SUSE alert openSUSE-SU-2026:21675-1 (broot)
| From: | null@suse.de | |
| To: | security-announce@lists.opensuse.org | |
| Subject: | openSUSE-SU-2026:21675-1: moderate: Security update for broot | |
| Date: | Sat, 29 Aug 2026 17:52:05 +0200 | |
| Message-ID: | <20260829155205.6D51FFDCB@maintenance.suse.de> | |
| Archive-link: | Article |
openSUSE security update: security update for broot ------------------------------------------------------------- Announcement ID: openSUSE-SU-2026:21675-1 Rating: moderate References: * bsc#1275994 Cross-References: * CVE-2026-72847 CVSS scores: * CVE-2026-72847 ( SUSE ): 4.6 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N Affected Products: openSUSE Leap 16.0 ------------------------------------------------------------- An update that solves one vulnerability and has one bug fix can now be installed. Description: This update for broot fixes the following issues: Changes in broot: - v1.59.0 (CVE-2026-72847 boo#1275994) * new shell_command verb attribute: run a command through a shell (sh -c / cmd /C) so &&, ; and pipes work, without leaving broot - Fix #1145 * fix invalid official Mac binary (duplicate linked dylib) with new build chain - Fix #1194 * Sixel graphics support for image preview, auto-detected: works in iterm2, Windows Terminal 1.22+ and Sixel-capable Unix terminals (foot, mlterm, xterm built with Sixel, recent WezTerm). Kitty remains the preferred protocol when available. Note: this requires broot to be compiled with sixel feature (eg cargo install broot --features sixel) - Fix #568 * High-Res images in Rio terminal (detect it to enable the Kitty image protocol) - Fix #1179 * fix iTerm2 3.6.10 and later not displaying Hi-Res images, the version being compared as text * fix content-exact match line number off-by-one when the match starts at the first byte of a line (broot jumped to the line above) * new :no_action internal, doing nothing, which can be used to disable a key - Fix #328 * fix: detect a duplicate broot server name instead of silently overtaking the running server - Fix #1065 * fix preview transformers extension matching not working with double extensions such as .tar.gz - Fix #1195 * strip escape sequences from displayed names to prevent OSC injections - Fix #1188 * fall back to numeric uid/gid instead of ???? when the user or group name can't be resolved, which is always the case on statically linked musl builds - Fix #1075 * fix panic on a content regex matching the empty string at the end of a line ending with a control char (eg cr/$/ on a CRLF file) * fix Windows paths (containing backslashes) being mangled by the launcher's eval when using :cd and similar; also fixes escaping of paths containing a single quote - Fix #1100 * fix br failing on Windows/PowerShell when the temp path contains a space (e.g. a space in the Windows username) - Fix #788 * JPEG XL images are no longer previewed: the decoder had out-of-bounds bugs and the fix needs a more recent rustc (if you need it, tell me and I'll try to make it opt-in) * rustc minimal version changed from 1.83 to 1.85, and edition 2024 - v1.58.0 * change the way possible verb completions are listed, making it more readable when there are more than what fits the screen * fix argument of :select and :show being ignored in a --cmd sequence - Fix 1176 - v1.57.0 * help: verb 'keys' and 'description' columns now searchable - Fix #1163 * fix :print_path / :print_relative_path adding a trailing empty line when printing a multi-item staging area - Fix #1062 * Skin: attributes (bold, underlined, etc.) of the "selected_line" entry now applied - Fix #1156 * if no Wezterm version is found, broot now assumes it's recent enough to support kitty protocol for image - Fix #509 - v1.56.4 * fix compilation on non unix platforms (1.56.3 isn't available on those systems) - v1.56.3 * fix control characters sometimes remaining in the terminal after broot exit * nushell: rename br module to avoid conflict in last nushell version - Fix #1138 * :open_stay on the staging area opens every staged file through the system opener - Fix #444 - v1.56.2 * {file-root-relative} argument - Fix #1142 * fix :clear_stage (or other operations closing the stage panel) often closing broot - Fix #1143 - v1.56.1 * fix a typo in a verb in default conf - v1.56.0 * impacted_panel verb argument, allows the effect of a verb to be on another panel (eg to scroll the preview panel without removing the focus from the tree) - Fix #1119 * focus_panel_left and focus_panel_right internals - Fix #1115 * Major Feature: merge staged files to issue a single command: when a verb argument has a space-separated or comma-separated flag, a single external command is run even when the selection is multiple - Fix #465 The default verbs.json file has an example of a zip verb building an archive from all staged files. - v1.55.0 * activate Kitty Graphics Protocol to display Hi-Res images in iTerm2 * Tokyo Night skin ( https://github.com/Canop/broot/blob/main/resources/defaul... ) * matches related to several name patterns joined with and/or in a composite pattern are merged instead of having just the first one shown * nushell integration: switch $nu.temp-path to $nu.temp-dir - #1116 - v1.54.0 * fix crash on rendering B&W images with Kitty image protocol * don't match directories when a composite pattern has a content pattern, even negated (eg /js$/&!c/;: it's clear the user wants to match js files not containing a semicolon) - v1.53.0 * fix some cases of the verb not removed from the input on execution (with a risk of accidental double execution) * add the :filesystems (short :fs) verb and state on windows (it was already present on linux and mac). * improve the generation of preview pattern from a file tree pattern (i.e. going from /java$/&c/test to /test on opening a matching file in preview). With this change broot avoids filtering the preview when it shouldn't (eg when you searched /java$/|c/test) - See #1097 * display files whose name isn't valid UTF-8 (they were previously ignored) * android executable is back to the official binary archive - v1.52.0 * auto_open_staging_area preference - Fix #1090 * search content of file target of symlink - Fix #1081 * fix nushell script (swapped logic for --listen and --listen-auto) * return non-zero exit code on error - v1.51.0 * improved image rendering (both speed by using the zune-image library, and quality with bilinear interpolation) * fix compilation broken by 1.50.0 on Android * --listen-auto listens for commands on a random linux socket - Fix #1064 * when auto-completing, back-tab cycles in reverse order - Fix #1071 - v1.50.0 * big text files now only partially loaded for initial display, remaining being done in background - Fix #1052 * better support of kitty image protocol over tmux, ssh or unknown terminals, with kitty_graphics_display option and $TMUX_NEST_COUNT env variable - see PR #1034 * "trash" compilation feature removed: trash related features are built depending on the platform * build chain revised. Future official releases should include a Mac binary * fix crash on double unstage of last entry in stage panel - fix #1057 * fallback to transparent background for text preview when the skin specifies nothing - v1.49.1 * watching made much more efficient (some deep changes won't lead to an automatic refresh which only impacts dir size) * the name given with `--listen` is now provided to verb as the `{server-name}` verb argument - v1.49.0 * `:toggle_watch` internal, with `:watch` shortcut, bound by default to `alt-w`. When watching is active, the tree is refreshed whenever any directory/file, even deep, is changed - Fix #730 * fallback to a transparent background for images in image preview instead of a specific color - Fix #1040 - Thanks @letmeiiiin * fix --server socket written at a non writable location on Android/termux - Fix #1045 - v1.48.0 * Support for the 'Cmd' modifier in key shortcuts (the key is called 'Command', 'Super', 'Apple', 'Windows', depending on systems and users) * "filesystem" features have been made available for Mac: - the `:fs` screen, listing filesystems - filesystem free space & total space displayed when size computations are requested - device id displayed with `:toggle_device_id` (shortcut: "dev") * Fix `.config/git/ignore` not being loaded on Mac - Fix #1032 - Thanks @9999years - v1.47.0 * text files with control chars were previously previewed as binary. They're now displayed as text with some '�' when needed - Fix #977 * files with ANSI escape codes (such as the one you would obtain with `dysk --color yes > ansi.txt` can now be previewed with `:preview_tty` - Fix #1019 * first line of the tree is cropped (right aligned) when it doesn't fit - v1.46.5 * fix `:focus some/path` called in a command sequence always opening new panel - Fix #1014 - v1.46.4 * support for keys F13 to F24 (if your system supports it) * fix `:focus` with argument given in configuration going up one level when root is selected - Fix #1009 * fix `--max-depth` ignored when in `default_flags` - Fix #1013 - v1.46.3 * fix broot waiting for events on internals like `:quit` - Fix #1006 - v1.46.2 * fix broken nushell script (`--max-depth` again) - v1.46.1 * fix nushell script broken by new `--max-depth` argument - v1.46.0 * :set_max_depth <number> and :unset_max_depth * clear cache when files are deleted in staging area * recompute preview transform when source file changed since last preview - v1.45.1 * Fix compilation failing without `--locked` - v1.45.0 * Fix total search impossible to redo after refresh * With `refresh_after: false`, a verb configuration can request that the tree isn't refreshed after its execution - v1.44.7 * fix bad regex match position * update resvg dependency to 0.44 * on `--server`, remove the existing socket if it already exists - v1.44.6 * fix .ignore files ignored when not in a git repository * update git2 dependency to 0.20 - v1.44.5 * no real change (just reverting a crate name to ease some packaging) - v1.44.4 * fix panic in preview on syntax coloring (when a sublime syntax isn't compatible with the regex engine) - v1.44.3 * removed default bindings on left and right keys. You may add them back by adding this to your verbs.hjson: { key: "left", internal: "back" } { key: "right", internal: "open_stay" } * rustc minimal version changed from 1.76 to 1.79, which allows better performing image rendering * remove dependency to onig, to allow compatibility with gcc 15 - v1.44.2 * temp files created for kitty now erased on quitting or when too many of them have been written * no longer panics when launched with BROOT_LOG=debug but the broot.log file can't be created * fix user and group names displayed as "????" when coming from openldap - v1.44.1 * fix wrong position of IMEs (input method editors) popup - See #948 * improve querying the terminal for capabilities (prevent some escape chars from leaking) - v1.44.0 * `:focus_staging_area_no_open` internal, focus the staging area if it's already open, does nothing in other case * fix some composite patterns with several operators and no parenthesis - v1.43.0 * 'Size' and 'Deletion date' columns in trash screen. This screen now supports the `:toggle_date`, `:toggle_size`, `:sort_by_date`, and `:sort_by_size` internals. * new `:show` internal make the provided path visible and selected, adding lines to the tree if necessary, does nothing if the provided path is not a descendant of the current tree root (this part may change depending on feedback) - v1.42.0 * support of `.ignore` files with the same syntax than `.gitignore`. They have priority over `.gitignore` so that a personal `.ignore` file can override a shared `.gitignore` - See https://dystroy.org/broot/tree_view/#hidden-ignored-files * `:toggle_ignore` internal, identical to `:toggle_git_ignore`, but with a clearer name so should be preferred * the `panels` verb filter now works in most contexts (it was previously only checked on key events) * many dependencies updated - v1.41.1 * allow compilation with rustc 1.76 - v1.41.0 * Major Feature: :search_again - ctrl-s now triggers `:search_again` which either - brings back the last used search pattern, when no filtering pattern is active - does a "total search" if a filtering pattern is active and the search wasn't complete * Major Feature: internals changing panel widths - `set_panel_width`, taking as parameter the index of the panel and the desired width - `move_panel_divider`, taking as parameter the index of the divider and the desired change - `ctrl-<` is bound by default to `:move_panel_divider 0 -1` - `ctrl->` is bound by default to `:move_panel_divider 0 1` - See http://dystroy.org/broot/panels/#resize-panels * Minor Changes: - when git file infos are shown, and git ignored files aren't hidden, those files are flagged with a 'I' - Remove .bak extension from content search exclusion list - Update nerdfont and vscode icons - `{initial-root}` verb argument - v1.40.0 * Major Feature: preview transformers You can now define preview transformers to be applied before preview. They allow for example previewing PDF or Office files, or beautifying JSON files. Edit the `preview_transformers` array in your conf.hjson file. See https://dystroy.org/broot/conf_file/#preview * fix search on root * fix some verb cycling problems - v1.39.2 * fix UNC paths being displayed on Windows (regression at 1.39.1) - v1.39.1 * fix high-resolution (kitty protocole) image broken in release mode * canonicalize paths when focusing them (mostly useful when following links) * a few minor internal optimizations Patch instructions: To install this openSUSE security update use the suse recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 16.0 zypper in -t patch openSUSE-Leap-16.0-packagehub-544=1 Package List: - openSUSE Leap 16.0: broot-1.59.0-bp160.1.1 References: * https://www.suse.com/security/cve/CVE-2026-72847.html
