CycloneDX (#11125)
+  * docs(sbom): clarify Rekor source compatibility with Cosign (#11323)
+  * fix(python): skip pip requirement lines with malformed extras brackets 
(#11300)
+  * feat(crypto): add analyzer and pass assets to the scan report (#11104)
+  * fix: correct grammar and typos in user-facing error messages and CLI flags 
(#11281)
+  * chore(deps): bump github.com/containerd/containerd/v2 from 2.4.0 to 2.4.1 
(#11310)
+  * fix(vex): avoid panic on CSAF relationships without a sub-component 
(#11067)
+  * chore(deps): bump the common group across 1 directory with 4 updates 
(#11306)
+  * chore(deps): bump the github-actions group across 1 directory with 5 
updates (#11173)
+  * chore(deps): bump the testcontainers group across 1 directory with 2 
updates (#11130)
+  * chore(deps): bump the aws group across 1 directory with 6 updates (#11129)
+  * chore(deps): bump github.com/docker/cli from 29.8.0+incompatible to 
29.8.1+incompatible in the docker group (#11305)
+  * chore(deps): bump the docker group across 1 directory with 4 updates 
(#11266)
+  * perf(secret): replace per-rule keyword search with one Aho-Corasick pass 
(#11179)
+  * perf(crypto): report repeated x509 material once per file (#11263)
+  * perf: take JSON line numbers from decoder offsets (#11233)
+  * refactor(java): parse MANIFEST.MF attributes by key (#11022)
+  * fix(sbom): skip null entries in SPDX file and package arrays (#11101)
+  * feat(crypto): describe ML-DSA keys and signature algorithms (#11137)
+  * docs: clarify community integration listing disclaimer (#11283)
+  * docs: add PerspectiveGraph to reporting integrations (#11255)
+  * docs: link security reporting guidance to relevant documentation (#11235)
+  * docs(misconf): clarify custom check security considerations (#11278)
+  * fix(license): report unparsable license names with UNKNOWN severity 
(#11254)
+  * chore(deps): bump the common group across 1 directory with 27 updates 
(#11267)
+  * feat(crypto): describe parsed material as cryptographic assets (#11092)
+  * fix: avoid panics on malformed dependency files and version-less Amazon 
Linux release (#10996)
+  * perf: reuse one JSON unmarshaler per document (#11232)
+  * perf: avoid regrowing the buffer when reading a cached file (#11134)
+  * fix(repo): strip credentials from remote repository URL in artifact name 
(#11213)
+  * fix: set locations for JSON values sharing a line (#11231)
+  * test: use httptest.NewTestServer for shared test servers (#11138)
+  * docs: clarify configuration file security considerations (#11209)
+  * docs(go): explain why go.sum is not scanned for Go 1.17+ modules (#11163)
+  * feat(cli): allow disabling configuration files with empty paths (#11210)
+  * fix(report)!: remove getHostByName from templates (#11206)
+  * test(misconf): rework the Terraform scanner tests (#11218)
+  * fix(go): honor go directive when merging go.sum (#11169)
+  * chore(deps): bump github.com/containerd/containerd/v2 from 2.3.3 to 2.3.5 
(#11224)
+  * docs(plugin): clarify plugin permissions and security considerations 
(#11202)
+  * refactor(misconf): take the result.new and isManaged built-ins from 
trivy-checks (#11194)
+  * fix: correct grammar and typos in user-facing error messages (#11211)
+  * chore(deps): bump google.golang.org/grpc from 1.83.1 to 1.83.2 (#11212)
+  * chore(deps): bump trivy-checks (#11205)
+  * fix(misconf): report correct line numbers in multi-document manifests 
(#11207)
+  * docs(terraform): clarify remote module downloads and network access 
(#11200)
+  * docs(server): clarify client/server security considerations (#11198)
+  * docs(java): recommend mvn install for multi-module Maven projects (#11196)
+  * fix(server): propagate package modularity label, build info and installed 
files (#11188)
+  * fix(terraform): do not override --skip-files with --skip-dirs (#11191)
+  * fix(license): use canonical SPDX casing for license.id (#11165)
+  * ci: remove redundant vulnerability scan (#11184)
+  * docs: fix --exclude-namespaces example and a typo in the Terraform 
tutorial (#11036)
+  * docs: define compatibility policy (#11128)
+  * docs(vm): mark monolithicSparse as a supported VMDK disk type (#11103)
+  * chore(deps): drop outdated note about spdx/tools-golang version (#11164)
+  * chore(deps): bump google.golang.org/grpc from 1.82.1 to 1.83.1 (#11176)
+  * refactor: use strings.CutLast and url.URL.Clone from Go 1.27 (#11136)
+  * refactor: use named constants for JSON token kinds (#11157)
+  * fix(nodejs): support boolean resolved field in package-lock.json (#11156)
+  * test(rapidfort): add integration test for the RapidFort curated image 
(#11150)
+  * perf(secret): avoid cloning the logger for every rule (#11133)
+  * ci: add rapidfort scope to PR title validation (#11151)
+  * chore: bump Go to 1.27 (#11127)
+  * fix(go): restore stdlib version parsing for vendor-patched Go toolchains 
(#11119)
+  * chore(deps): bump github.com/moby/go-archive from 0.2.1 to 0.3.3 (#11123)
+  * ci: add crypto scope to PR title validation (#11111)
+  * feat: add cryptographic asset model and parser (#10970)
+  * ci(helm): bump Trivy version to 0.74.0 for Trivy Helm Chart 0.26.0 (#11097)
+
+-------------------------------------------------------------------
+Sat Sep 12 17:25:00 UTC 2026 - Dirk Müller <[email protected]>
+
+- update vendor.tar to address:
+  * bsc#1278624, CVE-2026-56855,CVE-2026-56854,CVE-2026-78662:
+    golang.org/x/crypto/ssh: authentication bypass and deadlocks
+    in the crypto/ssh library
+  * bsc#1280111, CVE-2026-53495: containerd: CRI ExecSync Goroutine
+    Leak Leads to Node-Level Denial of Service
+
+-------------------------------------------------------------------

Old:
----
  trivy-0.74.0.tar.zst

New:
----
  trivy-0.75.0.tar.zst

++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Other differences:
------------------
++++++ trivy.spec ++++++
--- /var/tmp/diff_new_pack.sN8bv5/_old  2026-10-02 23:08:05.826251822 +0200
+++ /var/tmp/diff_new_pack.sN8bv5/_new  2026-10-02 23:08:05.828251906 +0200
@@ -17,7 +17,7 @@
 
 
 Name:           trivy
-Version:        0.74.0
+Version:        0.75.0
 Release:        0
 Summary:        A Simple and Comprehensive Vulnerability Scanner for Containers
 License:        Apache-2.0
@@ -27,7 +27,7 @@
 Source1:        vendor.tar.zst
 BuildRequires:  golang-packaging
 BuildRequires:  zstd
-BuildRequires:  golang(API) = 1.26
+BuildRequires:  golang(API) = 1.27
 Requires:       ca-certificates
 Requires:       git-core
 

++++++ _scmsync.obsinfo ++++++
--- /var/tmp/diff_new_pack.sN8bv5/_old  2026-10-02 23:08:05.900254916 +0200
+++ /var/tmp/diff_new_pack.sN8bv5/_new  2026-10-02 23:08:05.906255166 +0200
@@ -1,5 +1,5 @@
-mtime: 1788702191
-commit: 338e63f944e88480d3852ae5cc141c0a8787f6a7af09c24c0d64b0a758b86472
+mtime: 1790948135
+commit: e02b89ef2fbc03e481239ed9ce53c5920230ad36c6538e7cb49da9a28c4447fb
 url: https://src.opensuse.org/dirkmueller/trivy.git
 revision: factory
 

++++++ _service ++++++
--- /var/tmp/diff_new_pack.sN8bv5/_old  2026-10-02 23:08:05.946256839 +0200
+++ /var/tmp/diff_new_pack.sN8bv5/_new  2026-10-02 23:08:05.958257340 +0200
@@ -2,7 +2,7 @@
   <service name="tar_scm" mode="manual">
     <param name="url">https://github.com/aquasecurity/trivy</param>
     <param name="scm">git</param>
-    <param name="revision">v0.74.0</param>
+    <param name="revision">v0.75.0</param>
     <param name="versionformat">@PARENT_TAG@</param>
     <param name="versionrewrite-pattern">v(.*)</param>
     <param name="changesgenerate">enable</param>
@@ -16,7 +16,6 @@
   </service>
   <service name="go_modules" mode="manual">
     <param name="compression">zst</param>
-    <param 
name="replace">google.golang.org/grpc=google.golang.org/[email protected]</param>
   </service>
 </services>
 

++++++ _servicedata ++++++
--- /var/tmp/diff_new_pack.sN8bv5/_old  2026-10-02 23:08:05.999259054 +0200
+++ /var/tmp/diff_new_pack.sN8bv5/_new  2026-10-02 23:08:06.006259347 +0200
@@ -1,6 +1,6 @@
 <servicedata>
 <service name="tar_scm">
                 <param name="url">https://github.com/aquasecurity/trivy</param>
-              <param 
name="changesrevision">e1fd17a0ea4a8cf24bc4b4dd7e2cfbf4bb31b994</param></service></servicedata>
+              <param 
name="changesrevision">591e9799316a602e703f0b484f6c6d7b234ec8f3</param></service></servicedata>
 (No newline at EOF)
 

++++++ build.specials.obscpio ++++++

++++++ build.specials.obscpio ++++++
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/.gitignore new/.gitignore
--- old/.gitignore      1970-01-01 01:00:00.000000000 +0100
+++ new/.gitignore      2026-10-02 15:35:35.000000000 +0200
@@ -0,0 +1 @@
+.osc

++++++ trivy-0.74.0.tar.zst -> trivy-0.75.0.tar.zst ++++++
/work/SRC/openSUSE:Factory/trivy/trivy-0.74.0.tar.zst 
/work/SRC/openSUSE:Factory/.trivy.new.1631729/trivy-0.75.0.tar.zst differ: char 
7, line 1

++++++ vendor.tar.zst ++++++
/work/SRC/openSUSE:Factory/trivy/vendor.tar.zst 
/work/SRC/openSUSE:Factory/.trivy.new.1631729/vendor.tar.zst differ: char 7, 
line 1

Reply via email to