Mercurial was updated to fix a command injection via sshpeer._validaterepo() (CVE-2014-9462, bnc#923070):
{ "binaries": [ { "mercurial": "2.8.2-3.1" } ] }