openSUSE-SU-2026:0287-1: important: Security update for git-cliff
| Newsgroups | gmane.linux.suse.security.announce |
|---|---|
| Message-ID | <[email protected]> |
openSUSE Security Update: Security update for git-cliff
______________________________________________________________________________
Announcement ID: openSUSE-SU-2026:0287-1
Rating: important
References: #1248065 #1274523
Cross-References: CVE-2025-55159 CVE-2026-25541
CVSS scores:
CVE-2025-55159 (SUSE): 5.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N
CVE-2026-25541 (SUSE): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Affected Products:
openSUSE Backports SLE-15-SP7
______________________________________________________________________________
An update that fixes two vulnerabilities is now available.
Description:
This update for git-cliff fixes the following issues:
- Update to version 2.13.1:
* Support more configuration file locations
* Add per-commit statistics
* Expose determined bump type in release context
* Add configurable commit processing order
* Add environment variable for offline execution
* Migrate logging to tracing
* Add caching where applicable
- CVE-2026-25541: bytes: integer overflow in 'BytesMut:reserve' can lead
to undefined behavior and crashes (boo#1274523)
- Update to version 2.12.0:
* Add offline flag
* Add --skip-tags cli argument
* Implement commit processing summary
* Bug Fixes
- includes changes from 2.11.0:
* Support failing on unmatched commits
* Add support for azure devops
* Improve repository/directory path resolution
* Add split_regex, replace_regex, find_regex filters
* Bug Fixes
- -includes changes from 2.10.1:
* Add 'integrations' feature flag for enabling all integrations
* Bug Fixes
* CVE-2025-55159: lab: incorrect bounds check in get_disjoint_mut
function can lead to undefined behavior or potential crash due to
out-of-bounds access (boo#1248065)
- Update to version 2.10.0:
* (config) Support using include and exclude paths in the config (#1173)
- (7c2f922)
* (parser) Support regex matching on JSON arrays with scalar elements
(#1163) - (dc458ea)
* (template) Support adding commit statistics to the changelog (#1151) -
(05a50d7)
* (config) [breaking] Use empty header and footer as default (#1161)
(#1172) - (3e9311e)
* (config) Check if commit.footers is defined in detailed example
(#1170) - (078545f)
* (fixtures) Update expected.md after config change (#1176) - (76d3e81)
* (generation) Ensure skip_tags condition is evaluated first (#1190) -
(318be66)
* (repo) Use the correct order while diffing paths (#1188) - (ff6c310)
* (ci) Apply security best practices (#1180) - (a32deca)
* (config) Implement FromStr instead of Config::parse_from_str() (#1185)
- (692345e)
* (test) Standardize unit tests for commit module (#1147) - (0446d6a)
* (context) Add example usage for statistics (#1162) - (4f7379a)
* (quickstart) Remove repetitive words (#1200) - (434f9ee)
* (readme) Fix twitter badge (#1164) - (68bd85e)
* (readme) Polish badges (#1159) - (941cc2b)
* (remote) Fix inconsistency in remote integration documentation (#1165)
- (deb29dc)
* (website) Add highlights for 2.10.0 (#1225) - (a3fe8c9)
* (website) Add installation instructions for gentoo-linux (#1203) -
(07fe6bf)
* (formatting) Use spaces instead of tabs (#1184) - (0027300)
* (fixture) Add test fixture for overriding the conventional scope
(#1166) - (cb84a08)
* (build) Bump MSRV to 1.85.1 - (d8279d4)
* (cd) Use macos-15 runner - (c156fc5)
* (cd) Re-enable sccache for maturin - (871c3c9)
* (crate) Remove Rust nightly requirement - (4f3e5af)
* (fixture) Update test-regex-json-array fixture (#1178) - (95f4056)
* (format) Format module imports for readability (#1183) - (6db7d49)
* (git) Add .git-blame-ignore-revs - (5b64131)
* (npm) Bump git-cliff to 2.9.1 (#1156) - (e13b158)
* (website) Update the node version - (566c2a1)
* Check if commit.footers is defined in detailed example (#1170)
(078545f)
* (breaking) Use empty header and footer as default (#1161) (#1172)
(3e9311e)
* Update expected.md after config change (#1176) (76d3e81)
* Use the correct order while diffing paths (#1188) (ff6c310)
* Ensure skip_tags condition is evaluated first (#1190) (318be66)
* Polish badges (#1159) (941cc2b)
* Fix twitter badge (#1164) (68bd85e)
* Fix inconsistency in remote integration documentation (#1165) (deb29dc)
* Add example usage for statistics (#1162) (4f7379a)
* Remove repetitive words (#1200) (434f9ee)
* Add installation instructions for gentoo-linux (#1203) (07fe6bf)
* Add highlights for 2.10.0 (#1225) (a3fe8c9)
* Support regex matching on JSON arrays with scalar elements (#1163)
(dc458ea)
* Support using include and exclude paths in the config (#1173) (7c2f922)
* Support adding commit statistics to the changelog (#1151) (05a50d7)
* Bump git-cliff to 2.9.1 (#1156) (e13b158)
* Re-enable sccache for maturin (871c3c9)
* Update test-regex-json-array fixture (#1178) (95f4056)
* Format module imports for readability (#1183) (6db7d49)
* Use macos-15 runner (c156fc5)
* Update the node version (566c2a1)
* Remove Rust nightly requirement (4f3e5af)
* Bump MSRV to 1.85.1 (d8279d4)
* Add .git-blame-ignore-revs (5b64131)
* Standardize unit tests for commit module (#1147) (0446d6a)
* Resolve mismatched lifetime syntax warnings (#1167) (9970402)
* Implement FromStr instead of Config::parse_from_str() (#1185) (692345e)
* Apply security best practices (#1180) (a32deca)
* Use spaces instead of tabs (#1184) (0027300)
* Add test fixture for overriding the conventional scope (#1166)
(cb84a08)
- Update to version 2.9.1:
* CI/CD fixes only
- Update to version 2.9.0:
* chore(release): prepare for v2.9.0
* docs(website): add highlights for 2.9.0 (#1153)
* chore(deps-dev): bump typescript in /website in the patch group (#1139)
* chore(docs): fix some typos (#1149)
* fix(template): correctly serialize JSON for the commit fields (#1145)
* docs(security): extend security policy (#1142)
* chore(deps): bump the minor group in /website with 2 updates (#1116)
* refactor(lint): apply clippy suggestions
* feat(context): add release commit range (#1138)
* fix(submodules): fix submodules handling when using custom range
(#1136)
* docs(config): fix typo on commit.links (#1132)
* chore(deps): upgrade dependencies (#1129)
* chore(project): migrate to Rust 2024 edition (#1128)
* feat(changelog): support recursing into submodules (#1082)
* feat(remote): fetch commits from non-default branches using remotes
(#1086)
* feat(git): support disabling sorting commits topologically (#804)
(#1121)
* refactor(config): initialize config structs with default values (#1090)
* chore(dependabot): make dependency updates less noisy
* chore(dependabot): check dependency updates weekly
* fix(bump): check the next version against tag_pattern regex (#1070)
* feat(config): support configuring with a remote URL (#1083)
* fix(fixtures): evaluate the rc of git-cliff correctly (#1104)
* fix(bump): accept lowercase values for bump_type config (#1101)
* docs(readme): add blog posts from the community (#1102)
* fix(fixtures): use the correct syntax while checking fixture results
(#1099)
* docs(website): remove references of tj-actions (#1097)
* feat(config): add `require_conventional` option (#1061)
* docs(release): fix Docker Hub URL
* refactor(lint): use IOError::other (#1074)
* doc(config): update comments for all configuration options (#1057)
* docs(quickstart): clarify git-cliff command (#1051)
* fix(git): handle worktrees while retrieving the path of repository
(#1054)
* chore(npm): update yarn.lock
* fix(remote): fix detection of GitLab merge request sha if commits were
squashed (#1043)
* fix(deps): make glob dependency mandatory (#1035)
- Update to version 2.8.0:
* cli: Support initializing config with a custom filename
* config: Discover the configuration file when run in a sub directory
* git: Improve the set commit range error
* monorepo: Automatically set include-path for current directory
* remote: Support enabling native TLS
* repo: Allow running from sub directories
* config: Allow environment overwrites when using builtin config
* fixtures: Update the arguments for custom GitLab API fixture test
* monorepo: Do not set include-path if workdir is set
* remote: Fix detection of GitLab merge request sha
* lib: Add changelog modifier callback to run function
* lint: Use a shared lint config for the workspace
* lint: Apply clippy suggestions
* docker: Fix typo in comment
* highlights: Add link to the Nix flake
* jujutsu: Update links to the upstream documentation
* lib: Allow doc lint
* license: Update copyright years
* tips: Extend the merge commit filter example
* website: Add highlights for 2.8.0
* fixture: Add fixture for include-path
* build: Bump MSRV to 1.83.0
* lint: Allow false positive lint
- Update to version 2.7.0:
* refactor(clippy): apply clippy suggestions
* chore(deps): bump dependencies
* chore(integration): remove experimental feature disclaimer
* feat(config): allow overriding the remote API URL via config
* docs(git): improve docs for commit_preprocessors and commit_parsers
* feat(jujutsu): add jujustu support
* perf(test): don't create regex inside a loop
* chore(log): add trace log about which command is being run
* fix(remote): preserve first time contributors
* test(git): find upstream remote when using ssh
* docs(readme): add blog post about git-cliff
* chore(config): add the 'other' parser to the default config
* fix(changelog): fix missing commit fields in context
* refactor(clippy): apply clippy suggestions
* test(repo): expand unit tests of the repo module
* fix(changelog): include the root commit when `--latest` is used with
one tag
* chore(deps): bump clap from 4.5.18 to 4.5.19
* feat(args): add color to the help text
* chore(release): prepare for v2.6.1
* refactor(clippy): apply doc_markdown and ignored_unit_patterns lint
* chore(fixtures): build binaries using dev profile
* refactor(clippy): apply if_not_else lint
* fix(remote): avoid setting multiple remotes
* chore(deps): bump thiserror from 1.0.63 to 1.0.64
* refactor(clippy): apply assigning_clones lint
* refactor(clippy): apply single_match_else lint
* refactor(clippy): apply needless_pass_by_value lint
* chore(release): prepare for v2.6.0
* feat(config): add changelog.render_always option
* chore(deps): bump dependencies
* fix(changelog): do not change the tag date if tag already exists
* feat(config): allow configuring output file from config
* docs(args): fix copy-paste mistake where gitea mentioned gitlab
* fix(commit): trim the trailing newline for git2 commits
* fix(bump): suppress template warning when `--bumped-version` is used
* refactor(clippy): apply explicit_iter_loop lint
* refactor(clippy): apply manual_is_variant_and lint
* chore(deps): bump clap_complete from 4.5.23 to 4.5.28
* chore(deps-dev): bump typescript from 5.5.4 to 5.6.2 in /website in
the minor group
* chore(deps): bump pretty_assertions from 1.4.0 to 1.4.1
* fix(changelog): correctly set the tag message for the latest release
* refactor(clippy): apply case_sensitive_file_extension_comparisons lint
* refactor(clippy): apply clippy suggestions
* refactor(clippy): apply option_as_ref_cloned lint
* refactor(template)!: add name parameter to the constructor
* fix(core): avoid the unnecessary loop when no remote feature is
activated
* feat(core): add `remote` to commit and deprecate fields
* refactor(clippy): apply semicolon_if_nothing_returned clippy lint
* refactor(clippy): apply unnested_or_patterns clippy lint
* docs(contributing): mention fetching the tags for running tests
successfully
* fix(args): support using use_branch_tags from both config and args
* feat(changelog): support generating changelog for different branches
* chore(examples): improve example templates
* chore(lib): fix typos in code comments
* chore(deps): bump prism-react-renderer from 2.3.1 to 2.4.0 in /website
in the minor group
* fix(template): resolve parsing issues with `raw`/`endraw` in Jinja
* fix(changelog): don't change the context when provided via
`--from-context`
- update to version 2.5.0:
* Remove unnecessary git-cliff-action output file
* Include new contributors in repository changelog
* Check for null commit_id in detailed templa
* Fix comment for changelog header template
* Update keepachangelog.toml comme
* Clarify authentication with GitHub tok
* Correct inverted consequences of configuration val
* Make example templates more user-friendly
* Clean up url encoding for GitLab
* Allow using --bumped-version without conventional commits
* Allow using environment variables without config file present
* Fix fetching repository for gitlab integration test
* URL-encode the owner in remote requests for GitLab
* Include for-loop arguments in template variables
* Allow GitLab groups with --gitlab-repo
* Support bumping to a specific semver type
* Support count_tags option
* Skip ssh and x509 signatures in tag messages
* Generate changelog from JSON context
* Allow whole commit context to be used in commit parsers
* Support performance profiling via pprof
* Activate integration if remote is set manually
- update to 2.4.0:
* Support bumping based on configurable custom pattern
* Support setting the initial_tag
* multiple improvements to changelog generation
* Add Gitea support
* Add Bitbucket support
* Add GitLab support
* Support using stdout via dash (-o -)
* Bug Fixes and documentation updates
* Add --ignore-tags argument
* Allow -o and -p together if they point to different files
Patch Instructions:
To install this openSUSE Security Update use the SUSE recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Backports SLE-15-SP7:
zypper in -t patch openSUSE-2026-287=1
Package List:
- openSUSE Backports SLE-15-SP7 (aarch64 i586 ppc64le s390x x86_64):
git-cliff-2.13.1-bp157.2.3.1
- openSUSE Backports SLE-15-SP7 (noarch):
git-cliff-bash-completion-2.13.1-bp157.2.3.1
git-cliff-fish-completion-2.13.1-bp157.2.3.1
git-cliff-zsh-completion-2.13.1-bp157.2.3.1
References:
https://www.suse.com/security/cve/CVE-2025-55159.html
https://www.suse.com/security/cve/CVE-2026-25541.html
https://bugzilla.suse.com/1248065
https://bugzilla.suse.com/1274523