Update Info

SUSE-PackageHub-16.0-packagehub-92


Recommended update for minisign


Type: recommended
Severity: moderate
Issued: 2026-01-23
Description:
This update for minisign fixes the following issues:

Changes in minisign:

- Bugfix:
  * bugfix: duplicate command-line arguments [7dfdb3c]

- Security fix: [gpg.fail/trustcomment]
  * Trusted comment injection (minisign) [6c59875]
  * trim(): only trim trailing \r\n, reject straight \r characters

- Security fix: [gpg.fail/minisign]
  * Trusted comment injection (minisign) [a10dc92]
  * Bail out if the signature file contains unprintable characters

- Update to version 0.12
  * Libsodium is now an optional dependency. When using the Zig
    toolchain to compile Minisign, you can specify the
    -Dwithout-libsodium flag to build and run without libsodium.
  * Key identifiers are now zero-padded when printed.


              

References


No references

Packages


  • minisign-0.12-bp160.1.1