{"id":"openSUSE-SU-2026:21605-1","summary":"Security update for forgejo-cli","details":"This update for forgejo-cli fixes the following issues:\n\nChanges in forgejo-cli:\n\n- Update vendored bytes crate to 1.12.1\n  * CVE-2026-25541: Fixed an integer overflow in BytesMut::reserve that could\n    corrupt the tracked capacity and lead to out-of-bounds slices (boo#1274529).\n\n- update to 0.6.0:\n  * Localization!\n    - forgejo-cli has gained localization support!\n      You can now use it in your preferred language, just like\n      Forgejo itself.\n      Currently de-DE and zh-Hans are included, with several more\n      being in-progress.\n      See the project on Codeberg Translate if you want to help out\n      with any languages you know!\n      https://translate.codeberg.org/projects/forgejo-cli/forgejo-cli/\n  * Additions\n    - (!586) fj issue/pr view assignees to see who is assigned to\n      an issue or pull request\n    - (!582) --avatar/--unset-avatar options on fj repo edit\n    - (!554) fj repo star-status to check if you've starred a repo\n    - (!547) --cwd option to set the working directory a command is\n      run in\n    - (!533, !561) Commands to watch and unwatch repos\n    - (!462) Resolve SSH host names from SSH config\n    - (!279, !464, !472, !489, !491, !513, !594) Localization\n    - Added fj auth login support for the following instances:\n      - v16.next.forgejo.org\n      - v17.next.forgejo.org\n    - Removed fj auth login support for the following instances\n      that have shut down:\n      - v7.next.forgejo.org\n      - v12.next.forgejo.org\n  * Changes\n    - (!535) Added an error message when fj auth login fails to\n      open the browser\n    - (!523) fj auth add-key was renamed to fj auth add-token. An\n      alias still exists to add-key, so this isn't a breaking\n      change.\n    - (!514) The --host flag can now be anywhere in the command,\n      instead of only the beginning\n    - (!504) fj auth add-token no longer takes a username argument.\n  * Fixes\n    - (!579) Fixed fj issue unassign incorrectly unassigning\n      everyone except the intended users\n    - (!569) Fixed display of labels failing when a label is marked\n      as exclusive but does not contain a slash\n    - (!542) Fixed parsing of SSH shorthand urls\n    - (!510) Fixed fj pr checkout failing when the instance URL\n      contained a port\n    - (!437) Fixed incorrect parsing of activity info\n  * Other\n    - (!573) Use rust 2024 edition\n    - (!560) Simplify determining repo owner\n    - (!531) Fix clippy warnings\n    - (!527) Remove unused dependencies, narrow tokio features\n    - (!526) Replace crossterm with terminal_size\n    - (!520) Optimize cargo release profile\n    - (!469) Fix typo\n    - (!449) Restricted file permissions at creation time\n    - (!443) Add oneline helptext to 'repo migrate' command\n\n- update to 0.5.0:\n  * Additions\n    - (!334) Support for managing labels on issues and repos.\n    - (!349) repo edit and repo units for modifying settings on a\n      repo and repo units.\n    - (!373) Use the needed CLI flags for more editors when opening\n      them.\n    - (!385) Use the editor defined in git's core.editor config\n      option by default (falling back to $EDITOR if it is not set).\n    - (!414) Add commands to assign and unassign users to issues\n      and PRs.\n    - (!415) Support all README files in fj repo readme, regardless\n      of case or extension.\n    - (!416) Add the option to choose what repo to own the new repo\n      to fj repo migrate.\n    - (!419) Show a warning when viewing an archived repo.\n    - (!420) Add a notice about git push --force not being\n      supported on AGit PRs.\n    - Added fj auth login support for the following instances:\n      - v15.next.forgejo.org\n      - codefloe.com\n  * Fixes\n    - (!393) Don't include pull requests in fj issues search.\n    - (!407) Guarantee opening the browser in fj auth login doesn't\n      block.\n    - (!417) Prevent incorrectly reusing the refresh token when\n      refreshing OAuth tokens.\n  * Other\n    - (!278) Improved \"no repo info\" error message.\n    - (!403) Build aarch64 artifacts for new releases.\n\n- update to 0.4.1:\n  * Fixes\n    - (!368) Generate the correct PKCE challenge verifier. This was\n      preventing fj auth login from succeeding.\n\n- Update to version 0.4.0:\n  * Support for issue & pull request templates with fj issue/pr create\n    --template\n  * fj pr create --autofill, which will automatically populate the PR's title\n    and body from the commit(s)\n  * fj user key and fj user gpg commands for managing uploaded SSH and GPG keys\n  * fj user repos --page, to select the page of results to view\n  * fj issue/pr create/comment --body-from-file to use the contents of a file\n    as the body\n  * --identity-file/-I flag for selecting the SSH identity to use\n  * fj tag to manage git tags\n  * fj issue search --state all\n  * --remote & --repo flags can now be at the end of the command with the rest\n    of the flags\n\n- update to 0.3.0:\n  * Additions\n    - Added fj completion to generate completion scripts for various\n      shells\n    - Added fj org for Organization commands.\n    - Added fj actions for Forgejo Actions-related commands (thank\n      you, @LordMZTE !)\n    - OAuth client IDs for fj auth login can now be customized.\n    See the wiki for more on the new features.\n\thttps://codeberg.org/Cyborus/forgejo-cli/wiki/Organizations\n  * Fixes\n    - Keys file now has proper file permissions\n    - Fixed incorrect help commands (thank you, @0ko !)\n    - Always set user agent in requests\n\n- update to 0.2.0:\n  * Additions\n    - pr create and issue create now have a --web flag that opens\n      the creation page in your browser instead of creating it on\n      the terminal.\n    - pr --agit will create a pull request with agit flow, so you\n      don't need to fork the repository.\n    - pr status --wait will only exits once all PR checks finish.\n    - repo migrate to migrate/mirror repositories from other hosts.\n    - repo readme to print a repository's readme to the terminal.\n    - version --verbose prints extra info useful for debugging\n  * Fixes\n    - Public endpoints can now be accessed without authenticating\n    - The API will be accessed via the http url even when it\n      differs from the ssh url and the local remote points to the\n      ssh url.\n    - browse commands will no long hang the terminal\n    - Local repos will now be found even when in a subdirectory\n    - SSH urls in repo remotes will now be parsed correctly\n    - Improved pull request detection\n","modified":"2026-08-21T18:23:46.059602515Z","published":"2026-08-18T16:51:08Z","related":["CVE-2025-3416","CVE-2025-55159","CVE-2026-25541"],"upstream":["CVE-2025-3416","CVE-2025-55159","CVE-2026-25541"],"references":[{"type":"ADVISORY"},{"type":"REPORT","url":"https://bugzilla.suse.com/1242683"},{"type":"REPORT","url":"https://bugzilla.suse.com/1248047"},{"type":"REPORT","url":"https://bugzilla.suse.com/1274529"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-3416"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-55159"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-25541"}],"affected":[{"package":{"name":"forgejo-cli","ecosystem":"openSUSE:Leap 16.0","purl":"pkg:rpm/opensuse/forgejo-cli&distro=openSUSE%20Leap%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.6.0-bp160.1.1"}]}],"ecosystem_specific":{"binaries":[{"forgejo-cli":"0.6.0-bp160.1.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21605-1.json"}}],"schema_version":"1.9.0"}