The following Fedora EPEL 7 Security updates need testing:
Age URL
981 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2015-1087 dokuwiki-0-0.24.20140929c.el7
744 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2015-dac7ed832f mcollective-2.8.4-1.el7
326 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2016-04bc9dd81d libbsd-0.8.3-1.el7
223 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2017-d241156dfe mod_cluster-1.3.3-10.el7
221 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2017-7ecb12e378 python-XStatic-jquery-ui-1.12.0.1-1.el7
55 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2017-e27758bd23 libmspack-0.6-0.1.alpha.el7
53 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2017-52b8147c68 openvpn-auth-ldap-2.0.3-15.el7
26 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2017-1e541e27e9 nginx-1.12.2-1.el7
13 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2017-95bf973a7d wordpress-4.8.3-1.el7
10 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2017-020fe6e5ac rubygem-ox-2.4.11-3.el7
7 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2017-30026fdcc1 hostapd-2.6-6.el7
7 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2017-01fce22094 php-PHPMailer-5.2.26-1.el7
3 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2017-5e4edb1320 fedpkg-1.30-4.el7 rpkg-1.51-2.el7
3 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2017-227eb8f562 roundcubemail-1.1.10-1.el7
3 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2017-f412a32589 python-copr-1.84-1.el7
The following builds have been pushed to Fedora EPEL 7 updates-testing
blueberry-1.1.18-1.el7
boinc-client-7.8.4-1.el7
gnome-shell-extension-freon-31-1.el7
libglvnd-1.0.0-1.el7
qmltermwidget-0.1.0-3.20171027git08958f7.el7
rubygem-hiera-vault-0.2.2-2.el7
Details about builds:
================================================================================
blueberry-1.1.18-1.el7 (FEDORA-EPEL-2017-72c2681f7d)
Bluetooth configuration tool
--------------------------------------------------------------------------------
Update Information:
Update to new release ---- * New upstream release
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1478751 - Bluetooth tray icon appears twice when enabling it in settings
https://bugzilla.redhat.com/show_bug.cgi?id=1478751
[ 2 ] Bug #1511725 - blueberry-1.1.18 is available
https://bugzilla.redhat.com/show_bug.cgi?id=1511725
[ 3 ] Bug #1509725 - blueberry-1.1.17 is available
https://bugzilla.redhat.com/show_bug.cgi?id=1509725
--------------------------------------------------------------------------------
================================================================================
boinc-client-7.8.4-1.el7 (FEDORA-EPEL-2017-45b1e5bc58)
The BOINC client
--------------------------------------------------------------------------------
Update Information:
7.8.4 release ---- This is the new upstream release of the BOINC client.
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1397476 - SELinux is preventing boinc_client from 'read' accesses on the file mmap_min_addr.
https://bugzilla.redhat.com/show_bug.cgi?id=1397476
[ 2 ] Bug #1421482 - Remove (7.6.33) BOINC Xorg based idle detection
https://bugzilla.redhat.com/show_bug.cgi?id=1421482
--------------------------------------------------------------------------------
================================================================================
gnome-shell-extension-freon-31-1.el7 (FEDORA-EPEL-2017-a918223eba)
GNOME Shell extension to display system temperature, voltage, and fan speed
--------------------------------------------------------------------------------
Update Information:
Bump to upstream version 31, which includes fixes to the Russian translation,
and adds a Ukranian translation. ---- - Bump to upstream version 30, which
assures support in GNOME 3.26, fixes a bug related to Nvidia drivers, and adds
Spanish translations. - Move setup notes from RPM description to packaged
README-fedora file.
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1504347 - gnome-shell-extension-freon-29 is available
https://bugzilla.redhat.com/show_bug.cgi?id=1504347
--------------------------------------------------------------------------------
================================================================================
libglvnd-1.0.0-1.el7 (FEDORA-EPEL-2017-a72a09c073)
The GL Vendor-Neutral Dispatch library
--------------------------------------------------------------------------------
Update Information:
Update to 1.0.0 release.
--------------------------------------------------------------------------------
================================================================================
qmltermwidget-0.1.0-3.20171027git08958f7.el7 (FEDORA-EPEL-2017-c321ff9f07)
A port of QTermWidget to QML
--------------------------------------------------------------------------------
Update Information:
New package - initial build & update
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1511966 - Review Request: qmltermwidget - a QML port of QTermWidget
https://bugzilla.redhat.com/show_bug.cgi?id=1511966
--------------------------------------------------------------------------------
================================================================================
rubygem-hiera-vault-0.2.2-2.el7 (FEDORA-EPEL-2017-7d93923577)
Module for using vault as a hiera backend
--------------------------------------------------------------------------------
Update Information:
Fixes issue with v5 hiera configuration.
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1512760 - Hiera v5 configuration incompatible with hiera-vault
https://bugzilla.redhat.com/show_bug.cgi?id=1512760
--------------------------------------------------------------------------------
The following Fedora EPEL 7 Security updates need testing:
Age URL
981 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2015-1087 dokuwiki-0-0.24.20140929c.el7
743 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2015-dac7ed832f mcollective-2.8.4-1.el7
325 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2016-04bc9dd81d libbsd-0.8.3-1.el7
223 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2017-d241156dfe mod_cluster-1.3.3-10.el7
220 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2017-7ecb12e378 python-XStatic-jquery-ui-1.12.0.1-1.el7
55 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2017-e27758bd23 libmspack-0.6-0.1.alpha.el7
53 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2017-52b8147c68 openvpn-auth-ldap-2.0.3-15.el7
26 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2017-1e541e27e9 nginx-1.12.2-1.el7
12 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2017-95bf973a7d wordpress-4.8.3-1.el7
9 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2017-020fe6e5ac rubygem-ox-2.4.11-3.el7
7 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2017-30026fdcc1 hostapd-2.6-6.el7
7 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2017-01fce22094 php-PHPMailer-5.2.26-1.el7
2 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2017-5e4edb1320 fedpkg-1.30-4.el7 rpkg-1.51-2.el7
2 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2017-227eb8f562 roundcubemail-1.1.10-1.el7
2 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2017-f412a32589 python-copr-1.84-1.el7
The following builds have been pushed to Fedora EPEL 7 updates-testing
borgbackup-1.1.2-1.el7
golang-github-asaskevich-govalidator-8-1.el7
gsi-openssh-7.4p1-1.el7
nodejs-6.12.0-1.el7
perl-Finance-Quote-1.47-1.el7
perl-Plack-1.0033-1.el7
prelude-lml-rules-4.0.0-1.el7
psblas3-3.5.0-15.el7
python-msrest-0.4.18-1.el7
python-msrestazure-0.4.16-1.el7
python-openidc-client-0.4.0-1.20171113git54dee6e.el7
python-tinydb-3.7.0-1.el7
Details about builds:
================================================================================
borgbackup-1.1.2-1.el7 (FEDORA-EPEL-2017-ce31d16da8)
A deduplicating backup program with compression and authenticated encryption
--------------------------------------------------------------------------------
Update Information:
upstream version 1.1.2 ---- upstream version 1.1.1
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1473973 - Add zsh autocompletion
https://bugzilla.redhat.com/show_bug.cgi?id=1473973
[ 2 ] Bug #1509851 - borgbackup 1.1.2 is available
https://bugzilla.redhat.com/show_bug.cgi?id=1509851
[ 3 ] Bug #1508593 - BorgBackup v1.1.1 is available
https://bugzilla.redhat.com/show_bug.cgi?id=1508593
--------------------------------------------------------------------------------
================================================================================
golang-github-asaskevich-govalidator-8-1.el7 (FEDORA-EPEL-2017-21654fa7bb)
Validators and sanitizers for strings, numerics, slices and structs
--------------------------------------------------------------------------------
Update Information:
Update to latest upstream release.
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1512279 - golang-github-asaskevich-govalidator-8 is available
https://bugzilla.redhat.com/show_bug.cgi?id=1512279
--------------------------------------------------------------------------------
================================================================================
gsi-openssh-7.4p1-1.el7 (FEDORA-EPEL-2017-232408ad8b)
An implementation of the SSH protocol with GSI authentication
--------------------------------------------------------------------------------
Update Information:
Sync with openssh package.
--------------------------------------------------------------------------------
================================================================================
nodejs-6.12.0-1.el7 (FEDORA-EPEL-2017-a4b3ae88b2)
JavaScript runtime
--------------------------------------------------------------------------------
Update Information:
Update ---- # 2017-10-24, Version 6.11.5 'Boron' (LTS), @MylesBorins This is
a security release. All Node.js users should consult the security release
summary at https://nodejs.org/en/blog/vulnerability/oct-2017-dos/ for details on
patched vulnerabilities. ## Notable Changes * zlib: * CVE-2017-14919 - In
zlib v1.2.9, a change was made that causes an error to be raised when a raw
deflate stream is initialized with windowBits set to 8. On some versions this
crashes Node and you cannot recover from it, while on some versions it throws an
exception. Node.js will now gracefully set windowBits to 9 replicating the
legacy behavior to avoid a DOS vector. nodejs-private/node-private#95 ----
Update to Node.js 6.11.4
--------------------------------------------------------------------------------
================================================================================
perl-Finance-Quote-1.47-1.el7 (FEDORA-EPEL-2017-967e14970f)
A Perl module that retrieves stock and mutual fund quotes
--------------------------------------------------------------------------------
Update Information:
Current upstream maintenance release. Various sources fixed, new source
AlphaVantage added.
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1509722 - perl-Finance-Quote-1.40 is available
https://bugzilla.redhat.com/show_bug.cgi?id=1509722
[ 2 ] Bug #1510220 - perl-Finance-Quote-1.42 is available
https://bugzilla.redhat.com/show_bug.cgi?id=1510220
[ 3 ] Bug #1510678 - perl-Finance-Quote-1.44 is available
https://bugzilla.redhat.com/show_bug.cgi?id=1510678
[ 4 ] Bug #1511240 - perl-Finance-Quote-1.45 is available
https://bugzilla.redhat.com/show_bug.cgi?id=1511240
[ 5 ] Bug #1512341 - perl-Finance-Quote-1.47 is available
https://bugzilla.redhat.com/show_bug.cgi?id=1512341
--------------------------------------------------------------------------------
================================================================================
perl-Plack-1.0033-1.el7 (FEDORA-EPEL-2017-dbdb41f602)
Perl Superglue for Web frameworks and Web Servers (PSGI toolkit)
--------------------------------------------------------------------------------
Update Information:
This update upgrades the perl Plack module to 1.0033. There are several
improvements, new features and security fixes which can be found in the module's
changelog : http://cpansearch.perl.org/src/MIYAGAWA/Plack-1.0033/Changes
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1469031 - Please update perl-Plack version
https://bugzilla.redhat.com/show_bug.cgi?id=1469031
--------------------------------------------------------------------------------
================================================================================
prelude-lml-rules-4.0.0-1.el7 (FEDORA-EPEL-2017-83f4de81ad)
Prelude LML community ruleset
--------------------------------------------------------------------------------
Update Information:
Bump to 4.0.0
--------------------------------------------------------------------------------
================================================================================
psblas3-3.5.0-15.el7 (FEDORA-EPEL-2017-478c329655)
Parallel Sparse Basic Linear Algebra Subroutines
--------------------------------------------------------------------------------
Update Information:
- Update to post-release 3.5.0-1 ---- - New package
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1506949 - Review Request: psblas3 - Parallel Sparse Basic Linear Algebra Subroutines
https://bugzilla.redhat.com/show_bug.cgi?id=1506949
--------------------------------------------------------------------------------
================================================================================
python-msrest-0.4.18-1.el7 (FEDORA-EPEL-2017-8de7436e28)
AutoRest swagger generator Python client runtime
--------------------------------------------------------------------------------
Update Information:
#python-msrest 0.4.18 ##Features * Add ApiKeyCredentials class. This can be
used to support OpenAPI ApiKey feature. * Add CognitiveServicesAuthentication
class. Pre-declared ApiKeyCredentials class for Cognitive Services.
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1508202 - python-msrest-v0.4.18 is available
https://bugzilla.redhat.com/show_bug.cgi?id=1508202
--------------------------------------------------------------------------------
================================================================================
python-msrestazure-0.4.16-1.el7 (FEDORA-EPEL-2017-410b0b03eb)
AutoRest swagger generator Python client runtime (Azure-specific module)
--------------------------------------------------------------------------------
Update Information:
# python-msrestazure 0.4.16 ##Bugfixes * Fix AttributeError if input JSON is
not a dict ([#54](https://github.com/Azure/msrestazure-for-python/issues/54))
--------------------------------------------------------------------------------
================================================================================
python-openidc-client-0.4.0-1.20171113git54dee6e.el7 (FEDORA-EPEL-2017-fb0c5e91bc)
Python OpenID Connect client with token caching and management
--------------------------------------------------------------------------------
Update Information:
python-openidc-client-v0.4.0 is available Add Requests AuthBase wrapper Allow
specifying to not get new tokens in auther
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1455728 - python-openidc-client-v0.4.0 is available
https://bugzilla.redhat.com/show_bug.cgi?id=1455728
--------------------------------------------------------------------------------
================================================================================
python-tinydb-3.7.0-1.el7 (FEDORA-EPEL-2017-a226ef6d6e)
TinyDB is a tiny, document oriented database
--------------------------------------------------------------------------------
Update Information:
Update to latest version
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1512243 - python-tinydb-3.7.0 is available
https://bugzilla.redhat.com/show_bug.cgi?id=1512243
--------------------------------------------------------------------------------
Hello there,
I plan to upgrade the armadillo package (armadillo, armadillo-devel) to
its latest version in EPEL6/EPEL7/F27/rawhide, which incurs a soname
bump. There are only three dependent packages:
gdal
mlpack
mmseq
I will be working with a provenpackager (Mukundan) in order to rebuild
the affected downstream packages. We've already made a COPR for
testing:
https://copr.fedorainfracloud.org/coprs/rcurtin/arma-epel6/
This is related to the SuperLU soname bump recently:
https://lists.fedoraproject.org/archives/list/epel-devel@lists.fedoraprojec…
Please let me know if there are any problems. Otherwise we will get
started in the next few days.
Thanks,
Ryan
--
Ryan Curtin | "I just ran out of it, you see."
ryan(a)ratml.org | - Howard Beale
The following Fedora EPEL 7 Security updates need testing:
Age URL
978 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2015-1087 dokuwiki-0-0.24.20140929c.el7
741 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2015-dac7ed832f mcollective-2.8.4-1.el7
323 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2016-04bc9dd81d libbsd-0.8.3-1.el7
220 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2017-d241156dfe mod_cluster-1.3.3-10.el7
217 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2017-7ecb12e378 python-XStatic-jquery-ui-1.12.0.1-1.el7
52 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2017-e27758bd23 libmspack-0.6-0.1.alpha.el7
50 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2017-52b8147c68 openvpn-auth-ldap-2.0.3-15.el7
23 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2017-1e541e27e9 nginx-1.12.2-1.el7
15 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2017-f576d1826a nodejs-6.11.5-1.el7
9 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2017-95bf973a7d wordpress-4.8.3-1.el7
6 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2017-020fe6e5ac rubygem-ox-2.4.11-3.el7
4 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2017-30026fdcc1 hostapd-2.6-6.el7
4 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2017-01fce22094 php-PHPMailer-5.2.26-1.el7
0 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2017-5e4edb1320 fedpkg-1.30-4.el7 rpkg-1.51-2.el7
0 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2017-227eb8f562 roundcubemail-1.1.10-1.el7
0 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2017-f412a32589 python-copr-1.84-1.el7
The following builds have been pushed to Fedora EPEL 7 updates-testing
ProDy-1.9.3-1.el7
atop-2.3.0-4.el7
copr-cli-1.65-1.el7
fedfind-3.8.0-1.el7
fedpkg-1.30-4.el7
flcluster-1.0.3-1.el7
flnet-7.3.2-1.el7
flwkey-1.2.3-2.el7
globus-gridftp-server-12.4-1.el7
globus-gridftp-server-control-6.0-3.el7
globus-gsi-credential-7.14-1.el7
globus-gsi-sysconfig-8.0-1.el7
globus-gssapi-gsi-13.4-1.el7
libmediainfo-17.10-1.el7
linsim-2.0.3-1.el7
mediaconch-17.08-2.el7
mediainfo-17.10-1.el7
perl-Finance-Quote-1.45-1.el7
php-cs-fixer-2.2.10-1.el7
powerman-2.3.24-4.el7
python-copr-1.83-1.el7
python-copr-1.84-1.el7
python-wikitcms-2.2.0-1.el7
relval-2.2.0-1.el7
roundcubemail-1.1.10-1.el7
rpkg-1.51-2.el7
slick-greeter-1.1.0-4.el7
zstd-1.3.2-1.el7
Details about builds:
================================================================================
ProDy-1.9.3-1.el7 (FEDORA-EPEL-2017-cd6e45ef26)
Application for protein structure, dynamics and sequence analysis
--------------------------------------------------------------------------------
Update Information:
- Update to 1.9.3 - Obsolete old patch
--------------------------------------------------------------------------------
================================================================================
atop-2.3.0-4.el7 (FEDORA-EPEL-2017-00345ef554)
An advanced interactive monitor to view the load on system and process level
--------------------------------------------------------------------------------
Update Information:
Change from logrotate to upstream script. ---- 2.3.0
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1509943 - Update to version 2.3.0
https://bugzilla.redhat.com/show_bug.cgi?id=1509943
--------------------------------------------------------------------------------
================================================================================
copr-cli-1.65-1.el7 (FEDORA-EPEL-2017-2db7688f69)
Command line interface for COPR
--------------------------------------------------------------------------------
Update Information:
- allow to set use_bootstrap_container via API ---- - add SCM api - add
deprecation warnings for tito and mockscm methods ---- - fix unittests - run
tests with python3 - pag#130 update requirements - pag#125 copr build copr pkgs
[pkgs ...] builds only the first SRPM - pag#112 [RFE] copr-cli whoami - Bug
1431035 - coprs should check credentials before uploading source rpm -
Spelling fixes
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1431035 - coprs should check credentials before uploading source rpm
https://bugzilla.redhat.com/show_bug.cgi?id=1431035
--------------------------------------------------------------------------------
================================================================================
fedfind-3.8.0-1.el7 (FEDORA-EPEL-2017-c0be6372ac)
Fedora compose and image finder
--------------------------------------------------------------------------------
Update Information:
fedfind 3.6.4 fixes use of the `expected_images` property (and hence
`check_expected()` method) with modular composes. In 3.6.2 and earlier, it
caused a crash. fedfind 3.7.1 improves handling of various new compose types
introduced by release engineering. The new nightly modular composes from master
branch, now versioned `Bikeshed` rather than `Rawhide`, are handled with a new
`BikeshedModularNightly` class. 'updates' and 'updates-testing' composes are
explicitly not supported (`get_release` will raise a `ValueError` with a
specific text for these) as they do not contain images and so fedfind can't do
much with them. Note that the `fedfind.helpers.parse_cid` function is entirely
rewritten in support of this; the new version is much more capable and accurate
and should handle all compose IDs the previous version handled correctly, but
please report any issues you find. fedfind 3.8.0 adds support for the Modular
Server candidate composes which are currently being produced. The updates to
relval and python-wikitcms similarly add support for Modular composes and
events.
--------------------------------------------------------------------------------
================================================================================
fedpkg-1.30-4.el7 (FEDORA-EPEL-2017-5e4edb1320)
Fedora utility for working with dist-git
--------------------------------------------------------------------------------
Update Information:
**Update** - Fixed chain-build - Remove hard dependency of bash-completion from
fedpkg **rpkg** - Ignore TestModulesCli if openidc-client is unavailable (cqi)
- Port mbs-build to rpkg (mprahl) - Add .vscode to .gitignore (mprahl) - Fix
TestPatch.test_rediff in order to run with old version of mock (cqi) - Allow to
specify alternative Copr config file - #184 (cqi) - Tests for patch command
(cqi) - More Tests for mockbuild command (cqi) - More tests for getting spec
file (cqi) - Tests for container-build-setup command (cqi) - Test for container-
build to use custom config (cqi) - Suppress output from git command within setUp
(cqi) - Skip test if rpmfluff is not available (lsedlar) - Allow to override
build URL (cqi) - Test for mock-config command (cqi) - Tests for copr-build
command (cqi) - Fix arch-override for container-build (lucarval) - Remove
unsupported osbs for container-build (lucarval) - cli: add --arches support for
koji_cointainerbuild (mlangsdo) - Strip refs/heads/ from branch only once
(lsedlar) - Don't install bin and config files (cqi) - Fix kojiprofile selection
in cliClient.container_build_koji (cqi) - Avoid branch detection for 'rpkg
sources' (praiskup) - Fix encoding in new command (cqi) - Minor wording
improvement in help (pgier) - Fix indentation (pviktori) - Add --with and
--without options to mockbuild (pviktori) **fedpkg** - Tests for update
command (cqi) - Add support for module commands (mprahl) - Clean rest cert
related code (cqi) - Remove fedora cert (cqi) - Override build URL for Koji
(cqi) - changing anongiturl to use src.fp.o instead of pkgs.fp.o. - #119
(tflink) - Add tests (cqi) - Enable lookaside_namespaced - #130 (cqi) - Detect
dist tag correctly for RHEL and CentOS - #141 (cqi) - Remove deprecated call to
platform.dist (cqi) - Do not prompt hint for SSL cert if fail to log into Koji
(cqi) - Add more container-build options to bash completion (cqi) - Remove osbs
from bash completion - #138 (cqi) - Install executables via entry_points - #134
(cqi) - Fix container build target (lsedlar) - Get correct build target for
rawhide containers (lsedlar) - Update error message to reflect deprecation of
--dist option (pgier)
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1188634 - fedpkg clone -a should use https:// transport
https://bugzilla.redhat.com/show_bug.cgi?id=1188634
[ 2 ] Bug #1509322 - fedpkg >= 1.30-1 depends on bash-completion
https://bugzilla.redhat.com/show_bug.cgi?id=1509322
--------------------------------------------------------------------------------
================================================================================
flcluster-1.0.3-1.el7 (FEDORA-EPEL-2017-5ff6d0e947)
A management tool for accessing dxcluster nodes
--------------------------------------------------------------------------------
Update Information:
Initial package release for Fedora.
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1508492 - None
https://bugzilla.redhat.com/show_bug.cgi?id=1508492
[ 2 ] Bug #1060852 - None
https://bugzilla.redhat.com/show_bug.cgi?id=1060852
[ 3 ] Bug #1508478 - None
https://bugzilla.redhat.com/show_bug.cgi?id=1508478
[ 4 ] Bug #1321081 - None
https://bugzilla.redhat.com/show_bug.cgi?id=1321081
--------------------------------------------------------------------------------
================================================================================
flnet-7.3.2-1.el7 (FEDORA-EPEL-2017-5ff6d0e947)
Amateur Radio Net Control Station
--------------------------------------------------------------------------------
Update Information:
Initial package release for Fedora.
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1508492 - None
https://bugzilla.redhat.com/show_bug.cgi?id=1508492
[ 2 ] Bug #1060852 - None
https://bugzilla.redhat.com/show_bug.cgi?id=1060852
[ 3 ] Bug #1508478 - None
https://bugzilla.redhat.com/show_bug.cgi?id=1508478
[ 4 ] Bug #1321081 - None
https://bugzilla.redhat.com/show_bug.cgi?id=1321081
--------------------------------------------------------------------------------
================================================================================
flwkey-1.2.3-2.el7 (FEDORA-EPEL-2017-5ff6d0e947)
Modem program for the K1EL Winkeyer series
--------------------------------------------------------------------------------
Update Information:
Initial package release for Fedora.
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1508492 - None
https://bugzilla.redhat.com/show_bug.cgi?id=1508492
[ 2 ] Bug #1060852 - None
https://bugzilla.redhat.com/show_bug.cgi?id=1060852
[ 3 ] Bug #1508478 - None
https://bugzilla.redhat.com/show_bug.cgi?id=1508478
[ 4 ] Bug #1321081 - None
https://bugzilla.redhat.com/show_bug.cgi?id=1321081
--------------------------------------------------------------------------------
================================================================================
globus-gridftp-server-12.4-1.el7 (FEDORA-EPEL-2017-bd0f704639)
Globus Toolkit - Globus GridFTP Server
--------------------------------------------------------------------------------
Update Information:
globus-gridftp-server * Ignore backup & packaging files in config.d globus-
gridftp-server-control * Terminate the connection if server fails to write the
220 banner globus-gsi-credential * Remove prototype for non-existing function
(7.12) * Fix crash when handle->cert not set in call to globus_gsi_cred_get_cert
(7.13) * Remove compatibility shims for old versions of OpenSSL (7.13) * Fix
issue with voms proxy and openssl 1.1 (7.14) globus-gsi-sysconfig * Add cert
and key checks based on different uid globus-gssapi-gsi * Allow configuration
of non-root user to own credentials for root services (13.3) * Improve vhost
support (13.4)
--------------------------------------------------------------------------------
================================================================================
globus-gridftp-server-control-6.0-3.el7 (FEDORA-EPEL-2017-bd0f704639)
Globus Toolkit - Globus GridFTP Server Library
--------------------------------------------------------------------------------
Update Information:
globus-gridftp-server * Ignore backup & packaging files in config.d globus-
gridftp-server-control * Terminate the connection if server fails to write the
220 banner globus-gsi-credential * Remove prototype for non-existing function
(7.12) * Fix crash when handle->cert not set in call to globus_gsi_cred_get_cert
(7.13) * Remove compatibility shims for old versions of OpenSSL (7.13) * Fix
issue with voms proxy and openssl 1.1 (7.14) globus-gsi-sysconfig * Add cert
and key checks based on different uid globus-gssapi-gsi * Allow configuration
of non-root user to own credentials for root services (13.3) * Improve vhost
support (13.4)
--------------------------------------------------------------------------------
================================================================================
globus-gsi-credential-7.14-1.el7 (FEDORA-EPEL-2017-bd0f704639)
Globus Toolkit - Globus GSI Credential Library
--------------------------------------------------------------------------------
Update Information:
globus-gridftp-server * Ignore backup & packaging files in config.d globus-
gridftp-server-control * Terminate the connection if server fails to write the
220 banner globus-gsi-credential * Remove prototype for non-existing function
(7.12) * Fix crash when handle->cert not set in call to globus_gsi_cred_get_cert
(7.13) * Remove compatibility shims for old versions of OpenSSL (7.13) * Fix
issue with voms proxy and openssl 1.1 (7.14) globus-gsi-sysconfig * Add cert
and key checks based on different uid globus-gssapi-gsi * Allow configuration
of non-root user to own credentials for root services (13.3) * Improve vhost
support (13.4)
--------------------------------------------------------------------------------
================================================================================
globus-gsi-sysconfig-8.0-1.el7 (FEDORA-EPEL-2017-bd0f704639)
Globus Toolkit - Globus GSI System Config Library
--------------------------------------------------------------------------------
Update Information:
globus-gridftp-server * Ignore backup & packaging files in config.d globus-
gridftp-server-control * Terminate the connection if server fails to write the
220 banner globus-gsi-credential * Remove prototype for non-existing function
(7.12) * Fix crash when handle->cert not set in call to globus_gsi_cred_get_cert
(7.13) * Remove compatibility shims for old versions of OpenSSL (7.13) * Fix
issue with voms proxy and openssl 1.1 (7.14) globus-gsi-sysconfig * Add cert
and key checks based on different uid globus-gssapi-gsi * Allow configuration
of non-root user to own credentials for root services (13.3) * Improve vhost
support (13.4)
--------------------------------------------------------------------------------
================================================================================
globus-gssapi-gsi-13.4-1.el7 (FEDORA-EPEL-2017-bd0f704639)
Globus Toolkit - GSSAPI library
--------------------------------------------------------------------------------
Update Information:
globus-gridftp-server * Ignore backup & packaging files in config.d globus-
gridftp-server-control * Terminate the connection if server fails to write the
220 banner globus-gsi-credential * Remove prototype for non-existing function
(7.12) * Fix crash when handle->cert not set in call to globus_gsi_cred_get_cert
(7.13) * Remove compatibility shims for old versions of OpenSSL (7.13) * Fix
issue with voms proxy and openssl 1.1 (7.14) globus-gsi-sysconfig * Add cert
and key checks based on different uid globus-gssapi-gsi * Allow configuration
of non-root user to own credentials for root services (13.3) * Improve vhost
support (13.4)
--------------------------------------------------------------------------------
================================================================================
libmediainfo-17.10-1.el7 (FEDORA-EPEL-2017-6d6dfe25c8)
Library for supplies technical and tag information about a video or audio file
--------------------------------------------------------------------------------
Update Information:
Update to 17.10.
--------------------------------------------------------------------------------
================================================================================
linsim-2.0.3-1.el7 (FEDORA-EPEL-2017-5ff6d0e947)
Tool for Amateur Radio Digital Mode evaluation
--------------------------------------------------------------------------------
Update Information:
Initial package release for Fedora.
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1508492 - None
https://bugzilla.redhat.com/show_bug.cgi?id=1508492
[ 2 ] Bug #1060852 - None
https://bugzilla.redhat.com/show_bug.cgi?id=1060852
[ 3 ] Bug #1508478 - None
https://bugzilla.redhat.com/show_bug.cgi?id=1508478
[ 4 ] Bug #1321081 - None
https://bugzilla.redhat.com/show_bug.cgi?id=1321081
--------------------------------------------------------------------------------
================================================================================
mediaconch-17.08-2.el7 (FEDORA-EPEL-2017-7415cb15d8)
Most relevant technical and tag data for video and audio files (CLI)
--------------------------------------------------------------------------------
Update Information:
Rebuild for new libmediainfo.
--------------------------------------------------------------------------------
================================================================================
mediainfo-17.10-1.el7 (FEDORA-EPEL-2017-6d6dfe25c8)
Supplies technical and tag information about a video or audio file (CLI)
--------------------------------------------------------------------------------
Update Information:
Update to 17.10.
--------------------------------------------------------------------------------
================================================================================
perl-Finance-Quote-1.45-1.el7 (FEDORA-EPEL-2017-967e14970f)
A Perl module that retrieves stock and mutual fund quotes
--------------------------------------------------------------------------------
Update Information:
Current upstream maintenance release. Various sources fixed, new source
AlphaVantage added.
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1509722 - perl-Finance-Quote-1.40 is available
https://bugzilla.redhat.com/show_bug.cgi?id=1509722
[ 2 ] Bug #1510220 - perl-Finance-Quote-1.42 is available
https://bugzilla.redhat.com/show_bug.cgi?id=1510220
[ 3 ] Bug #1510678 - perl-Finance-Quote-1.44 is available
https://bugzilla.redhat.com/show_bug.cgi?id=1510678
[ 4 ] Bug #1511240 - perl-Finance-Quote-1.45 is available
https://bugzilla.redhat.com/show_bug.cgi?id=1511240
--------------------------------------------------------------------------------
================================================================================
php-cs-fixer-2.2.10-1.el7 (FEDORA-EPEL-2017-59f8857c74)
A tool to automatically fix PHP code style
--------------------------------------------------------------------------------
Update Information:
**Changelog for v2.2.10** * bug #3199 TokensAnalyzer - getClassyElements
(SpacePossum) * bug #3208 BracesFixer - Fix for instantiation in control
structures (julienfalque, SpacePossum) * bug #3215 BinaryOperatorSpacesFixer -
Fix spaces around multiple exception catching (|) (ntzm) * bug #3216
AbstractLinesBeforeNamespaceFixer - add min. and max. option, not only single
target count (SpacePossum) * bug #3217 TokenizerLinter - fix lack of linting
when code is cached (SpacePossum, keradus) * minor #3200 Skip slow test when
Xdebug is loaded (julienfalque) * minor #3219 Normalise references to GitHub in
docs (ntzm) * minor #3226 Remove unused imports (ntzm) * minor #3231 Fix typos
(ntzm) * minor #3234 Simplify Cache\Signature::equals (ntzm) * minor #3237
UnconfigurableFixer - use only LF (keradus) * minor #3238 AbstractFixerTest -
fix @cover annotation (keradus) ---- **Changelog for v2.2.9** * bug #3062
BraceClassInstantiationTransformer - Fix instantiation inside method call braces
case (julienfalque, keradus) * bug #3083 SingleBlankLineBeforeNamespaceFixer -
Fix handling namespace right after opening tag (mlocati) * bug #3109
SwitchCaseSemicolonToColonFixer - Fix bug with nested constructs (SpacePossum) *
bug #3123 Cache - File permissions (SpacePossum) * bug #3172
IndentationTypeFixer - do not touch whitespace that is not indentation
(SpacePossum) * bug #3176 NoMultilineWhitespaceBeforeSemicolonsFixer -
SpaceAfterSemicolonFixer - priority fix (SpacePossum) * bug #3193
TokensAnalyzer::getClassyElements - sort result before returning (SpacePossum) *
bug #3196 SelfUpdateCommand - fix exit status when can't determine newest
version (julienfalque) * minor #3107 ConfigurationResolver - improve error
message when rule is not found (SpacePossum) * minor #3113 Add WordMatcher
(keradus) * minor #3133 Unify Reporter tests (keradus) * minor #3134 Allow
Symfony 4 (keradus, garak) * minor #3136 PHPUnit - call hooks from parent class
as well (keradus) * minor #3145 misc - Typo (localheinz) * minor #3150 Fix
CircleCI (julienfalque) * minor #3151 Update gitattributes to ignore next file
(keradus) * minor #3156 Update php-coveralls (keradus) * minor #3166 README -
add link to new gitter channel. (SpacePossum) * minor #3174 Update UPGRADE.md
(vitek-rostislav) * minor #3180 Fix usage of static variables (kubawerlos) *
minor #3184 Code grooming - sort content of arrays (keradus) * minor #3191
Travis - add nightly build to allow_failures due to Travis issues (keradus) *
minor #3197 DX groom CS (keradus)
--------------------------------------------------------------------------------
================================================================================
powerman-2.3.24-4.el7 (FEDORA-EPEL-2017-1503cf8814)
Centralized power control for clusters
--------------------------------------------------------------------------------
Update Information:
Fix systemd support
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1489093 - powerman in EPEL7 should have systemd support
https://bugzilla.redhat.com/show_bug.cgi?id=1489093
--------------------------------------------------------------------------------
================================================================================
python-copr-1.83-1.el7 (FEDORA-EPEL-2017-2db7688f69)
Python interface for Copr
--------------------------------------------------------------------------------
Update Information:
- allow to set use_bootstrap_container via API ---- - add SCM api - add
deprecation warnings for tito and mockscm methods ---- - fix unittests - run
tests with python3 - pag#130 update requirements - pag#125 copr build copr pkgs
[pkgs ...] builds only the first SRPM - pag#112 [RFE] copr-cli whoami - Bug
1431035 - coprs should check credentials before uploading source rpm -
Spelling fixes
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1431035 - coprs should check credentials before uploading source rpm
https://bugzilla.redhat.com/show_bug.cgi?id=1431035
--------------------------------------------------------------------------------
================================================================================
python-copr-1.84-1.el7 (FEDORA-EPEL-2017-f412a32589)
Python interface for Copr
--------------------------------------------------------------------------------
Update Information:
Change default COPR URL route from http://copr.fedoraproject.org to
https://copr.fedorainfracloud.org
--------------------------------------------------------------------------------
================================================================================
python-wikitcms-2.2.0-1.el7 (FEDORA-EPEL-2017-c0be6372ac)
Fedora QA wiki test management Python library
--------------------------------------------------------------------------------
Update Information:
fedfind 3.6.4 fixes use of the `expected_images` property (and hence
`check_expected()` method) with modular composes. In 3.6.2 and earlier, it
caused a crash. fedfind 3.7.1 improves handling of various new compose types
introduced by release engineering. The new nightly modular composes from master
branch, now versioned `Bikeshed` rather than `Rawhide`, are handled with a new
`BikeshedModularNightly` class. 'updates' and 'updates-testing' composes are
explicitly not supported (`get_release` will raise a `ValueError` with a
specific text for these) as they do not contain images and so fedfind can't do
much with them. Note that the `fedfind.helpers.parse_cid` function is entirely
rewritten in support of this; the new version is much more capable and accurate
and should handle all compose IDs the previous version handled correctly, but
please report any issues you find. fedfind 3.8.0 adds support for the Modular
Server candidate composes which are currently being produced. The updates to
relval and python-wikitcms similarly add support for Modular composes and
events.
--------------------------------------------------------------------------------
================================================================================
relval-2.2.0-1.el7 (FEDORA-EPEL-2017-c0be6372ac)
Tool for interacting with Fedora QA wiki pages
--------------------------------------------------------------------------------
Update Information:
fedfind 3.6.4 fixes use of the `expected_images` property (and hence
`check_expected()` method) with modular composes. In 3.6.2 and earlier, it
caused a crash. fedfind 3.7.1 improves handling of various new compose types
introduced by release engineering. The new nightly modular composes from master
branch, now versioned `Bikeshed` rather than `Rawhide`, are handled with a new
`BikeshedModularNightly` class. 'updates' and 'updates-testing' composes are
explicitly not supported (`get_release` will raise a `ValueError` with a
specific text for these) as they do not contain images and so fedfind can't do
much with them. Note that the `fedfind.helpers.parse_cid` function is entirely
rewritten in support of this; the new version is much more capable and accurate
and should handle all compose IDs the previous version handled correctly, but
please report any issues you find. fedfind 3.8.0 adds support for the Modular
Server candidate composes which are currently being produced. The updates to
relval and python-wikitcms similarly add support for Modular composes and
events.
--------------------------------------------------------------------------------
================================================================================
roundcubemail-1.1.10-1.el7 (FEDORA-EPEL-2017-227eb8f562)
Round Cube Webmail is a browser-based multilingual IMAP client
--------------------------------------------------------------------------------
Update Information:
Upstream announcement for **Version 1.1.10** This is a security update to the
stable version 1.1. It fixes a recently discovered file disclosure vulnerability
caused by insufficient input validation in conjunction with file-based
attachment plugins, which are used by default. More details will be published
under CVE-2017-16651. We strongly recommend to update all productive
installations of Roundcube 1.1.x. Please do backup your data before updating!
**Changelog** - Fix file disclosure vulnerability caused by insufficient input
validation **CVE-2017-16651** (#6026)
--------------------------------------------------------------------------------
================================================================================
rpkg-1.51-2.el7 (FEDORA-EPEL-2017-5e4edb1320)
Python library for interacting with rpm+git
--------------------------------------------------------------------------------
Update Information:
**Update** - Fixed chain-build - Remove hard dependency of bash-completion from
fedpkg **rpkg** - Ignore TestModulesCli if openidc-client is unavailable (cqi)
- Port mbs-build to rpkg (mprahl) - Add .vscode to .gitignore (mprahl) - Fix
TestPatch.test_rediff in order to run with old version of mock (cqi) - Allow to
specify alternative Copr config file - #184 (cqi) - Tests for patch command
(cqi) - More Tests for mockbuild command (cqi) - More tests for getting spec
file (cqi) - Tests for container-build-setup command (cqi) - Test for container-
build to use custom config (cqi) - Suppress output from git command within setUp
(cqi) - Skip test if rpmfluff is not available (lsedlar) - Allow to override
build URL (cqi) - Test for mock-config command (cqi) - Tests for copr-build
command (cqi) - Fix arch-override for container-build (lucarval) - Remove
unsupported osbs for container-build (lucarval) - cli: add --arches support for
koji_cointainerbuild (mlangsdo) - Strip refs/heads/ from branch only once
(lsedlar) - Don't install bin and config files (cqi) - Fix kojiprofile selection
in cliClient.container_build_koji (cqi) - Avoid branch detection for 'rpkg
sources' (praiskup) - Fix encoding in new command (cqi) - Minor wording
improvement in help (pgier) - Fix indentation (pviktori) - Add --with and
--without options to mockbuild (pviktori) **fedpkg** - Tests for update
command (cqi) - Add support for module commands (mprahl) - Clean rest cert
related code (cqi) - Remove fedora cert (cqi) - Override build URL for Koji
(cqi) - changing anongiturl to use src.fp.o instead of pkgs.fp.o. - #119
(tflink) - Add tests (cqi) - Enable lookaside_namespaced - #130 (cqi) - Detect
dist tag correctly for RHEL and CentOS - #141 (cqi) - Remove deprecated call to
platform.dist (cqi) - Do not prompt hint for SSL cert if fail to log into Koji
(cqi) - Add more container-build options to bash completion (cqi) - Remove osbs
from bash completion - #138 (cqi) - Install executables via entry_points - #134
(cqi) - Fix container build target (lsedlar) - Get correct build target for
rawhide containers (lsedlar) - Update error message to reflect deprecation of
--dist option (pgier)
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1188634 - fedpkg clone -a should use https:// transport
https://bugzilla.redhat.com/show_bug.cgi?id=1188634
[ 2 ] Bug #1509322 - fedpkg >= 1.30-1 depends on bash-completion
https://bugzilla.redhat.com/show_bug.cgi?id=1509322
--------------------------------------------------------------------------------
================================================================================
slick-greeter-1.1.0-4.el7 (FEDORA-EPEL-2017-f1f1998578)
A slick-looking LightDM greeter
--------------------------------------------------------------------------------
Update Information:
- Show system-logo in lower left corner by default - Add patch from upstream to
use gsettings default if there is no different preset in the config file
--------------------------------------------------------------------------------
================================================================================
zstd-1.3.2-1.el7 (FEDORA-EPEL-2017-3bb6d9294a)
Zstd compression library
--------------------------------------------------------------------------------
Update Information:
Latest upstream
--------------------------------------------------------------------------------
The following Fedora EPEL 6 Security updates need testing:
Age URL
856 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2015-7031 python-virtualenv-12.0.7-1.el6
850 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2015-7168 rubygem-crack-0.3.2-2.el6
740 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2015-e2b4b5b2fb mcollective-2.8.4-1.el6
712 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2015-35e240edd9 thttpd-2.25b-24.el6
323 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2016-e3e50897ac libbsd-0.8.3-2.el6
52 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2017-4c76ddcc92 libmspack-0.6-0.1.alpha.el6
9 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2017-29f7b67071 wordpress-4.8.3-1.el6
8 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2017-16d441d000 pcre2-10.21-21.el6
4 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2017-ed87c07972 hostapd-2.6-6.el6
4 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2017-2bd5c2db5b php-PHPMailer-5.2.26-1.el6
0 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2017-68e2defc4c fedpkg-1.30-4.el6 rpkg-1.51-2.el6
0 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2017-b490886f67 roundcubemail-1.0.12-1.el6
0 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2017-b791c39304 python-copr-1.84-1.el6
The following builds have been pushed to Fedora EPEL 6 updates-testing
ProDy-1.9.3-1.el6
copr-cli-1.65-1.el6
fedpkg-1.30-4.el6
globus-gridftp-server-12.4-1.el6
globus-gridftp-server-control-6.0-3.el6
globus-gsi-credential-7.14-1.el6
globus-gsi-sysconfig-8.0-1.el6
globus-gssapi-gsi-13.4-1.el6
libmediainfo-17.10-1.el6
mediainfo-17.10-1.el6
perl-Finance-Quote-1.45-1.el6
python-copr-1.83-1.el6
python-copr-1.84-1.el6
roundcubemail-1.0.12-1.el6
rpkg-1.51-2.el6
zstd-1.3.2-1.el6
Details about builds:
================================================================================
ProDy-1.9.3-1.el6 (FEDORA-EPEL-2017-0498e9b356)
Application for protein structure, dynamics and sequence analysis
--------------------------------------------------------------------------------
Update Information:
- Update to 1.9.3 - Obsolete old patch
--------------------------------------------------------------------------------
================================================================================
copr-cli-1.65-1.el6 (FEDORA-EPEL-2017-93916bf5e9)
Command line interface for COPR
--------------------------------------------------------------------------------
Update Information:
- allow to set use_bootstrap_container via API
--------------------------------------------------------------------------------
================================================================================
fedpkg-1.30-4.el6 (FEDORA-EPEL-2017-68e2defc4c)
Fedora utility for working with dist-git
--------------------------------------------------------------------------------
Update Information:
**Update** - Fixed chain-build - Remove hard dependency of bash-completion from
fedpkg **rpkg** - Ignore TestModulesCli if openidc-client is unavailable (cqi)
- Port mbs-build to rpkg (mprahl) - Add .vscode to .gitignore (mprahl) - Fix
TestPatch.test_rediff in order to run with old version of mock (cqi) - Allow to
specify alternative Copr config file - #184 (cqi) - Tests for patch command
(cqi) - More Tests for mockbuild command (cqi) - More tests for getting spec
file (cqi) - Tests for container-build-setup command (cqi) - Test for container-
build to use custom config (cqi) - Suppress output from git command within setUp
(cqi) - Skip test if rpmfluff is not available (lsedlar) - Allow to override
build URL (cqi) - Test for mock-config command (cqi) - Tests for copr-build
command (cqi) - Fix arch-override for container-build (lucarval) - Remove
unsupported osbs for container-build (lucarval) - cli: add --arches support for
koji_cointainerbuild (mlangsdo) - Strip refs/heads/ from branch only once
(lsedlar) - Don't install bin and config files (cqi) - Fix kojiprofile selection
in cliClient.container_build_koji (cqi) - Avoid branch detection for 'rpkg
sources' (praiskup) - Fix encoding in new command (cqi) - Minor wording
improvement in help (pgier) - Fix indentation (pviktori) - Add --with and
--without options to mockbuild (pviktori) **fedpkg** - Tests for update
command (cqi) - Add support for module commands (mprahl) - Clean rest cert
related code (cqi) - Remove fedora cert (cqi) - Override build URL for Koji
(cqi) - changing anongiturl to use src.fp.o instead of pkgs.fp.o. - #119
(tflink) - Add tests (cqi) - Enable lookaside_namespaced - #130 (cqi) - Detect
dist tag correctly for RHEL and CentOS - #141 (cqi) - Remove deprecated call to
platform.dist (cqi) - Do not prompt hint for SSL cert if fail to log into Koji
(cqi) - Add more container-build options to bash completion (cqi) - Remove osbs
from bash completion - #138 (cqi) - Install executables via entry_points - #134
(cqi) - Fix container build target (lsedlar) - Get correct build target for
rawhide containers (lsedlar) - Update error message to reflect deprecation of
--dist option (pgier)
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1188634 - fedpkg clone -a should use https:// transport
https://bugzilla.redhat.com/show_bug.cgi?id=1188634
[ 2 ] Bug #1509322 - fedpkg >= 1.30-1 depends on bash-completion
https://bugzilla.redhat.com/show_bug.cgi?id=1509322
--------------------------------------------------------------------------------
================================================================================
globus-gridftp-server-12.4-1.el6 (FEDORA-EPEL-2017-5536233b7d)
Globus Toolkit - Globus GridFTP Server
--------------------------------------------------------------------------------
Update Information:
globus-gridftp-server * Ignore backup & packaging files in config.d globus-
gridftp-server-control * Terminate the connection if server fails to write the
220 banner globus-gsi-credential * Remove prototype for non-existing function
(7.12) * Fix crash when handle->cert not set in call to globus_gsi_cred_get_cert
(7.13) * Remove compatibility shims for old versions of OpenSSL (7.13) * Fix
issue with voms proxy and openssl 1.1 (7.14) globus-gsi-sysconfig * Add cert
and key checks based on different uid globus-gssapi-gsi * Allow configuration
of non-root user to own credentials for root services (13.3) * Improve vhost
support (13.4)
--------------------------------------------------------------------------------
================================================================================
globus-gridftp-server-control-6.0-3.el6 (FEDORA-EPEL-2017-5536233b7d)
Globus Toolkit - Globus GridFTP Server Library
--------------------------------------------------------------------------------
Update Information:
globus-gridftp-server * Ignore backup & packaging files in config.d globus-
gridftp-server-control * Terminate the connection if server fails to write the
220 banner globus-gsi-credential * Remove prototype for non-existing function
(7.12) * Fix crash when handle->cert not set in call to globus_gsi_cred_get_cert
(7.13) * Remove compatibility shims for old versions of OpenSSL (7.13) * Fix
issue with voms proxy and openssl 1.1 (7.14) globus-gsi-sysconfig * Add cert
and key checks based on different uid globus-gssapi-gsi * Allow configuration
of non-root user to own credentials for root services (13.3) * Improve vhost
support (13.4)
--------------------------------------------------------------------------------
================================================================================
globus-gsi-credential-7.14-1.el6 (FEDORA-EPEL-2017-5536233b7d)
Globus Toolkit - Globus GSI Credential Library
--------------------------------------------------------------------------------
Update Information:
globus-gridftp-server * Ignore backup & packaging files in config.d globus-
gridftp-server-control * Terminate the connection if server fails to write the
220 banner globus-gsi-credential * Remove prototype for non-existing function
(7.12) * Fix crash when handle->cert not set in call to globus_gsi_cred_get_cert
(7.13) * Remove compatibility shims for old versions of OpenSSL (7.13) * Fix
issue with voms proxy and openssl 1.1 (7.14) globus-gsi-sysconfig * Add cert
and key checks based on different uid globus-gssapi-gsi * Allow configuration
of non-root user to own credentials for root services (13.3) * Improve vhost
support (13.4)
--------------------------------------------------------------------------------
================================================================================
globus-gsi-sysconfig-8.0-1.el6 (FEDORA-EPEL-2017-5536233b7d)
Globus Toolkit - Globus GSI System Config Library
--------------------------------------------------------------------------------
Update Information:
globus-gridftp-server * Ignore backup & packaging files in config.d globus-
gridftp-server-control * Terminate the connection if server fails to write the
220 banner globus-gsi-credential * Remove prototype for non-existing function
(7.12) * Fix crash when handle->cert not set in call to globus_gsi_cred_get_cert
(7.13) * Remove compatibility shims for old versions of OpenSSL (7.13) * Fix
issue with voms proxy and openssl 1.1 (7.14) globus-gsi-sysconfig * Add cert
and key checks based on different uid globus-gssapi-gsi * Allow configuration
of non-root user to own credentials for root services (13.3) * Improve vhost
support (13.4)
--------------------------------------------------------------------------------
================================================================================
globus-gssapi-gsi-13.4-1.el6 (FEDORA-EPEL-2017-5536233b7d)
Globus Toolkit - GSSAPI library
--------------------------------------------------------------------------------
Update Information:
globus-gridftp-server * Ignore backup & packaging files in config.d globus-
gridftp-server-control * Terminate the connection if server fails to write the
220 banner globus-gsi-credential * Remove prototype for non-existing function
(7.12) * Fix crash when handle->cert not set in call to globus_gsi_cred_get_cert
(7.13) * Remove compatibility shims for old versions of OpenSSL (7.13) * Fix
issue with voms proxy and openssl 1.1 (7.14) globus-gsi-sysconfig * Add cert
and key checks based on different uid globus-gssapi-gsi * Allow configuration
of non-root user to own credentials for root services (13.3) * Improve vhost
support (13.4)
--------------------------------------------------------------------------------
================================================================================
libmediainfo-17.10-1.el6 (FEDORA-EPEL-2017-8e4ce3215d)
Library for supplies technical and tag information about a video or audio file
--------------------------------------------------------------------------------
Update Information:
Update to 17.10.
--------------------------------------------------------------------------------
================================================================================
mediainfo-17.10-1.el6 (FEDORA-EPEL-2017-8e4ce3215d)
Supplies technical and tag information about a video or audio file (CLI)
--------------------------------------------------------------------------------
Update Information:
Update to 17.10.
--------------------------------------------------------------------------------
================================================================================
perl-Finance-Quote-1.45-1.el6 (FEDORA-EPEL-2017-84459b620f)
A Perl module that retrieves stock and mutual fund quotes
--------------------------------------------------------------------------------
Update Information:
Current upstream maintenance release. Various sources fixed, new source
AlphaVantage added.
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1509722 - perl-Finance-Quote-1.40 is available
https://bugzilla.redhat.com/show_bug.cgi?id=1509722
[ 2 ] Bug #1510220 - perl-Finance-Quote-1.42 is available
https://bugzilla.redhat.com/show_bug.cgi?id=1510220
[ 3 ] Bug #1510678 - perl-Finance-Quote-1.44 is available
https://bugzilla.redhat.com/show_bug.cgi?id=1510678
[ 4 ] Bug #1511240 - perl-Finance-Quote-1.45 is available
https://bugzilla.redhat.com/show_bug.cgi?id=1511240
--------------------------------------------------------------------------------
================================================================================
python-copr-1.83-1.el6 (FEDORA-EPEL-2017-93916bf5e9)
Python interface for Copr
--------------------------------------------------------------------------------
Update Information:
- allow to set use_bootstrap_container via API
--------------------------------------------------------------------------------
================================================================================
python-copr-1.84-1.el6 (FEDORA-EPEL-2017-b791c39304)
Python interface for Copr
--------------------------------------------------------------------------------
Update Information:
Change default COPR URL route from http://copr.fedoraproject.org to
https://copr.fedorainfracloud.org
--------------------------------------------------------------------------------
================================================================================
roundcubemail-1.0.12-1.el6 (FEDORA-EPEL-2017-b490886f67)
Round Cube Webmail is a browser-based multilingual IMAP client
--------------------------------------------------------------------------------
Update Information:
Upstream announcement for **Version 1.0.12** This is a security update to the
LTS version 1.0. It closes a potential file disclosure vulnerability discovered
in the file-based attachment plugins. While there's currently no exploit path
for Roundcube 1.0.x the fix was nevertheless back-ported to protect from yet
unknown zero-day exploits. It's considered stable and we recommend to update
all productive installations of Roundcube 1.0.x with this version if for some
reason you're not able to upgrade to the latest stable version. Please do backup
your data before updating! **Changelog** - Fix file disclosure vulnerability
caused by insufficient input validation **CVE-2017-16651** (#6026)
--------------------------------------------------------------------------------
================================================================================
rpkg-1.51-2.el6 (FEDORA-EPEL-2017-68e2defc4c)
Python library for interacting with rpm+git
--------------------------------------------------------------------------------
Update Information:
**Update** - Fixed chain-build - Remove hard dependency of bash-completion from
fedpkg **rpkg** - Ignore TestModulesCli if openidc-client is unavailable (cqi)
- Port mbs-build to rpkg (mprahl) - Add .vscode to .gitignore (mprahl) - Fix
TestPatch.test_rediff in order to run with old version of mock (cqi) - Allow to
specify alternative Copr config file - #184 (cqi) - Tests for patch command
(cqi) - More Tests for mockbuild command (cqi) - More tests for getting spec
file (cqi) - Tests for container-build-setup command (cqi) - Test for container-
build to use custom config (cqi) - Suppress output from git command within setUp
(cqi) - Skip test if rpmfluff is not available (lsedlar) - Allow to override
build URL (cqi) - Test for mock-config command (cqi) - Tests for copr-build
command (cqi) - Fix arch-override for container-build (lucarval) - Remove
unsupported osbs for container-build (lucarval) - cli: add --arches support for
koji_cointainerbuild (mlangsdo) - Strip refs/heads/ from branch only once
(lsedlar) - Don't install bin and config files (cqi) - Fix kojiprofile selection
in cliClient.container_build_koji (cqi) - Avoid branch detection for 'rpkg
sources' (praiskup) - Fix encoding in new command (cqi) - Minor wording
improvement in help (pgier) - Fix indentation (pviktori) - Add --with and
--without options to mockbuild (pviktori) **fedpkg** - Tests for update
command (cqi) - Add support for module commands (mprahl) - Clean rest cert
related code (cqi) - Remove fedora cert (cqi) - Override build URL for Koji
(cqi) - changing anongiturl to use src.fp.o instead of pkgs.fp.o. - #119
(tflink) - Add tests (cqi) - Enable lookaside_namespaced - #130 (cqi) - Detect
dist tag correctly for RHEL and CentOS - #141 (cqi) - Remove deprecated call to
platform.dist (cqi) - Do not prompt hint for SSL cert if fail to log into Koji
(cqi) - Add more container-build options to bash completion (cqi) - Remove osbs
from bash completion - #138 (cqi) - Install executables via entry_points - #134
(cqi) - Fix container build target (lsedlar) - Get correct build target for
rawhide containers (lsedlar) - Update error message to reflect deprecation of
--dist option (pgier)
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1188634 - fedpkg clone -a should use https:// transport
https://bugzilla.redhat.com/show_bug.cgi?id=1188634
[ 2 ] Bug #1509322 - fedpkg >= 1.30-1 depends on bash-completion
https://bugzilla.redhat.com/show_bug.cgi?id=1509322
--------------------------------------------------------------------------------
================================================================================
zstd-1.3.2-1.el6 (FEDORA-EPEL-2017-92595fad02)
Zstd compression library
--------------------------------------------------------------------------------
Update Information:
Latest upstream
--------------------------------------------------------------------------------
The following Fedora EPEL 7 Security updates need testing:
Age URL
976 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2015-1087 dokuwiki-0-0.24.20140929c.el7
738 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2015-dac7ed832f mcollective-2.8.4-1.el7
320 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2016-04bc9dd81d libbsd-0.8.3-1.el7
218 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2017-d241156dfe mod_cluster-1.3.3-10.el7
215 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2017-7ecb12e378 python-XStatic-jquery-ui-1.12.0.1-1.el7
50 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2017-e27758bd23 libmspack-0.6-0.1.alpha.el7
47 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2017-52b8147c68 openvpn-auth-ldap-2.0.3-15.el7
21 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2017-1e541e27e9 nginx-1.12.2-1.el7
16 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2017-21fb9891af modulemd-1.3.2-1.el7
12 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2017-f576d1826a nodejs-6.11.5-1.el7
7 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2017-95bf973a7d wordpress-4.8.3-1.el7
5 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2017-5e4edb1320 fedpkg-1.30-3.el7 rpkg-1.51-1.el7
4 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2017-020fe6e5ac rubygem-ox-2.4.11-3.el7
2 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2017-30026fdcc1 hostapd-2.6-6.el7
2 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2017-01fce22094 php-PHPMailer-5.2.26-1.el7
The following builds have been pushed to Fedora EPEL 7 updates-testing
ansible-inventory-grapher-2.4.2-1.el7
d-din-fonts-1.0-1.el7
darktable-2.0.7-3.el7
fedfind-3.8.0-1.el7
git-publish-1.4.2-2.el7
knot-2.6.1-1.el7
knot-resolver-1.5.0-1.el7
perl-Finance-Quote-1.44-1.el7
purple-discord-0-13.20171010git2ca7b3c.el7
purple-hangouts-0-52.20171023hg4ce9b33.el7
purple-skypeweb-1.4-6.20171024gitc442007.el7
recap-1.2.0-2.el7
sendemail-1.56-1.el7
stomppy-3.1.6-3.el7
vrms-rpm-1.3-1.el7
Details about builds:
================================================================================
ansible-inventory-grapher-2.4.2-1.el7 (FEDORA-EPEL-2017-37149ebcb3)
Creates graphs representing ansible inventory
--------------------------------------------------------------------------------
Update Information:
Update to 2.4.2 version (#1510677) ---- Update to 2.4.1 version (#1509732)
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1510677 - ansible-inventory-grapher-v2.4.2 is available
https://bugzilla.redhat.com/show_bug.cgi?id=1510677
[ 2 ] Bug #1510288 - Bump version to be compatible with ansible 2.4.x (now in el7 Extras)
https://bugzilla.redhat.com/show_bug.cgi?id=1510288
--------------------------------------------------------------------------------
================================================================================
d-din-fonts-1.0-1.el7 (FEDORA-EPEL-2017-1d5ff26956)
Datto D-DIN fonts
--------------------------------------------------------------------------------
Update Information:
Initial import into Fedora EPEL
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1509777 - Review Request: d-din-fonts - Datto D-DIN fonts
https://bugzilla.redhat.com/show_bug.cgi?id=1509777
--------------------------------------------------------------------------------
================================================================================
darktable-2.0.7-3.el7 (FEDORA-EPEL-2017-04c5bfc8f6)
Utility to organize and develop raw images
--------------------------------------------------------------------------------
Update Information:
rebuild against new gtk
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1490361 - None
https://bugzilla.redhat.com/show_bug.cgi?id=1490361
--------------------------------------------------------------------------------
================================================================================
fedfind-3.8.0-1.el7 (FEDORA-EPEL-2017-c0be6372ac)
Fedora compose and image finder
--------------------------------------------------------------------------------
Update Information:
fedfind 3.6.4 fixes use of the `expected_images` property (and hence
`check_expected()` method) with modular composes. In 3.6.2 and earlier, it
caused a crash. fedfind 3.7.1 improves handling of various new compose types
introduced by release engineering. The new nightly modular composes from master
branch, now versioned `Bikeshed` rather than `Rawhide`, are handled with a new
`BikeshedModularNightly` class. 'updates' and 'updates-testing' composes are
explicitly not supported (`get_release` will raise a `ValueError` with a
specific text for these) as they do not contain images and so fedfind can't do
much with them. Note that the `fedfind.helpers.parse_cid` function is entirely
rewritten in support of this; the new version is much more capable and accurate
and should handle all compose IDs the previous version handled correctly, but
please report any issues you find. fedfind 3.8.0 adds support for the Modular
Server candidate composes which are currently being produced.
--------------------------------------------------------------------------------
================================================================================
git-publish-1.4.2-2.el7 (FEDORA-EPEL-2017-8a148ce945)
Prepare and store patch revisions as git tags
--------------------------------------------------------------------------------
Update Information:
Add missing BuildRequires: pythonX-devel
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1508384 - Review Request: git-publish - Prepare and store patch revisions as git tags
https://bugzilla.redhat.com/show_bug.cgi?id=1508384
--------------------------------------------------------------------------------
================================================================================
knot-2.6.1-1.el7 (FEDORA-EPEL-2017-6d2a35b0f7)
High-performance authoritative DNS server
--------------------------------------------------------------------------------
Update Information:
Knot DNS major update: Knot DNS 2.6.1 (2017-11-02) ===========================
Features: --------- - NSEC3 Opt-Out support in the DNSSEC signing - New
CDS/CDNSKEY publish configuration option Improvements: ------------- -
Simplified DNSSEC log message with DNSKEY details - +tls-hostname in kdig
implies +tls-ca if neither +tls-ca nor +tls-pin is given - New documentation
sections for DNSSEC key rollovers and shared keys - Keymgr no longer prints
useless algorithm number for generated key - Kdig prints unknown RCODE in a
numeric format - Better support for LLVM libFuzzer Bugfixes: --------- -
Faulty DNAME semantic check if present in the zone apex and NSEC3 is used -
Immediate zone flush not scheduled during the zone load event - Server crashes
upon dynamic zone addition if a query module is loaded - Kdig fails to connect
over TLS due to SNI is set to server IP address - Possible out-of-bounds memory
access at the end of the input - TCP Fast Open enabled by default in kdig
breaks TLS connection Knot DNS 2.6.0 (2017-09-29) ===========================
Features: --------- - On-slave (inline) signing support - Automatic DNSSEC key
algorithm rollover - Ed25519 algorithm support in DNSSEC (requires GnuTLS
3.6.0) - New 'journal-content' and 'zonefile-load' configuration options -
keymgr tries to run as user/group set in the configuration - Public-only DNSSEC
key import into KASP DB via keymgr - NSEC3 resalt and parent DS query events
are persistent in timer DB - New processing state for a response suppression
within a query module - Enabled server side TCP Fast Open if supported - TCP
Fast Open support in kdig Improvements: ------------- - Better record owner
compression if related to the previous rdata dname - NSEC(3) chain is no longer
recomputed whole on every update - Remove inconsistent and unnecessary quoting
in log files - Avoiding of overlapping key rollovers at a time - More DNSSSEC-
related semantic checks - Extended timestamp format in keymgr Bugfixes:
--------- - Incorrect journal free space computation causing inefficient space
handling - Interface-automatic broken on Linux in the presence of asymmetric
routing Knot DNS 2.5.5 (2017-09-29) =========================== Improvements:
------------- - Constant time memory comparison in the TSIG processing -
Proper use of the ctype functions - Generated RRSIG records have inception time
90 minutes in the past Bugfixes: --------- - Incorrect online signature for
NSEC in the case of a CNAME record - Incorrect timestamps in dnstap records -
EDNS Subnet Client validation rejects valid payloads - Module configuration
semantic checks are not executed - Kzonecheck segfaults with unusual inputs
Knot DNS 2.5.4 (2017-08-31) =========================== Improvements:
------------- - New minimum and maximum refresh interval config options (Thanks
to Manabu Sonoda) - New warning when unforced flush with disabled zone file
synchronization - New 'dnskey' keymgr command - Linking with libatomic on
architectures that require it (Thanks to Pierre-Olivier Mercier) - Removed 'OK'
from listing keymgr command outputs - Extended journal and keymgr documentation
and logging Bugfixes: --------- - Incorrect handling of specific corner-cases
with zone-in-journal - The 'share' keymgr command doesn't work - Server
crashes if configured with query-size and reply-size statistics options -
Malformed big integer configuration values on some 32-bit platforms - Keymgr
uses local time when parsing date inputs - Memory leak in kdig upon IXFR query
Knot DNS 2.5.3 (2017-07-14) =========================== Features: --------- -
CSK rollover support for Single-Type Signing Scheme Improvements: -------------
- Allowed binding to non-local adresses for TCP (Thanks to Julian Brost!) - New
documentation section for manual DNSSEC key algorithm rollover - Initial KSK
also generated in the submission state - The 'ds' keymgr command with no
parameter uses all KSK keys - New debug mode in kjournalprint - Updated keymgr
documentation Bugfixes: --------- - Sometimes missing RRSIG by KSK in
submission state. - Minor DNSSEC-related issues
--------------------------------------------------------------------------------
================================================================================
knot-resolver-1.5.0-1.el7 (FEDORA-EPEL-2017-3b44fea72e)
Caching full DNS Resolver
--------------------------------------------------------------------------------
Update Information:
Knot Resolver is full caching DNS resolver implementation. Knot Resolver 1.5.0
(2017-11-02) ================================ Bugfixes -------- - fix loading
modules on Darwin Improvements ------------ - new module ta_signal_query
supporting Signaling Trust Anchor Knowledge using Keytag Query (RFC 8145
section 5); it is enabled by default - attempt validation for more records but
require it for fewer of them (e.g. avoids SERVFAIL when server adds extra
records but omits RRSIGs) Knot Resolver 1.4.0 (2017-09-22)
================================ Incompatible changes -------------------- -
lua: query flag-sets are no longer represented as plain integers. kres.query.*
no longer works, and kr_query_t lost trivial methods 'hasflag' and 'resolved'.
You can instead write code like qry.flags.NO_0X20 = true. Bugfixes -------- -
fix exiting one of multiple forks (#150) - cache: change the way of using LMDB
transactions. That in particular fixes some cases of using too much space
with multiple kresd forks (#240). Improvements ------------ - policy.suffix:
update the aho-corasick code (#200) - root hints are now loaded from a zonefile;
exposed as hints.root_file(). You can override the path by defining ROOTHINTS
during compilation. - policy.FORWARD: work around resolvers adding unsigned NS
records (#248) - reduce unneeded records previously put into authority in
wildcarded answers Knot Resolver 1.3.3 (2017-08-09)
================================ Security -------- - Fix a critical DNSSEC
flaw. Signatures might be accepted as valid even if the signed data was not
in bailiwick of the DNSKEY used to sign it, assuming the trust chain to that
DNSKEY was valid. Bugfixes -------- - iterate: skip RRSIGs with bad label count
instead of immediate SERVFAIL - utils: fix possible incorrect seeding of the
random generator - modules/http: fix compatibility with the Prometheus text
format Improvements ------------ - policy: implement remaining special-use
domain names from RFC6761 (#205), and make these rules apply only if no other
non-chain rule applies Knot Resolver 1.3.2 (2017-07-28)
================================ Security -------- - fix possible opportunities
to use insecure data from cache as keys for validation Bugfixes -------- -
daemon: check existence of config file even if rundir isn't specified -
policy.FORWARD and STUB: use RTT tracking to choose servers (#125, #208) -
dns64: fix CNAME problems (#203) It still won't work with policy.STUB. - hints:
better interpretation of hosts-like files (#204) also, error out if a
bad entry is encountered in the file - dnssec: handle unknown DNSKEY/DS
algorithms (#210) - predict: fix the module, broken since 1.2.0 (#154)
Improvements ------------ - embedded LMDB fallback: update 0.9.18 -> 0.9.21
Knot Resolver 1.3.1 (2017-06-23) ================================ Bugfixes
-------- - modules/http: fix finding the static files (bug from 1.3.0) -
policy.FORWARD: fix some cases of CNAMEs obstructing search for zone cuts Knot
Resolver 1.3.0 (2017-06-13) ================================ Security --------
- Refactor handling of AD flag and security status of resource records. In
some cases it was possible for secure domains to get cached as insecure, even
for a TLD, leading to disabled validation. It also fixes answering with non-
authoritative data about nameservers. Improvements ------------ - major
feature: support for forwarding with validation (#112). The old policy.FORWARD
action now does that; the previous non-validating mode is still avaliable as
policy.STUB except that also uses caching (#122). - command line: specify ports
via @ but still support # for compatibility - policy: recognize 100.64.0.0/10 as
local addresses - layer/iterate: *do* retry repeatedly if REFUSED, as we can't
yet easily retry with other NSs while avoiding retrying with those who REFUSED
- modules: allow changing the directory where modules are found, and do not
search the default library path anymore. Bugfixes -------- - validate: fix
insufficient caching for some cases (relatively rare) - avoid putting
"duplicate" record-sets into the answer (#198) Knot Resolver 1.2.6
(2017-04-24) ================================ Security -------- - dnssec: don't
set AD flag for NODATA answers if wildcard non-existence is not guaranteed due
to opt-out in NSEC3 Improvements ------------ - layer/iterate: don't retry
repeatedly if REFUSED Bugfixes -------- - lib/nsrep: revert some changes to NS
reputation tracking that caused severe problems to some users of 1.2.5 (#178
and #179) - dnssec: fix verification of wildcarded non-singleton RRsets -
dnssec: allow wildcards located directly under the root - layer/rrcache: avoid
putting answer records into queries in some cases Knot Resolver 1.2.5
(2017-04-05) ================================ Security -------- -
layer/validate: clear AD if closest encloser proof has opt-outed NSEC3 (#169)
- layer/validate: check if NSEC3 records in wildcard expansion proof has an
opt-out - dnssec/nsec: missed wildcard no-data answers validation has been
implemented Improvements ------------ - modules/dnstap: a DNSTAP support module
(Contributed by Vicky Shrestha) - modules/workarounds: a module adding
workarounds for known DNS protocol violators - layer/iterate: fix logging of
glue addresses - kr_bitcmp: allow bits=0 and consequently 0.0.0.0/0 matches in
view and renumber modules. - modules/padding: Improve default padding of
responses (Contributed by Daniel Kahn Gillmor) - New kresc client utility
(experimental; don't rely on the API yet) Bugfixes -------- - trust anchors:
Improve trust anchors storage format (#167) - trust anchors: support non-root
TAs, one domain per file - policy.DENY: set AA flag and clear AD flag -
lib/resolve: avoid unnecessary DS queries - lib/nsrep: don't treat servers with
NOIP4 + NOIP6 flags as timeouted - layer/iterate: During packet classification
(answer vs. referral) don't analyze AUTHORITY section in authoritative answer
if ANSWER section contains records that have been requested Knot Resolver
1.2.4 (2017-03-09) ================================ Security -------- - Knot
Resolver 1.2.0 and higher could return AD flag for insecure answer if the
daemon received answer with invalid RRSIG several times in a row.
Improvements ------------ - modules/policy: allow QTRACE policy to be chained
with other policies - hints.add_hosts(path): a new property - module: document
the API and simplify the code - policy.MIRROR: support IPv6 link-local addresses
- policy.FORWARD: support IPv6 link-local addresses - add net.outgoing_{v4,v6}
to allow specifying address to use for connections Bugfixes -------- -
layer/iterate: some improvements in cname chain unrolling - layer/validate: fix
duplicate records in AUTHORITY section in case of WC expansion proof - lua: do
*not* truncate cache size to unsigned - forwarding mode: correctly forward +cd
flag - fix a potential memory leak - don't treat answers that contain DS non-
existance proof as insecure - don't store NSEC3 and their signatures in the
cache - layer/iterate: when processing delegations, check if qname is at or
below new authority Knot Resolver 1.2.3 (2017-02-23)
================================ Bugfixes -------- - Disable storing GLUE
records into the cache even in the (non-default) QUERY_PERMISSIVE mode -
iterate: skip answer RRs that don't match the query - layer/iterate: some
additional processing for referrals - lib/resolve: zonecut fetching error was
fixed Knot Resolver 1.2.2 (2017-02-10) ================================
Bugfixes: --------- - Fix -k argument processing to avoid out-of-bounds memory
accesses - lib/resolve: fix zonecut fetching for explicit DS queries - hints:
more NULL checks - Fix TA bootstrapping for multiple TAs in the IANA XML file
Testing: -------- - Update tests to run tests with and without QNAME
minimization Knot Resolver 1.2.1 (2017-02-01)
==================================== Security: --------- - Under certain
conditions, a cached negative answer from a CD query would be reused to
construct response for non-CD queries, resulting in Insecure status instead of
Bogus. Only 1.2.0 release was affected. Documentation ------------- - Update
the typo in the documentation: The query trace policy is named policy.QTRACE
(and not policy.TRACE) Bugfixes: --------- - lua: make the map command check
its arguments Knot Resolver 1.2.0 (2017-01-24)
==================================== Security: --------- - In a
policy.FORWARD() mode, the AD flag was being always set by mistake. It is now
cleared, as the policy.FORWARD() doesn't do DNSSEC validation yet.
Improvements: ------------- - The DNSSEC Validation has been refactored, fixing
many resolving failures. - Add module `version` that checks for updates and
CVEs periodically. - Support RFC7830: EDNS(0) padding in responses over TLS. -
Support CD flag on incoming requests. - hints module: previously /etc/hosts was
loaded by default, but not anymore. Users can now actually avoid loading any
file. - DNS over TLS now creates ephemeral certs. - Configurable
cache.{min,max}_tll option, with max_ttl defaulting to 6 days. - Option to
reorder RRs in the response. - New policy.QTRACE policy to print packet contents
Bugfixes: --------- - Trust Anchor configuration is now more robust. - Correctly
answer NOTIMPL for meta-types and non-IN RR classes. - Free TCP buffer on
cancelled connection. - Fix crash in hints module on empty hints file, and fix
non-lowercase hints. Miscelaneous: ------------- - It now requires knot >=
2.3.1 to link successfully. - The API+ABI for modules changed slightly. - New
LRU implementation. Knot Resolver 1.1.1 (2016-08-24)
================================ Bugfixes: --------- - Fix 0x20 randomization
with retransmit - Fix pass-through for the stub mode - Fix the root hints IPv6
addresses - Fix dst addr for retries over TCP Improvements: ------------- -
Track RTT of all tried servers for faster retransmit - DAF: Allow forwarding to
custom port - systemd: Read EnvironmentFile and user $KRESD_ARGS - systemd:
Update systemd units to be named after daemon Knot Resolver 1.1.0 (2016-08-12)
================================ Improvements: ------------- - RFC7873 DNS
Cookies - RFC7858 DNS over TLS - HTTP/2 web interface, RESTful API - Metrics
exported in Prometheus - DNS firewall module - Explicit CNAME target fetching
in strict mode - Query minimisation improvements - Improved integration with
systemd Knot Resolver 1.0.0 (2016-05-30) ================================
Initial release: ---------------- - The first initial release
--------------------------------------------------------------------------------
================================================================================
perl-Finance-Quote-1.44-1.el7 (FEDORA-EPEL-2017-967e14970f)
A Perl module that retrieves stock and mutual fund quotes
--------------------------------------------------------------------------------
Update Information:
Current upstream maintenance release. Various sources fixed, new source
AlphaVantage added.
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1509722 - perl-Finance-Quote-1.40 is available
https://bugzilla.redhat.com/show_bug.cgi?id=1509722
[ 2 ] Bug #1510220 - perl-Finance-Quote-1.42 is available
https://bugzilla.redhat.com/show_bug.cgi?id=1510220
[ 3 ] Bug #1510678 - perl-Finance-Quote-1.44 is available
https://bugzilla.redhat.com/show_bug.cgi?id=1510678
--------------------------------------------------------------------------------
================================================================================
purple-discord-0-13.20171010git2ca7b3c.el7 (FEDORA-EPEL-2017-ddf3df9c66)
Discord plugin for libpurple
--------------------------------------------------------------------------------
Update Information:
Updated purple plugins to latest Git snapshots.
--------------------------------------------------------------------------------
================================================================================
purple-hangouts-0-52.20171023hg4ce9b33.el7 (FEDORA-EPEL-2017-ddf3df9c66)
Hangouts plugin for libpurple
--------------------------------------------------------------------------------
Update Information:
Updated purple plugins to latest Git snapshots.
--------------------------------------------------------------------------------
================================================================================
purple-skypeweb-1.4-6.20171024gitc442007.el7 (FEDORA-EPEL-2017-ddf3df9c66)
Adds support for Skype to Pidgin
--------------------------------------------------------------------------------
Update Information:
Updated purple plugins to latest Git snapshots.
--------------------------------------------------------------------------------
================================================================================
recap-1.2.0-2.el7 (FEDORA-EPEL-2017-32d4e6a1fb)
Generates reports of various system information
--------------------------------------------------------------------------------
Update Information:
- Drop requirement on bc - Add requirement on links ---- - Latest upstream
rhbz#1489995 - Switch dependency of net-tools to iproute rhbz#1496151
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1496151 - Remove dependency on net-tools
https://bugzilla.redhat.com/show_bug.cgi?id=1496151
[ 2 ] Bug #1489995 - recap-1.2.0 is available
https://bugzilla.redhat.com/show_bug.cgi?id=1489995
--------------------------------------------------------------------------------
================================================================================
sendemail-1.56-1.el7 (FEDORA-EPEL-2017-5fc6ae1c30)
Lightweight command line SMTP e-mail client
--------------------------------------------------------------------------------
Update Information:
SendEmail is a lightweight, completely command line based, SMTP e-mail client.
It was designed to be used in bash scripts, batch files, Perl programs and web
sites, but is also quite useful in many other contexts. SendEmail is written in
Perl and is unique in that it requires no special modules. It has a straight
forward interface, making it very easy to use.
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1509770 - Review Request: sendemail - Lightweight command line SMTP e-mail client
https://bugzilla.redhat.com/show_bug.cgi?id=1509770
--------------------------------------------------------------------------------
================================================================================
stomppy-3.1.6-3.el7 (FEDORA-EPEL-2017-ce93b28876)
Python stomp client for messaging
--------------------------------------------------------------------------------
Update Information:
Fixes RHBZ#1510105 - Adds support for ipv6.
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1510105 - None
https://bugzilla.redhat.com/show_bug.cgi?id=1510105
--------------------------------------------------------------------------------
================================================================================
vrms-rpm-1.3-1.el7 (FEDORA-EPEL-2017-462a6c5d91)
Report non-free software
--------------------------------------------------------------------------------
Update Information:
Update to new upstream version
--------------------------------------------------------------------------------
The following Fedora EPEL 6 Security updates need testing:
Age URL
854 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2015-7031 python-virtualenv-12.0.7-1.el6
848 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2015-7168 rubygem-crack-0.3.2-2.el6
738 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2015-e2b4b5b2fb mcollective-2.8.4-1.el6
710 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2015-35e240edd9 thttpd-2.25b-24.el6
320 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2016-e3e50897ac libbsd-0.8.3-2.el6
50 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2017-4c76ddcc92 libmspack-0.6-0.1.alpha.el6
13 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2017-e031963c40 tomcat-7.0.82-1.el6
7 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2017-29f7b67071 wordpress-4.8.3-1.el6
5 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2017-68e2defc4c fedpkg-1.30-3.el6 rpkg-1.51-1.el6
5 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2017-16d441d000 pcre2-10.21-21.el6
2 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2017-ed87c07972 hostapd-2.6-6.el6
2 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2017-2bd5c2db5b php-PHPMailer-5.2.26-1.el6
The following builds have been pushed to Fedora EPEL 6 updates-testing
fedfind-3.8.0-1.el6
perl-Finance-Quote-1.44-1.el6
recap-1.2.0-2.el6
sendemail-1.56-1.el6
stomppy-3.1.6-2.el6
vrms-rpm-1.3-1.el6
Details about builds:
================================================================================
fedfind-3.8.0-1.el6 (FEDORA-EPEL-2017-a96a15e55c)
Fedora compose and image finder
--------------------------------------------------------------------------------
Update Information:
fedfind 3.6.4 fixes use of the `expected_images` property (and hence
`check_expected()` method) with modular composes. In 3.6.2 and earlier, it
caused a crash. fedfind 3.7.1 improves handling of various new compose types
introduced by release engineering. The new nightly modular composes from master
branch, now versioned `Bikeshed` rather than `Rawhide`, are handled with a new
`BikeshedModularNightly` class. 'updates' and 'updates-testing' composes are
explicitly not supported (`get_release` will raise a `ValueError` with a
specific text for these) as they do not contain images and so fedfind can't do
much with them. Note that the `fedfind.helpers.parse_cid` function is entirely
rewritten in support of this; the new version is much more capable and accurate
and should handle all compose IDs the previous version handled correctly, but
please report any issues you find. fedfind 3.8.0 adds support for the Modular
Server candidate composes which are currently being produced.
--------------------------------------------------------------------------------
================================================================================
perl-Finance-Quote-1.44-1.el6 (FEDORA-EPEL-2017-84459b620f)
A Perl module that retrieves stock and mutual fund quotes
--------------------------------------------------------------------------------
Update Information:
Current upstream maintenance release. Various sources fixed, new source
AlphaVantage added.
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1509722 - perl-Finance-Quote-1.40 is available
https://bugzilla.redhat.com/show_bug.cgi?id=1509722
[ 2 ] Bug #1510220 - perl-Finance-Quote-1.42 is available
https://bugzilla.redhat.com/show_bug.cgi?id=1510220
[ 3 ] Bug #1510678 - perl-Finance-Quote-1.44 is available
https://bugzilla.redhat.com/show_bug.cgi?id=1510678
--------------------------------------------------------------------------------
================================================================================
recap-1.2.0-2.el6 (FEDORA-EPEL-2017-92325c7400)
Generates reports of various system information
--------------------------------------------------------------------------------
Update Information:
- Drop requirement on bc - Add requirement on links ---- - Latest upstream
rhbz#1489995 - Switch dependency of net-tools to iproute rhbz#1496151
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1496151 - Remove dependency on net-tools
https://bugzilla.redhat.com/show_bug.cgi?id=1496151
[ 2 ] Bug #1489995 - recap-1.2.0 is available
https://bugzilla.redhat.com/show_bug.cgi?id=1489995
--------------------------------------------------------------------------------
================================================================================
sendemail-1.56-1.el6 (FEDORA-EPEL-2017-86ce304327)
Lightweight command line SMTP e-mail client
--------------------------------------------------------------------------------
Update Information:
SendEmail is a lightweight, completely command line based, SMTP e-mail client.
It was designed to be used in bash scripts, batch files, Perl programs and web
sites, but is also quite useful in many other contexts. SendEmail is written in
Perl and is unique in that it requires no special modules. It has a straight
forward interface, making it very easy to use.
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1509770 - Review Request: sendemail - Lightweight command line SMTP e-mail client
https://bugzilla.redhat.com/show_bug.cgi?id=1509770
--------------------------------------------------------------------------------
================================================================================
stomppy-3.1.6-2.el6 (FEDORA-EPEL-2017-eb67f4aebb)
Python stomp client for messaging
--------------------------------------------------------------------------------
Update Information:
Fixes RHBZ#1510105 - Adds support for ipv6.
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1510105 - None
https://bugzilla.redhat.com/show_bug.cgi?id=1510105
--------------------------------------------------------------------------------
================================================================================
vrms-rpm-1.3-1.el6 (FEDORA-EPEL-2017-a087912479)
Report non-free software
--------------------------------------------------------------------------------
Update Information:
Update to new upstream version
--------------------------------------------------------------------------------