openSUSE-SU-2026:0287-1: important: Security update for git-cliff

[email protected]
Newsgroups gmane.linux.suse.security.announce
Message-ID <[email protected]>
   openSUSE Security Update: Security update for git-cliff
______________________________________________________________________________

Announcement ID:    openSUSE-SU-2026:0287-1
Rating:             important
References:         #1248065 #1274523 
Cross-References:   CVE-2025-55159 CVE-2026-25541
CVSS scores:
                    CVE-2025-55159 (SUSE): 5.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N
                    CVE-2026-25541 (SUSE): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

Affected Products:
                    openSUSE Backports SLE-15-SP7
______________________________________________________________________________

   An update that fixes two vulnerabilities is now available.

Description:

   This update for git-cliff fixes the following issues:

   - Update to version 2.13.1:
     * Support more configuration file locations
     * Add per-commit statistics
     * Expose determined bump type in release context
     * Add configurable commit processing order
     * Add environment variable for offline execution
     * Migrate logging to tracing
     * Add caching where applicable
   - CVE-2026-25541: bytes: integer overflow in 'BytesMut:reserve' can lead
     to undefined behavior and crashes (boo#1274523)

   - Update to version 2.12.0:
     * Add offline flag
     * Add --skip-tags cli argument
     * Implement commit processing summary
     * Bug Fixes
   - includes changes from 2.11.0:
     * Support failing on unmatched commits
     * Add support for azure devops
     * Improve repository/directory path resolution
     * Add split_regex, replace_regex, find_regex filters
     * Bug Fixes
   - -includes changes from 2.10.1:
     * Add 'integrations' feature flag for enabling all integrations
     * Bug Fixes
     * CVE-2025-55159: lab: incorrect bounds check in get_disjoint_mut
       function can lead to undefined behavior or potential crash due to
       out-of-bounds access (boo#1248065)

   - Update to version 2.10.0:
     * (config) Support using include and exclude paths in the config (#1173)
       - (7c2f922)
     * (parser) Support regex matching on JSON arrays with scalar elements
       (#1163) - (dc458ea)
     * (template) Support adding commit statistics to the changelog (#1151) -
       (05a50d7)
     * (config) [breaking] Use empty header and footer as default (#1161)
       (#1172) - (3e9311e)
     * (config) Check if commit.footers is defined in detailed example
       (#1170) - (078545f)
     * (fixtures) Update expected.md after config change (#1176) - (76d3e81)
     * (generation) Ensure skip_tags condition is evaluated first (#1190) -
       (318be66)
     * (repo) Use the correct order while diffing paths (#1188) - (ff6c310)
     * (ci) Apply security best practices (#1180) - (a32deca)
     * (config) Implement FromStr instead of Config::parse_from_str() (#1185)
       - (692345e)
     * (test) Standardize unit tests for commit module (#1147) - (0446d6a)
     * (context) Add example usage for statistics (#1162) - (4f7379a)
     * (quickstart) Remove repetitive words (#1200) - (434f9ee)
     * (readme) Fix twitter badge (#1164) - (68bd85e)
     * (readme) Polish badges (#1159) - (941cc2b)
     * (remote) Fix inconsistency in remote integration documentation (#1165)
       - (deb29dc)
     * (website) Add highlights for 2.10.0 (#1225) - (a3fe8c9)
     * (website) Add installation instructions for gentoo-linux (#1203) -
       (07fe6bf)
     * (formatting) Use spaces instead of tabs (#1184) - (0027300)
     * (fixture) Add test fixture for overriding the conventional scope
       (#1166) - (cb84a08)
     * (build) Bump MSRV to 1.85.1 - (d8279d4)
     * (cd) Use macos-15 runner - (c156fc5)
     * (cd) Re-enable sccache for maturin - (871c3c9)
     * (crate) Remove Rust nightly requirement - (4f3e5af)
     * (fixture) Update test-regex-json-array fixture (#1178) - (95f4056)
     * (format) Format module imports for readability (#1183) - (6db7d49)
     * (git) Add .git-blame-ignore-revs - (5b64131)
     * (npm) Bump git-cliff to 2.9.1 (#1156) - (e13b158)
     * (website) Update the node version - (566c2a1)
     * Check if commit.footers is defined in detailed example (#1170)
       (078545f)
     * (breaking) Use empty header and footer as default (#1161) (#1172)
       (3e9311e)
     * Update expected.md after config change (#1176) (76d3e81)
     * Use the correct order while diffing paths (#1188) (ff6c310)
     * Ensure skip_tags condition is evaluated first (#1190) (318be66)
     * Polish badges (#1159) (941cc2b)
     * Fix twitter badge (#1164) (68bd85e)
     * Fix inconsistency in remote integration documentation (#1165) (deb29dc)
     * Add example usage for statistics (#1162) (4f7379a)
     * Remove repetitive words (#1200) (434f9ee)
     * Add installation instructions for gentoo-linux (#1203) (07fe6bf)
     * Add highlights for 2.10.0 (#1225) (a3fe8c9)
     * Support regex matching on JSON arrays with scalar elements (#1163)
       (dc458ea)
     * Support using include and exclude paths in the config (#1173) (7c2f922)
     * Support adding commit statistics to the changelog (#1151) (05a50d7)
     * Bump git-cliff to 2.9.1 (#1156) (e13b158)
     * Re-enable sccache for maturin (871c3c9)
     * Update test-regex-json-array fixture (#1178) (95f4056)
     * Format module imports for readability (#1183) (6db7d49)
     * Use macos-15 runner (c156fc5)
     * Update the node version (566c2a1)
     * Remove Rust nightly requirement (4f3e5af)
     * Bump MSRV to 1.85.1 (d8279d4)
     * Add .git-blame-ignore-revs (5b64131)
     * Standardize unit tests for commit module (#1147) (0446d6a)
     * Resolve mismatched lifetime syntax warnings (#1167) (9970402)
     * Implement FromStr instead of Config::parse_from_str() (#1185) (692345e)
     * Apply security best practices (#1180) (a32deca)
     * Use spaces instead of tabs (#1184) (0027300)
     * Add test fixture for overriding the conventional scope (#1166)
       (cb84a08)

   - Update to version 2.9.1:
     * CI/CD fixes only

   - Update to version 2.9.0:
     * chore(release): prepare for v2.9.0
     * docs(website): add highlights for 2.9.0 (#1153)
     * chore(deps-dev): bump typescript in /website in the patch group (#1139)
     * chore(docs): fix some typos (#1149)
     * fix(template): correctly serialize JSON for the commit fields (#1145)
     * docs(security): extend security policy (#1142)
     * chore(deps): bump the minor group in /website with 2 updates (#1116)
     * refactor(lint): apply clippy suggestions
     * feat(context): add release commit range (#1138)
     * fix(submodules): fix submodules handling when using custom range
       (#1136)
     * docs(config): fix typo on commit.links (#1132)
     * chore(deps): upgrade dependencies (#1129)
     * chore(project): migrate to Rust 2024 edition (#1128)
     * feat(changelog): support recursing into submodules (#1082)
     * feat(remote): fetch commits from non-default branches using remotes
       (#1086)
     * feat(git): support disabling sorting commits topologically (#804)
       (#1121)
     * refactor(config): initialize config structs with default values (#1090)
     * chore(dependabot): make dependency updates less noisy
     * chore(dependabot): check dependency updates weekly
     * fix(bump): check the next version against tag_pattern regex (#1070)
     * feat(config): support configuring with a remote URL (#1083)
     * fix(fixtures): evaluate the rc of git-cliff correctly (#1104)
     * fix(bump): accept lowercase values for bump_type config (#1101)
     * docs(readme): add blog posts from the community (#1102)
     * fix(fixtures): use the correct syntax while checking fixture results
       (#1099)
     * docs(website): remove references of tj-actions (#1097)
     * feat(config): add `require_conventional` option (#1061)
     * docs(release): fix Docker Hub URL
     * refactor(lint): use IOError::other (#1074)
     * doc(config): update comments for all configuration options (#1057)
     * docs(quickstart): clarify git-cliff command (#1051)
     * fix(git): handle worktrees while retrieving the path of repository
       (#1054)
     * chore(npm): update yarn.lock
     * fix(remote): fix detection of GitLab merge request sha if commits were
       squashed (#1043)
     * fix(deps): make glob dependency mandatory (#1035)

   - Update to version 2.8.0:
     * cli: Support initializing config with a custom filename
     * config: Discover the configuration file when run in a sub directory
     * git: Improve the set commit range error
     * monorepo: Automatically set include-path for current directory
     * remote: Support enabling native TLS
     * repo: Allow running from sub directories
     * config: Allow environment overwrites when using builtin config
     * fixtures: Update the arguments for custom GitLab API fixture test
     * monorepo: Do not set include-path if workdir is set
     * remote: Fix detection of GitLab merge request sha
     * lib: Add changelog modifier callback to run function
     * lint: Use a shared lint config for the workspace
     * lint: Apply clippy suggestions
     * docker: Fix typo in comment
     * highlights: Add link to the Nix flake
     * jujutsu: Update links to the upstream documentation
     * lib: Allow doc lint
     * license: Update copyright years
     * tips: Extend the merge commit filter example
     * website: Add highlights for 2.8.0
     * fixture: Add fixture for include-path
     * build: Bump MSRV to 1.83.0
     * lint: Allow false positive lint

   - Update to version 2.7.0:
     * refactor(clippy): apply clippy suggestions
     * chore(deps): bump dependencies
     * chore(integration): remove experimental feature disclaimer
     * feat(config): allow overriding the remote API URL via config
     * docs(git): improve docs for commit_preprocessors and commit_parsers
     * feat(jujutsu): add jujustu support
     * perf(test): don't create regex inside a loop
     * chore(log): add trace log about which command is being run
     * fix(remote): preserve first time contributors
     * test(git): find upstream remote when using ssh
     * docs(readme): add blog post about git-cliff
     * chore(config): add the 'other' parser to the default config
     * fix(changelog): fix missing commit fields in context
     * refactor(clippy): apply clippy suggestions
     * test(repo): expand unit tests of the repo module
     * fix(changelog): include the root commit when `--latest` is used with
       one tag
     * chore(deps): bump clap from 4.5.18 to 4.5.19
     * feat(args): add color to the help text
     * chore(release): prepare for v2.6.1
     * refactor(clippy): apply doc_markdown and ignored_unit_patterns lint
     * chore(fixtures): build binaries using dev profile
     * refactor(clippy): apply if_not_else lint
     * fix(remote): avoid setting multiple remotes
     * chore(deps): bump thiserror from 1.0.63 to 1.0.64
     * refactor(clippy): apply assigning_clones lint
     * refactor(clippy): apply single_match_else lint
     * refactor(clippy): apply needless_pass_by_value lint
     * chore(release): prepare for v2.6.0
     * feat(config): add changelog.render_always option
     * chore(deps): bump dependencies
     * fix(changelog): do not change the tag date if tag already exists
     * feat(config): allow configuring output file from config
     * docs(args): fix copy-paste mistake where gitea mentioned gitlab
     * fix(commit): trim the trailing newline for git2 commits
     * fix(bump): suppress template warning when `--bumped-version` is used
     * refactor(clippy): apply explicit_iter_loop lint
     * refactor(clippy): apply manual_is_variant_and lint
     * chore(deps): bump clap_complete from 4.5.23 to 4.5.28
     * chore(deps-dev): bump typescript from 5.5.4 to 5.6.2 in /website in
       the minor group
     * chore(deps): bump pretty_assertions from 1.4.0 to 1.4.1
     * fix(changelog): correctly set the tag message for the latest release
     * refactor(clippy): apply case_sensitive_file_extension_comparisons lint
     * refactor(clippy): apply clippy suggestions
     * refactor(clippy): apply option_as_ref_cloned lint
     * refactor(template)!: add name parameter to the constructor
     * fix(core): avoid the unnecessary loop when no remote feature is
       activated
     * feat(core): add `remote` to commit and deprecate fields
     * refactor(clippy): apply semicolon_if_nothing_returned clippy lint
     * refactor(clippy): apply unnested_or_patterns clippy lint
     * docs(contributing): mention fetching the tags for running tests
       successfully
     * fix(args): support using use_branch_tags from both config and args
     * feat(changelog): support generating changelog for different branches
     * chore(examples): improve example templates
     * chore(lib): fix typos in code comments
     * chore(deps): bump prism-react-renderer from 2.3.1 to 2.4.0 in /website
       in the minor group
     * fix(template): resolve parsing issues with `raw`/`endraw` in Jinja
     * fix(changelog): don't change the context when provided via
       `--from-context`

   - update to version 2.5.0:
     * Remove unnecessary git-cliff-action output file
     * Include new contributors in repository changelog
     * Check for null commit_id in detailed templa
     * Fix comment for changelog header template
     * Update keepachangelog.toml comme
     * Clarify authentication with GitHub tok
     * Correct inverted consequences of configuration val
     * Make example templates more user-friendly
     * Clean up url encoding for GitLab
     * Allow using --bumped-version without conventional commits
     * Allow using environment variables without config file present
     * Fix fetching repository for gitlab integration test
     * URL-encode the owner in remote requests for GitLab
     * Include for-loop arguments in template variables
     * Allow GitLab groups with --gitlab-repo
     * Support bumping to a specific semver type
     * Support count_tags option
     * Skip ssh and x509 signatures in tag messages
     * Generate changelog from JSON context
     * Allow whole commit context to be used in commit parsers
     * Support performance profiling via pprof
     * Activate integration if remote is set manually

   - update to 2.4.0:
     * Support bumping based on configurable custom pattern
     * Support setting the initial_tag
     * multiple improvements to changelog generation
     * Add Gitea support
     * Add Bitbucket support
     * Add GitLab support
     * Support using stdout via dash (-o -)
     * Bug Fixes and documentation updates
     * Add --ignore-tags argument
     * Allow -o and -p together if they point to different files


Patch Instructions:

   To install this openSUSE Security Update use the SUSE recommended installation methods
   like YaST online_update or "zypper patch".

   Alternatively you can run the command listed for your product:

   - openSUSE Backports SLE-15-SP7:

      zypper in -t patch openSUSE-2026-287=1



Package List:

   - openSUSE Backports SLE-15-SP7 (aarch64 i586 ppc64le s390x x86_64):

      git-cliff-2.13.1-bp157.2.3.1

   - openSUSE Backports SLE-15-SP7 (noarch):

      git-cliff-bash-completion-2.13.1-bp157.2.3.1
      git-cliff-fish-completion-2.13.1-bp157.2.3.1
      git-cliff-zsh-completion-2.13.1-bp157.2.3.1


References:

   https://www.suse.com/security/cve/CVE-2025-55159.html
   https://www.suse.com/security/cve/CVE-2026-25541.html
   https://bugzilla.suse.com/1248065
   https://bugzilla.suse.com/1274523
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.