Script 'mail_helper' called by obssrc
Hello community,

here is the log from the commit of package go1.18 for openSUSE:Factory checked 
in at 2022-07-14 16:33:13
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Comparing /work/SRC/openSUSE:Factory/go1.18 (Old)
 and      /work/SRC/openSUSE:Factory/.go1.18.new.1523 (New)
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Package is "go1.18"

Thu Jul 14 16:33:13 2022 rev:12 rq:988809 version:1.18.4

Changes:
--------
--- /work/SRC/openSUSE:Factory/go1.18/go1.18.changes    2022-06-03 
14:15:47.941248862 +0200
+++ /work/SRC/openSUSE:Factory/.go1.18.new.1523/go1.18.changes  2022-07-14 
16:33:17.276572503 +0200
@@ -1,0 +2,40 @@
+Tue Jul 12 20:28:01 UTC 2022 - Jeff Kowalczyk <[email protected]>
+
+- go1.18.4 (released 2022-07-12) includes security fixes to the
+  compress/gzip, encoding/gob, encoding/xml, go/parser, io/fs,
+  net/http, and path/filepath packages, as well as bug fixes to the
+  compiler, the go command, the linker, the runtime, and the
+  runtime/metrics package.
+  Refs boo#1193742 go1.18 release tracking
+  CVE-2022-1705 CVE-2022-32148 CVE-2022-30631 CVE-2022-30633 CVE-2022-28131 
CVE-2022-30635 CVE-2022-30632 CVE-2022-30630 CVE-2022-1962
+  * boo#1201434 CVE-2022-1705 go#53188
+  * go#53433 net/http: improper sanitization of Transfer-Encoding header
+  * boo#1201436 CVE-2022-32148 go#53423
+  * go#53621 net/http/httputil: NewSingleHostReverseProxy - omit 
X-Forwarded-For not working
+  * boo#1201437 CVE-2022-30631 go#53168
+  * go#53718 compress/gzip: stack exhaustion in Reader.Read (CVE-2022-30631)
+  * boo#1201440 CVE-2022-30633 go#53611
+  * go#53716 encoding/xml: stack exhaustion in Unmarshal (CVE-2022-30633)
+  * boo#1201443 CVE-2022-28131 go#53614
+  * go#53712 encoding/xml: stack exhaustion in Decoder.Skip (CVE-2022-28131)
+  * boo#1201444 CVE-2022-30635 go#53615
+  * go#53710 encoding/gob: stack exhaustion in Decoder.Decode (CVE-2022-30635)
+  * boo#1201445 CVE-2022-30632 go#53416
+  * go#53714 path/filepath: stack exhaustion in Glob (CVE-2022-30632)
+  * boo#1201447 CVE-2022-30630 go#53415
+  * go#53720 io/fs: stack exhaustion in Glob (CVE-2022-30630)
+  * boo#1201448 CVE-2022-1962 go#53616
+  * go#53708 go/parser: stack exhaustion in all Parse* functions 
(CVE-2022-1962)
+  * go#53723 cmd/compile: ambiguous selector with generic interface & embedded 
types
+  * go#53618 cmd/compile: condition in for loop body is incorrectly optimised 
away
+  * go#53613 syscall: NewCallback triggers data race on Windows when used from 
different goroutine
+  * go#53590 runtime/metrics: data race detected in Read
+  * go#53588 cmd/go: "v1.x.y is not a tag" when .gitconfig sets log.decorate 
to full
+  * go#53587 cmd/compile: miscompilation of value switch involving generic 
interface types
+  * go#53471 cmd/compile: internal compiler error: width not calculated: int128
+  * go#53357 cmd/compile: type assertion on generic type fails incorrectly
+  * go#53159 cmd/compile: unsafe.Offsetof returns incorrect value in embedded 
struct with type parameters
+  * go#53107 cmd/link: unexpected trampoline error on ppc64le musl with 
-buildmode=pie
+  * go#52689 runtime: total allocation stats are managed in a uintptr which 
can quickly wrap around on 32-bit architectures
+
+-------------------------------------------------------------------

Old:
----
  go1.18.3.src.tar.gz

New:
----
  go1.18.4.src.tar.gz

++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Other differences:
------------------
++++++ go1.18.spec ++++++
--- /var/tmp/diff_new_pack.qXzn6y/_old  2022-07-14 16:33:17.764572961 +0200
+++ /var/tmp/diff_new_pack.qXzn6y/_new  2022-07-14 16:33:17.768572965 +0200
@@ -145,7 +145,7 @@
 %endif
 
 Name:           go1.18
-Version:        1.18.3
+Version:        1.18.4
 Release:        0
 Summary:        A compiled, garbage-collected, concurrent programming language
 License:        BSD-3-Clause

++++++ go1.18.3.src.tar.gz -> go1.18.4.src.tar.gz ++++++
/work/SRC/openSUSE:Factory/go1.18/go1.18.3.src.tar.gz 
/work/SRC/openSUSE:Factory/.go1.18.new.1523/go1.18.4.src.tar.gz differ: char 
17, line 1

Reply via email to