Hello community, here is the log from the commit of package go1.14 for openSUSE:Factory checked in at 2020-09-05 23:57:16 ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Comparing /work/SRC/openSUSE:Factory/go1.14 (Old) and /work/SRC/openSUSE:Factory/.go1.14.new.3399 (New) ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Package is "go1.14" Sat Sep 5 23:57:16 2020 rev:9 rq:831306 version:1.14.8 Changes: -------- --- /work/SRC/openSUSE:Factory/go1.14/go1.14.changes 2020-08-12 10:20:05.395662157 +0200 +++ /work/SRC/openSUSE:Factory/.go1.14.new.3399/go1.14.changes 2020-09-05 23:57:34.907109001 +0200 @@ -1,0 +2,10 @@ +Tue Sep 1 17:01:46 UTC 2020 - Jeff Kowalczyk <[email protected]> + +- go1.14.8 (released 2020-09-01) includes security fixes to the + net/http/cgi, net/http/fcgi packages. + CVE-2020-24553 + Refs boo#1164903 go1.14 release tracking + * boo#1176031 CVE-2020-24553 + * go#41164 net/http/cgi,net/http/fcgi: Cross-Site Scripting (XSS) when Content-Type is not specified + +------------------------------------------------------------------- Old: ---- go1.14.7.src.tar.gz New: ---- go1.14.8.src.tar.gz ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Other differences: ------------------ ++++++ go1.14.spec ++++++ --- /var/tmp/diff_new_pack.JUDk6Y/_old 2020-09-05 23:57:36.367109732 +0200 +++ /var/tmp/diff_new_pack.JUDk6Y/_new 2020-09-05 23:57:36.371109734 +0200 @@ -135,7 +135,7 @@ %endif Name: go1.14 -Version: 1.14.7 +Version: 1.14.8 Release: 0 Summary: A compiled, garbage-collected, concurrent programming language License: BSD-3-Clause ++++++ go1.14.7.src.tar.gz -> go1.14.8.src.tar.gz ++++++ /work/SRC/openSUSE:Factory/go1.14/go1.14.7.src.tar.gz /work/SRC/openSUSE:Factory/.go1.14.new.3399/go1.14.8.src.tar.gz differ: char 141, line 1
