The following Fedora EPEL 8 Security updates need testing:
Age URL
5 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2024-cef1a533b1 clamav-1.0.7-1.el8
The following builds have been pushed to Fedora EPEL 8 updates-testing
libopenmpt-0.7.9-1.el8
Details about builds:
================================================================================
libopenmpt-0.7.9-1.el8 (FEDORA-EPEL-2024-a72ba05853)
C/C++ library to decode tracker music module (MOD) files
--------------------------------------------------------------------------------
Update Information:
libopenmpt 0.7.9 (2024-07-21)
[Sec] Potential division by 0 when seeking in the module with seek.sync_samples
enabled (r21167).
[Change] The work-around for https://gcc.gnu.org/bugzilla/show_bug.cgi?id=115049
has been changed from forcing -O1 on GCC 14 to setting -fno-ipa-ra on all GCC
versions on non-ELF platforms. We are still not 100% sure if this work-around is
sufficient in all circumstances. If you are using a non-ELF platform, it is
strongly recommended to update GCC to versions 12.5.0, 13.4.0, 14.2.0, or 15.1.0
as soon as they are released, or to apply the patch from the linked GCC issues.
MOD: Allow sample swapping to work when swapping from a non-looping, stopped
sample back to a looping sample (fixes MOD.energy).
DBM: Import second sustain point in case the first sustain point is not set, or
if it has a lower index than the first.
DBM: When several instruments referenced the same sample with different
properties (volume, loop points, etc.), only one set of properties was imported
(fixes DBM.Supernova).
DBM: Prioritize effects more correctly when the same effect is encountered in
both effect columns of a cell (fixes DBM.143_Gnoj).
DBM: Don’t import offset effects when there’s a tone portmento next to them.
DBM: A few IT-specific playback quirks are disabled for more accurate playback
(e.g. in “Are You Flying With Me?” by Jazzcat).
DIGI: Sample play direction was reset if adjacent channel contained a Note Cut
note.
AMF: When running out of sample slots, file reading became be misaligned because
the sample name was not skipped.
MED: Command 0F was not imported.
MED: Upper frequency limits should be more accurate now.
MED: Channel panning is now only applied in MMD2 files if the free pan flag is
set.
MED: Volume command resolution was incorrect for pre-MMD3 files.
XM: oggmod does not support stereo samples but keeps the stereo flag when
encoding such samples. Such samples are now imported as mono samples instead of
not importing them at all.
XM: For files saved with registered MadTracker 2 versions, do not put binary
garbage (the user ID) in the tracker metadata field. It is replaced with
“registered” instead.
For some truncated files, the used tracker was not identified correctly.
S3M: Identify files saved with early Impulse Tracker versions, Sound Club 2,
Liquid Tracker, NESMusa, UNMO3, deMODifier, Kosmic To-S3M, and better tell old
ModPlug Tracker versions apart.
S3M: When skipping sample loading, some tracker identifications were not working
as intended.
IT: Identify files saved with itwriter.
DTM: Identify files saved with Digital Tracker 2.3.
xmp-openmpt: If there is only one subsong, set the song title to the “global”
song title instead of the name of that subsong.
xmp-openmpt: Sample and instrument names were not sanitized, sometimes showing
on multiple rows.
--------------------------------------------------------------------------------
ChangeLog:
* Sun Jul 21 2024 Michael Schwendt <mschwendt(a)fedoraproject.org> - 0.7.9-1
- update to 0.7.9
* Thu Jul 18 2024 Fedora Release Engineering <releng(a)fedoraproject.org> - 0.7.8-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_41_Mass_Rebuild
--------------------------------------------------------------------------------
The following Fedora EPEL 9 Security updates need testing:
Age URL
5 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2024-702a565078 clamav-1.0.7-1.el9
The following builds have been pushed to Fedora EPEL 9 updates-testing
libopenmpt-0.7.9-1.el9
rust-sequoia-sq-0.38.0-1.el9
wordpress-6.6.2-1.el9
Details about builds:
================================================================================
libopenmpt-0.7.9-1.el9 (FEDORA-EPEL-2024-45ce2e6776)
C/C++ library to decode tracker music module (MOD) files
--------------------------------------------------------------------------------
Update Information:
libopenmpt 0.7.9 (2024-07-21)
[Sec] Potential division by 0 when seeking in the module with seek.sync_samples
enabled (r21167).
[Change] The work-around for https://gcc.gnu.org/bugzilla/show_bug.cgi?id=115049
has been changed from forcing -O1 on GCC 14 to setting -fno-ipa-ra on all GCC
versions on non-ELF platforms. We are still not 100% sure if this work-around is
sufficient in all circumstances. If you are using a non-ELF platform, it is
strongly recommended to update GCC to versions 12.5.0, 13.4.0, 14.2.0, or 15.1.0
as soon as they are released, or to apply the patch from the linked GCC issues.
MOD: Allow sample swapping to work when swapping from a non-looping, stopped
sample back to a looping sample (fixes MOD.energy).
DBM: Import second sustain point in case the first sustain point is not set, or
if it has a lower index than the first.
DBM: When several instruments referenced the same sample with different
properties (volume, loop points, etc.), only one set of properties was imported
(fixes DBM.Supernova).
DBM: Prioritize effects more correctly when the same effect is encountered in
both effect columns of a cell (fixes DBM.143_Gnoj).
DBM: Don’t import offset effects when there’s a tone portmento next to them.
DBM: A few IT-specific playback quirks are disabled for more accurate playback
(e.g. in “Are You Flying With Me?” by Jazzcat).
DIGI: Sample play direction was reset if adjacent channel contained a Note Cut
note.
AMF: When running out of sample slots, file reading became be misaligned because
the sample name was not skipped.
MED: Command 0F was not imported.
MED: Upper frequency limits should be more accurate now.
MED: Channel panning is now only applied in MMD2 files if the free pan flag is
set.
MED: Volume command resolution was incorrect for pre-MMD3 files.
XM: oggmod does not support stereo samples but keeps the stereo flag when
encoding such samples. Such samples are now imported as mono samples instead of
not importing them at all.
XM: For files saved with registered MadTracker 2 versions, do not put binary
garbage (the user ID) in the tracker metadata field. It is replaced with
“registered” instead.
For some truncated files, the used tracker was not identified correctly.
S3M: Identify files saved with early Impulse Tracker versions, Sound Club 2,
Liquid Tracker, NESMusa, UNMO3, deMODifier, Kosmic To-S3M, and better tell old
ModPlug Tracker versions apart.
S3M: When skipping sample loading, some tracker identifications were not working
as intended.
IT: Identify files saved with itwriter.
DTM: Identify files saved with Digital Tracker 2.3.
xmp-openmpt: If there is only one subsong, set the song title to the “global”
song title instead of the name of that subsong.
xmp-openmpt: Sample and instrument names were not sanitized, sometimes showing
on multiple rows.
--------------------------------------------------------------------------------
ChangeLog:
* Sun Jul 21 2024 Michael Schwendt <mschwendt(a)fedoraproject.org> - 0.7.9-1
- update to 0.7.9
* Thu Jul 18 2024 Fedora Release Engineering <releng(a)fedoraproject.org> - 0.7.8-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_41_Mass_Rebuild
--------------------------------------------------------------------------------
================================================================================
rust-sequoia-sq-0.38.0-1.el9 (FEDORA-EPEL-2024-a7acf57426)
Command-line frontends for Sequoia
--------------------------------------------------------------------------------
Update Information:
Update to version 0.38.0.
--------------------------------------------------------------------------------
ChangeLog:
* Wed Sep 11 2024 Fabio Valentini <decathorpe(a)gmail.com> - 0.38.0-1
- Update to version 0.38.0; Fixes RHBZ#2309491
--------------------------------------------------------------------------------
================================================================================
wordpress-6.6.2-1.el9 (FEDORA-EPEL-2024-118ce76d75)
Blog tool and publishing platform
--------------------------------------------------------------------------------
Update Information:
Upstream announcement:
WordPress 6.6.2 Maintenance Release
--------------------------------------------------------------------------------
ChangeLog:
* Wed Sep 11 2024 Remi Collet <remi(a)remirepo.net> - 6.6.2-1
- WordPress 6.6.2 Maintenance Release
--------------------------------------------------------------------------------
The following Fedora EPEL 8 Security updates need testing:
Age URL
3 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2024-cef1a533b1 clamav-1.0.7-1.el8
The following builds have been pushed to Fedora EPEL 8 updates-testing
syncthing-1.27.12-1.el8
Details about builds:
================================================================================
syncthing-1.27.12-1.el8 (FEDORA-EPEL-2024-56e289a08f)
Continuous File Synchronization
--------------------------------------------------------------------------------
Update Information:
Update to version 1.27.12.
Release notes for 1.17.10:
https://github.com/syncthing/syncthing/releases/tag/v1.27.10
Release notes for 1.17.11:
https://github.com/syncthing/syncthing/releases/tag/v1.27.11
Release notes for 1.17.12:
https://github.com/syncthing/syncthing/releases/tag/v1.27.12
--------------------------------------------------------------------------------
ChangeLog:
* Mon Sep 9 2024 Fabio Valentini <decathorpe(a)gmail.com> - 1.27.12-1
- Update to version 1.27.12; Fixes RHBZ#2303591
--------------------------------------------------------------------------------
I got a request to build rgb for EPEL 10
(https://bugzilla.redhat.com/show_bug.cgi?id=2309102) which is not surprising as I did the same for EPEL 9. A local test build of that package failed due to a missing dependency of 'pkgconfig(xorg-macros)', so I requested an EPEL 10 build of xorg-x11-util-macros to resolve that (https://bugzilla.redhat.com/show_bug.cgi?id=2309121)
That package request was then declined:
fedpkg request-branch epel10
Could not execute request_branch: This package is already an EL
package, therefore it cannot be in EPEL. If this is a mistake....
Looking at the compose metadata, it appears that xorg-x11-util-macros
is in CRB, but only for the aarch64 architecture.
So, my questions are:
1. Is this intentional (seems unlikely, given that this is fundamental
to building just about anything using xorg-x11), and
2. If this *is* intentional, what should be done to facilitate building
rgb and similarly-affected packages in EPEL?
Any thoughts?
Regards, Paul.
The following Fedora EPEL 9 Security updates need testing:
Age URL
2 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2024-5f0c4ba4b8 wolfssl-5.7.2-2.el9
2 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2024-87852e6d70 nextcloud-29.0.6-1.el9
2 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2024-ebc9668713 osc-1.9.1-420.1.1.el9
0 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2024-702a565078 clamav-1.0.7-1.el9
The following builds have been pushed to Fedora EPEL 9 updates-testing
apptainer-1.3.4-1.el9
fastfetch-2.23.0-1.el9
packit-0.101.0-1.el9
tio-3.7-1.el9
Details about builds:
================================================================================
apptainer-1.3.4-1.el9 (FEDORA-EPEL-2024-c7d07c605c)
Application and environment virtualization formerly known as Singularity
--------------------------------------------------------------------------------
Update Information:
Update to upstream 1.3.4
--------------------------------------------------------------------------------
ChangeLog:
* Thu Sep 5 2024 Dave Dykstra <dwd(a)cern.ch> - 1.3.4
- Update to upstream 1.3.4
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #2310334 - apptainer-1.3.4 is available
https://bugzilla.redhat.com/show_bug.cgi?id=2310334
--------------------------------------------------------------------------------
================================================================================
fastfetch-2.23.0-1.el9 (FEDORA-EPEL-2024-33e3734ec9)
Like neofetch, but much faster because written in c
--------------------------------------------------------------------------------
Update Information:
update to 2.23.0
--------------------------------------------------------------------------------
ChangeLog:
* Fri Sep 6 2024 Jonathan Wright <jonathan(a)almalinux.org> - 2.23.0-1
- update to 2.23.0 rhbz#2308109
--------------------------------------------------------------------------------
================================================================================
packit-0.101.0-1.el9 (FEDORA-EPEL-2024-4dd5dac59b)
A tool for integrating upstream projects with Fedora operating system
--------------------------------------------------------------------------------
Update Information:
Automatic update for packit-0.101.0-1.el9.
Changelog for packit
* Fri Sep 06 2024 Packit <hello(a)packit.dev> - 0.101.0-1
- Packit now supports passing custom arguments to various static analyzers
through `--csmock-args` CLI option and `csmock_args` configuration. (#2402)
- When synching a new release Packit is now able to fast forward a specified
merge to a configured list of branches.
Use the `dist_git_branches` new syntax as in this example:
`{"rawhide": {"fast_forward_merge_into": ["f40"]}, "fedora-stable": {}}`
(#2363)
- Resolves: rhbz#2310376
--------------------------------------------------------------------------------
ChangeLog:
* Fri Sep 6 2024 Packit <hello(a)packit.dev> - 0.101.0-1
- Packit now supports passing custom arguments to various static analyzers through `--csmock-args` CLI option and `csmock_args` configuration. (#2402)
- When synching a new release Packit is now able to fast forward a specified merge to a configured list of branches.
Use the `dist_git_branches` new syntax as in this example:
`{"rawhide": {"fast_forward_merge_into": ["f40"]}, "fedora-stable": {}}` (#2363)
- Resolves: rhbz#2310376
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #2310376 - packit-0.101.0 is available
https://bugzilla.redhat.com/show_bug.cgi?id=2310376
--------------------------------------------------------------------------------
================================================================================
tio-3.7-1.el9 (FEDORA-EPEL-2024-2e24baebae)
Simple TTY terminal I/O application
--------------------------------------------------------------------------------
Update Information:
tio v3.7
Remove unnecessary sync in line input mode
This caused a problem for some highly timing sensitive modem read-eval-print
loops because the input line and line termination characters (cr/nl) would be
shifted out on the UART with too big delay inbetween because of two syncs.
Fix socket send call on platforms without MSG_NOSIGNAL
To fix build issue encountered on MacOS Catalina but may apply to other
platforms.
Add "epoch" timestamp option
Add an option that prints the timestamp as the number of seconds since the Unix
epoch.
The log-directory options is not read from the configuration file.
--------------------------------------------------------------------------------
ChangeLog:
* Fri Sep 6 2024 Robert Scheck <robert(a)fedoraproject.org> 3.7-1
- Upgrade to 3.7 (#2309659)
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #2309659 - tio-3.7 is available
https://bugzilla.redhat.com/show_bug.cgi?id=2309659
--------------------------------------------------------------------------------