Script 'mail_helper' called by obssrc Hello community, here is the log from the commit of package trivy for openSUSE:Factory checked in at 2026-10-02 23:05:34 ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Comparing /work/SRC/openSUSE:Factory/trivy (Old) and /work/SRC/openSUSE:Factory/.trivy.new.1631729 (New) ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Package is "trivy" Fri Oct 2 23:05:34 2026 rev:104 rq:1382112 version:0.75.0 Changes: -------- --- /work/SRC/openSUSE:Factory/trivy/trivy.changes 2026-09-07 11:35:00.910945920 +0200 +++ /work/SRC/openSUSE:Factory/.trivy.new.1631729/trivy.changes 2026-10-02 23:07:57.165889418 +0200 @@ -1,0 +2,95 @@ +Fri Oct 02 13:26:24 UTC 2026 - Dirk Müller <[email protected]> + +- Update to version 0.75.0: + * release: v0.75.0 [main] (#11110) + * feat(crypto): add the crypto scanner to the image command (#11144) + * fix(os): keep the fullest OS version when merging analyzer results (#11039) + * feat(echo): add vulnerability detection for Echo-patched Python packages (#10555) + * fix(crypto): read RSA private keys without validating their math (#11319) + * feat(crypto): transfer cryptographic assets in client/server mode (#11141) + * chore: bump SPDX license IDs and exceptions to `v3.29.0` (#11284) + * fix(python): support uv workspace lockfiles (#10553) + * fix(purl): classify julia, bottlerocket and centos stream packages (#11326) + * chore(deps): bump alpine to 3.24.2 (#11309) + * chore(alpine): add EOL date for Alpine 3.24 and fix 3.21/3.22 dates (#11308) + * feat(crypto): output cryptographic assets in CycloneDX (#11125) + * docs(sbom): clarify Rekor source compatibility with Cosign (#11323) + * fix(python): skip pip requirement lines with malformed extras brackets (#11300) + * feat(crypto): add analyzer and pass assets to the scan report (#11104) + * fix: correct grammar and typos in user-facing error messages and CLI flags (#11281) + * chore(deps): bump github.com/containerd/containerd/v2 from 2.4.0 to 2.4.1 (#11310) + * fix(vex): avoid panic on CSAF relationships without a sub-component (#11067) + * chore(deps): bump the common group across 1 directory with 4 updates (#11306) + * chore(deps): bump the github-actions group across 1 directory with 5 updates (#11173) + * chore(deps): bump the testcontainers group across 1 directory with 2 updates (#11130) + * chore(deps): bump the aws group across 1 directory with 6 updates (#11129) + * chore(deps): bump github.com/docker/cli from 29.8.0+incompatible to 29.8.1+incompatible in the docker group (#11305) + * chore(deps): bump the docker group across 1 directory with 4 updates (#11266) + * perf(secret): replace per-rule keyword search with one Aho-Corasick pass (#11179) + * perf(crypto): report repeated x509 material once per file (#11263) + * perf: take JSON line numbers from decoder offsets (#11233) + * refactor(java): parse MANIFEST.MF attributes by key (#11022) + * fix(sbom): skip null entries in SPDX file and package arrays (#11101) + * feat(crypto): describe ML-DSA keys and signature algorithms (#11137) + * docs: clarify community integration listing disclaimer (#11283) + * docs: add PerspectiveGraph to reporting integrations (#11255) + * docs: link security reporting guidance to relevant documentation (#11235) + * docs(misconf): clarify custom check security considerations (#11278) + * fix(license): report unparsable license names with UNKNOWN severity (#11254) + * chore(deps): bump the common group across 1 directory with 27 updates (#11267) + * feat(crypto): describe parsed material as cryptographic assets (#11092) + * fix: avoid panics on malformed dependency files and version-less Amazon Linux release (#10996) + * perf: reuse one JSON unmarshaler per document (#11232) + * perf: avoid regrowing the buffer when reading a cached file (#11134) + * fix(repo): strip credentials from remote repository URL in artifact name (#11213) + * fix: set locations for JSON values sharing a line (#11231) + * test: use httptest.NewTestServer for shared test servers (#11138) + * docs: clarify configuration file security considerations (#11209) + * docs(go): explain why go.sum is not scanned for Go 1.17+ modules (#11163) + * feat(cli): allow disabling configuration files with empty paths (#11210) + * fix(report)!: remove getHostByName from templates (#11206) + * test(misconf): rework the Terraform scanner tests (#11218) + * fix(go): honor go directive when merging go.sum (#11169) + * chore(deps): bump github.com/containerd/containerd/v2 from 2.3.3 to 2.3.5 (#11224) + * docs(plugin): clarify plugin permissions and security considerations (#11202) + * refactor(misconf): take the result.new and isManaged built-ins from trivy-checks (#11194) + * fix: correct grammar and typos in user-facing error messages (#11211) + * chore(deps): bump google.golang.org/grpc from 1.83.1 to 1.83.2 (#11212) + * chore(deps): bump trivy-checks (#11205) + * fix(misconf): report correct line numbers in multi-document manifests (#11207) + * docs(terraform): clarify remote module downloads and network access (#11200) + * docs(server): clarify client/server security considerations (#11198) + * docs(java): recommend mvn install for multi-module Maven projects (#11196) + * fix(server): propagate package modularity label, build info and installed files (#11188) + * fix(terraform): do not override --skip-files with --skip-dirs (#11191) + * fix(license): use canonical SPDX casing for license.id (#11165) + * ci: remove redundant vulnerability scan (#11184) + * docs: fix --exclude-namespaces example and a typo in the Terraform tutorial (#11036) + * docs: define compatibility policy (#11128) + * docs(vm): mark monolithicSparse as a supported VMDK disk type (#11103) + * chore(deps): drop outdated note about spdx/tools-golang version (#11164) + * chore(deps): bump google.golang.org/grpc from 1.82.1 to 1.83.1 (#11176) + * refactor: use strings.CutLast and url.URL.Clone from Go 1.27 (#11136) + * refactor: use named constants for JSON token kinds (#11157) + * fix(nodejs): support boolean resolved field in package-lock.json (#11156) + * test(rapidfort): add integration test for the RapidFort curated image (#11150) + * perf(secret): avoid cloning the logger for every rule (#11133) + * ci: add rapidfort scope to PR title validation (#11151) + * chore: bump Go to 1.27 (#11127) + * fix(go): restore stdlib version parsing for vendor-patched Go toolchains (#11119) + * chore(deps): bump github.com/moby/go-archive from 0.2.1 to 0.3.3 (#11123) + * ci: add crypto scope to PR title validation (#11111) + * feat: add cryptographic asset model and parser (#10970) + * ci(helm): bump Trivy version to 0.74.0 for Trivy Helm Chart 0.26.0 (#11097) + +------------------------------------------------------------------- +Sat Sep 12 17:25:00 UTC 2026 - Dirk Müller <[email protected]> + +- update vendor.tar to address: + * bsc#1278624, CVE-2026-56855,CVE-2026-56854,CVE-2026-78662: + golang.org/x/crypto/ssh: authentication bypass and deadlocks + in the crypto/ssh library + * bsc#1280111, CVE-2026-53495: containerd: CRI ExecSync Goroutine + Leak Leads to Node-Level Denial of Service + +------------------------------------------------------------------- Old: ---- trivy-0.74.0.tar.zst New: ---- trivy-0.75.0.tar.zst ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Other differences: ------------------ ++++++ trivy.spec ++++++ --- /var/tmp/diff_new_pack.sN8bv5/_old 2026-10-02 23:08:05.826251822 +0200 +++ /var/tmp/diff_new_pack.sN8bv5/_new 2026-10-02 23:08:05.828251906 +0200 @@ -17,7 +17,7 @@ Name: trivy -Version: 0.74.0 +Version: 0.75.0 Release: 0 Summary: A Simple and Comprehensive Vulnerability Scanner for Containers License: Apache-2.0 @@ -27,7 +27,7 @@ Source1: vendor.tar.zst BuildRequires: golang-packaging BuildRequires: zstd -BuildRequires: golang(API) = 1.26 +BuildRequires: golang(API) = 1.27 Requires: ca-certificates Requires: git-core ++++++ _scmsync.obsinfo ++++++ --- /var/tmp/diff_new_pack.sN8bv5/_old 2026-10-02 23:08:05.900254916 +0200 +++ /var/tmp/diff_new_pack.sN8bv5/_new 2026-10-02 23:08:05.906255166 +0200 @@ -1,5 +1,5 @@ -mtime: 1788702191 -commit: 338e63f944e88480d3852ae5cc141c0a8787f6a7af09c24c0d64b0a758b86472 +mtime: 1790948135 +commit: e02b89ef2fbc03e481239ed9ce53c5920230ad36c6538e7cb49da9a28c4447fb url: https://src.opensuse.org/dirkmueller/trivy.git revision: factory ++++++ _service ++++++ --- /var/tmp/diff_new_pack.sN8bv5/_old 2026-10-02 23:08:05.946256839 +0200 +++ /var/tmp/diff_new_pack.sN8bv5/_new 2026-10-02 23:08:05.958257340 +0200 @@ -2,7 +2,7 @@ <service name="tar_scm" mode="manual"> <param name="url">https://github.com/aquasecurity/trivy</param> <param name="scm">git</param> - <param name="revision">v0.74.0</param> + <param name="revision">v0.75.0</param> <param name="versionformat">@PARENT_TAG@</param> <param name="versionrewrite-pattern">v(.*)</param> <param name="changesgenerate">enable</param> @@ -16,7 +16,6 @@ </service> <service name="go_modules" mode="manual"> <param name="compression">zst</param> - <param name="replace">google.golang.org/grpc=google.golang.org/[email protected]</param> </service> </services> ++++++ _servicedata ++++++ --- /var/tmp/diff_new_pack.sN8bv5/_old 2026-10-02 23:08:05.999259054 +0200 +++ /var/tmp/diff_new_pack.sN8bv5/_new 2026-10-02 23:08:06.006259347 +0200 @@ -1,6 +1,6 @@ <servicedata> <service name="tar_scm"> <param name="url">https://github.com/aquasecurity/trivy</param> - <param name="changesrevision">e1fd17a0ea4a8cf24bc4b4dd7e2cfbf4bb31b994</param></service></servicedata> + <param name="changesrevision">591e9799316a602e703f0b484f6c6d7b234ec8f3</param></service></servicedata> (No newline at EOF) ++++++ build.specials.obscpio ++++++ ++++++ build.specials.obscpio ++++++ diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/.gitignore new/.gitignore --- old/.gitignore 1970-01-01 01:00:00.000000000 +0100 +++ new/.gitignore 2026-10-02 15:35:35.000000000 +0200 @@ -0,0 +1 @@ +.osc ++++++ trivy-0.74.0.tar.zst -> trivy-0.75.0.tar.zst ++++++ /work/SRC/openSUSE:Factory/trivy/trivy-0.74.0.tar.zst /work/SRC/openSUSE:Factory/.trivy.new.1631729/trivy-0.75.0.tar.zst differ: char 7, line 1 ++++++ vendor.tar.zst ++++++ /work/SRC/openSUSE:Factory/trivy/vendor.tar.zst /work/SRC/openSUSE:Factory/.trivy.new.1631729/vendor.tar.zst differ: char 7, line 1
