{"id":"openSUSE-SU-2026:21603-1","summary":"Security update for gitea-tea","details":"This update for gitea-tea fixes the following issues:\n\nChanges in gitea-tea:\n\n- Update to 0.15.1, bringing in the 0.14.2/0.15.0/0.15.1 upstream\n  changes below (bsc#1253576):\n  * CVE-2025-47913: golang.org/x/crypto/ssh/agent client process\n    termination on an unexpected response to a key listing or\n    signing request, fixed by the vendored x/crypto bump to 0.54.0\n    (fix floor is 0.43.0 per GO-2025-4116)\n\n- update to 0.15.1:\n  * f34697c5ed chore(config): replace authgate SDK with signet (#1081)\n  * a613a344de fix(test): disable gpg signing in worktree test repo (#1072)\n  * 6435b12202 chore(deps): pin dependencies (#1064)\n\n- update to 0.15.0:\n  * fix(context): clarify the fallback login prompt wording in #1061\n  * Fix notifications --mine outside git repositories in #1056\n  * feat(assignees): add set, add, and remove assignees APIs in #1045\n  * fix(deps): update go dependencies in #1057\n  * fix(deps): update go dependencies in #1051\n  * fix(theme): don't query the terminal at start-up in #1054\n  * upgrade go sdk and add test in #1048\n  * feat(comments): accept -d/--description for comment body in #1043\n  * Add reply to code review in #978\n  * fix(http): add transport timeouts so tea fails fast on stalled\n    servers in #1020\n  * fix(config): write to keychain before config in #1044\n\n- Update to version 0.14.2:\n  + fix(labels): add org label for ls and pr\n  + fix(oauth): pass resolved redirect_uri to token exchange\n  + feat(pulls): show PR URL in detail view\n  + feat(comments): add list/edit/delete subcommands to tea comment\n  + feat(pulls): add --draft to create and --draft/--ready to edit\n  + fix(pulls): restore standard fork-flow PR creation\n  + fix(comment): don't block on stdin when body is given positionally\n  + docs(login): make the git credential helper discoverable\n  + fix(print): distinguish draft PRs from conflicting PRs\n  + feat: add wiki CLI commands\n  + fix(context): improve local repo detection logic and test\n","modified":"2026-08-21T18:23:47.098203026Z","published":"2026-08-18T16:01:16Z","related":["CVE-2024-45337","CVE-2024-45338","CVE-2025-22869","CVE-2025-22872","CVE-2025-47911","CVE-2025-47913","CVE-2025-58190"],"upstream":["CVE-2024-45337","CVE-2024-45338","CVE-2025-22869","CVE-2025-22872","CVE-2025-47911","CVE-2025-47913","CVE-2025-58190"],"references":[{"type":"ADVISORY"},{"type":"REPORT","url":"https://bugzilla.suse.com/1234598"},{"type":"REPORT","url":"https://bugzilla.suse.com/1235367"},{"type":"REPORT","url":"https://bugzilla.suse.com/1239493"},{"type":"REPORT","url":"https://bugzilla.suse.com/1241819"},{"type":"REPORT","url":"https://bugzilla.suse.com/1251471"},{"type":"REPORT","url":"https://bugzilla.suse.com/1251663"},{"type":"REPORT","url":"https://bugzilla.suse.com/1253576"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2024-45337"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2024-45338"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-22869"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-22872"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-47911"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-47913"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-58190"}],"affected":[{"package":{"name":"gitea-tea","ecosystem":"openSUSE:Leap 16.0","purl":"pkg:rpm/opensuse/gitea-tea&distro=openSUSE%20Leap%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.15.1-bp160.1.1"}]}],"ecosystem_specific":{"binaries":[{"gitea-tea-zsh-completion":"0.15.1-bp160.1.1","gitea-tea":"0.15.1-bp160.1.1","gitea-tea-bash-completion":"0.15.1-bp160.1.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21603-1.json"}}],"schema_version":"1.9.0"}