{"id":"openSUSE-SU-2026:21584-1","summary":"Security update for git-cliff","details":"This update for git-cliff fixes the following issues:\n\nChanges in git-cliff:\n\n- Update to version 2.13.1:\n  * Support more configuration file locations\n  * Add per-commit statistics\n  * Expose determined bump type in release context\n  * Add configurable commit processing order\n  * Add environment variable for offline execution\n  * Migrate logging to tracing\n  * Add caching where applicable\n- CVE-2026-25541: bytes: integer overflow in 'BytesMut:reserve' can\n  lead to undefined behavior and crashes (boo#1274523)\n\n- Update to version 2.12.0:\n  * Add offline flag\n  * Add --skip-tags cli argument\n  * Implement commit processing summary\n  * Bug Fixes\n- includes changes from 2.11.0:\n  * Support failing on unmatched commits\n  * Add support for azure devops\n  * Improve repository/directory path resolution\n  * Add split_regex, replace_regex, find_regex filters\n  * Bug Fixes\n- includes changes from 2.10.1:\n  * Add 'integrations' feature flag for enabling all integrations\n  * Bug Fixes\n  * CVE-2025-55159: lab: incorrect bounds check in get_disjoint_mut\n    function can lead to undefined behavior or potential crash due\n    to out-of-bounds access (boo#1248065)\n\n- Update to version 2.10.0:\n  * (config) Support using include and exclude paths in the config (#1173) - (7c2f922)\n  * (parser) Support regex matching on JSON arrays with scalar elements (#1163) - (dc458ea)\n  * (template) Support adding commit statistics to the changelog (#1151) - (05a50d7)\n  * (config) [breaking] Use empty header and footer as default (#1161) (#1172) - (3e9311e)\n  * (config) Check if commit.footers is defined in detailed example (#1170) - (078545f)\n  * (fixtures) Update expected.md after config change (#1176) - (76d3e81)\n  * (generation) Ensure skip_tags condition is evaluated first (#1190) - (318be66)\n  * (repo) Use the correct order while diffing paths (#1188) - (ff6c310)\n  * (ci) Apply security best practices (#1180) - (a32deca)\n  * (config) Implement FromStr instead of Config::parse_from_str() (#1185) - (692345e)\n  * (test) Standardize unit tests for commit module (#1147) - (0446d6a)\n  * (context) Add example usage for statistics (#1162) - (4f7379a)\n  * (quickstart) Remove repetitive words (#1200) - (434f9ee)\n  * (readme) Fix twitter badge (#1164) - (68bd85e)\n  * (readme) Polish badges (#1159) - (941cc2b)\n  * (remote) Fix inconsistency in remote integration documentation (#1165) - (deb29dc)\n  * (website) Add highlights for 2.10.0 (#1225) - (a3fe8c9)\n  * (website) Add installation instructions for gentoo-linux (#1203) - (07fe6bf)\n  * (formatting) Use spaces instead of tabs (#1184) - (0027300)\n  * (fixture) Add test fixture for overriding the conventional scope (#1166) - (cb84a08)\n  * (build) Bump MSRV to 1.85.1 - (d8279d4)\n  * (cd) Use macos-15 runner - (c156fc5)\n  * (cd) Re-enable sccache for maturin - (871c3c9)\n  * (crate) Remove Rust nightly requirement - (4f3e5af)\n  * (fixture) Update test-regex-json-array fixture (#1178) - (95f4056)\n  * (format) Format module imports for readability (#1183) - (6db7d49)\n  * (git) Add .git-blame-ignore-revs - (5b64131)\n  * (npm) Bump git-cliff to 2.9.1 (#1156) - (e13b158)\n  * (website) Update the node version - (566c2a1)\n  * Check if commit.footers is defined in detailed example (#1170) (078545f)\n  * (breaking) Use empty header and footer as default (#1161) (#1172) (3e9311e)\n  * Update expected.md after config change (#1176) (76d3e81)\n  * Use the correct order while diffing paths (#1188) (ff6c310)\n  * Ensure skip_tags condition is evaluated first (#1190) (318be66)\n  * Polish badges (#1159) (941cc2b)\n  * Fix twitter badge (#1164) (68bd85e)\n  * Fix inconsistency in remote integration documentation (#1165) (deb29dc)\n  * Add example usage for statistics (#1162) (4f7379a)\n  * Remove repetitive words (#1200) (434f9ee)\n  * Add installation instructions for gentoo-linux (#1203) (07fe6bf)\n  * Add highlights for 2.10.0 (#1225) (a3fe8c9)\n  * Support regex matching on JSON arrays with scalar elements (#1163) (dc458ea)\n  * Support using include and exclude paths in the config (#1173) (7c2f922)\n  * Support adding commit statistics to the changelog (#1151) (05a50d7)\n  * Bump git-cliff to 2.9.1 (#1156) (e13b158)\n  * Re-enable sccache for maturin (871c3c9)\n  * Update test-regex-json-array fixture (#1178) (95f4056)\n  * Format module imports for readability (#1183) (6db7d49)\n  * Use macos-15 runner (c156fc5)\n  * Update the node version (566c2a1)\n  * Remove Rust nightly requirement (4f3e5af)\n  * Bump MSRV to 1.85.1 (d8279d4)\n  * Add .git-blame-ignore-revs (5b64131)\n  * Standardize unit tests for commit module (#1147) (0446d6a)\n  * Resolve mismatched lifetime syntax warnings (#1167) (9970402)\n  * Implement FromStr instead of Config::parse_from_str() (#1185) (692345e)\n  * Apply security best practices (#1180) (a32deca)\n  * Use spaces instead of tabs (#1184) (0027300)\n  * Add test fixture for overriding the conventional scope (#1166) (cb84a08)\n\n- Update to version 2.9.1:\n  * CI/CD fixes only\n\n- Update to version 2.9.0:\n  * chore(release): prepare for v2.9.0\n  * docs(website): add highlights for 2.9.0 (#1153)\n  * chore(deps-dev): bump typescript in /website in the patch group (#1139)\n  * chore(docs): fix some typos (#1149)\n  * fix(template): correctly serialize JSON for the commit fields (#1145)\n  * docs(security): extend security policy (#1142)\n  * chore(deps): bump the minor group in /website with 2 updates (#1116)\n  * refactor(lint): apply clippy suggestions\n  * feat(context): add release commit range (#1138)\n  * fix(submodules): fix submodules handling when using custom range (#1136)\n  * docs(config): fix typo on commit.links (#1132)\n  * chore(deps): upgrade dependencies (#1129)\n  * chore(project): migrate to Rust 2024 edition (#1128)\n  * feat(changelog): support recursing into submodules (#1082)\n  * feat(remote): fetch commits from non-default branches using remotes (#1086)\n  * feat(git): support disabling sorting commits topologically (#804) (#1121)\n  * refactor(config): initialize config structs with default values (#1090)\n  * chore(dependabot): make dependency updates less noisy\n  * chore(dependabot): check dependency updates weekly\n  * fix(bump): check the next version against tag_pattern regex (#1070)\n  * feat(config): support configuring with a remote URL (#1083)\n  * fix(fixtures): evaluate the rc of git-cliff correctly (#1104)\n  * fix(bump): accept lowercase values for bump_type config (#1101)\n  * docs(readme): add blog posts from the community (#1102)\n  * fix(fixtures): use the correct syntax while checking fixture results (#1099)\n  * docs(website): remove references of tj-actions (#1097)\n  * feat(config): add `require_conventional` option (#1061)\n  * docs(release): fix Docker Hub URL\n  * refactor(lint): use IOError::other (#1074)\n  * doc(config): update comments for all configuration options (#1057)\n  * docs(quickstart): clarify git-cliff command (#1051)\n  * fix(git): handle worktrees while retrieving the path of repository (#1054)\n  * chore(npm): update yarn.lock\n  * fix(remote): fix detection of GitLab merge request sha if commits were squashed (#1043)\n  * fix(deps): make glob dependency mandatory (#1035)\n\n- Update to version 2.8.0:\n  * cli: Support initializing config with a custom filename\n  * config: Discover the configuration file when run in a sub directory\n  * git: Improve the set commit range error\n  * monorepo: Automatically set include-path for current directory\n  * remote: Support enabling native TLS\n  * repo: Allow running from sub directories\n  * config: Allow environment overwrites when using builtin config\n  * fixtures: Update the arguments for custom GitLab API fixture test\n  * monorepo: Do not set include-path if workdir is set\n  * remote: Fix detection of GitLab merge request sha\n  * lib: Add changelog modifier callback to run function\n  * lint: Use a shared lint config for the workspace\n  * lint: Apply clippy suggestions\n  * docker: Fix typo in comment\n  * highlights: Add link to the Nix flake\n  * jujutsu: Update links to the upstream documentation\n  * lib: Allow doc lint\n  * license: Update copyright years\n  * tips: Extend the merge commit filter example\n  * website: Add highlights for 2.8.0\n  * fixture: Add fixture for include-path\n  * build: Bump MSRV to 1.83.0\n  * lint: Allow false positive lint\n\n- Update to version 2.7.0:\n  * refactor(clippy): apply clippy suggestions\n  * chore(deps): bump dependencies\n  * chore(integration): remove experimental feature disclaimer\n  * feat(config): allow overriding the remote API URL via config\n  * docs(git): improve docs for commit_preprocessors and commit_parsers\n  * feat(jujutsu): add jujustu support\n  * perf(test): don't create regex inside a loop\n  * chore(log): add trace log about which command is being run\n  * fix(remote): preserve first time contributors\n  * test(git): find upstream remote when using ssh\n  * docs(readme): add blog post about git-cliff\n  * chore(config): add the 'other' parser to the default config\n  * fix(changelog): fix missing commit fields in context\n  * refactor(clippy): apply clippy suggestions\n  * test(repo): expand unit tests of the repo module\n  * fix(changelog): include the root commit when `--latest` is used with one tag\n  * chore(deps): bump clap from 4.5.18 to 4.5.19\n  * feat(args): add color to the help text\n  * chore(release): prepare for v2.6.1\n  * refactor(clippy): apply doc_markdown and ignored_unit_patterns lint\n  * chore(fixtures): build binaries using dev profile\n  * refactor(clippy): apply if_not_else lint\n  * fix(remote): avoid setting multiple remotes\n  * chore(deps): bump thiserror from 1.0.63 to 1.0.64\n  * refactor(clippy): apply assigning_clones lint\n  * refactor(clippy): apply single_match_else lint\n  * refactor(clippy): apply needless_pass_by_value lint\n  * chore(release): prepare for v2.6.0\n  * feat(config): add changelog.render_always option\n  * chore(deps): bump dependencies\n  * fix(changelog): do not change the tag date if tag already exists\n  * feat(config): allow configuring output file from config\n  * docs(args): fix copy-paste mistake where gitea mentioned gitlab\n  * fix(commit): trim the trailing newline for git2 commits\n  * fix(bump): suppress template warning when `--bumped-version` is used\n  * refactor(clippy): apply explicit_iter_loop lint\n  * refactor(clippy): apply manual_is_variant_and lint\n  * chore(deps): bump clap_complete from 4.5.23 to 4.5.28\n  * chore(deps-dev): bump typescript from 5.5.4 to 5.6.2 in /website in the minor group\n  * chore(deps): bump pretty_assertions from 1.4.0 to 1.4.1\n  * fix(changelog): correctly set the tag message for the latest release\n  * refactor(clippy): apply case_sensitive_file_extension_comparisons lint\n  * refactor(clippy): apply clippy suggestions\n  * refactor(clippy): apply option_as_ref_cloned lint\n  * refactor(template)!: add name parameter to the constructor\n  * fix(core): avoid the unnecessary loop when no remote feature is activated\n  * feat(core): add `remote` to commit and deprecate fields\n  * refactor(clippy): apply semicolon_if_nothing_returned clippy lint\n  * refactor(clippy): apply unnested_or_patterns clippy lint\n  * docs(contributing): mention fetching the tags for running tests successfully\n  * fix(args): support using use_branch_tags from both config and args\n  * feat(changelog): support generating changelog for different branches\n  * chore(examples): improve example templates\n  * chore(lib): fix typos in code comments\n  * chore(deps): bump prism-react-renderer from 2.3.1 to 2.4.0 in /website in the minor group\n  * fix(template): resolve parsing issues with `raw`/`endraw` in Jinja\n  * fix(changelog): don't change the context when provided via `--from-context`\n","modified":"2026-08-16T18:23:43.551645376Z","published":"2026-08-14T15:43:56Z","related":["CVE-2025-55159","CVE-2026-25541"],"upstream":["CVE-2025-55159","CVE-2026-25541"],"references":[{"type":"ADVISORY"},{"type":"REPORT","url":"https://bugzilla.suse.com/1248065"},{"type":"REPORT","url":"https://bugzilla.suse.com/1274523"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-55159"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-25541"}],"affected":[{"package":{"name":"git-cliff","ecosystem":"openSUSE:Leap 16.0","purl":"pkg:rpm/opensuse/git-cliff&distro=openSUSE%20Leap%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.13.1-bp160.1.1"}]}],"ecosystem_specific":{"binaries":[{"git-cliff":"2.13.1-bp160.1.1","git-cliff-bash-completion":"2.13.1-bp160.1.1","git-cliff-fish-completion":"2.13.1-bp160.1.1","git-cliff-zsh-completion":"2.13.1-bp160.1.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21584-1.json"}}],"schema_version":"1.9.0"}