The following Fedora EPEL 8 Security updates need testing: Age URL 6 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2023-ee729bf9b2 sympa-6.2.72-2.el8 1 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2023-d55abd83c7 perl-HTML-StripScripts-1.06-22.el8 1 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2023-e14003b86d syncthing-1.23.5-1.el8
The following builds have been pushed to Fedora EPEL 8 updates-testing
chromium-114.0.5735.106-1.el8 icewm-3.4.0-2.el8 radare2-5.8.6-1.el8 tmt-1.24.1-1.el8
Details about builds:
================================================================================ chromium-114.0.5735.106-1.el8 (FEDORA-EPEL-2023-c018b37680) A WebKit (Blink) powered web browser that Google doesn't want you to use -------------------------------------------------------------------------------- Update Information:
update to 114.0.5735.106. Fixes the following security issue: CVE-2023-3709 -------------------------------------------------------------------------------- ChangeLog:
* Wed Jun 7 2023 Than Ngo than@redhat.com - 114.0.5735.106-1 - update to 114.0.5735.106 * Sun May 28 2023 Than Ngo than@redhat.com - 114.0.5735.45-1 - update to 114.0.5735.45 - add qt6 linuxui backend - backport: handle scale factor changes - backport: fix font double_scaling -------------------------------------------------------------------------------- References:
[ 1 ] Bug #2212975 - CVE-2023-3079 chromium: chromium-browser: Type Confusion in V8 [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2212975 [ 2 ] Bug #2212976 - CVE-2023-3079 chromium: chromium-browser: Type Confusion in V8 [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2212976 --------------------------------------------------------------------------------
================================================================================ icewm-3.4.0-2.el8 (FEDORA-EPEL-2023-6239221bd9) Window manager designed for speed, usability, and consistency -------------------------------------------------------------------------------- Update Information:
Update to latest version -------------------------------------------------------------------------------- ChangeLog:
* Fri Jun 9 2023 Artem Polishchuk ego.cordatus@gmail.com - 3.4.0-1 - chore: Update to 3.4.0 (rhbz#2212455) * Fri May 19 2023 Artem Polishchuk ego.cordatus@gmail.com - 3.3.5-1 - chore: Update to 3.3.5 --------------------------------------------------------------------------------
================================================================================ radare2-5.8.6-1.el8 (FEDORA-EPEL-2023-3dd846c7ab) The reverse engineering framework -------------------------------------------------------------------------------- Update Information:
Bump to 5.8.6 -------------------------------------------------------------------------------- ChangeLog:
* Tue May 23 2023 Michal Ambroz <rebus at, seznam.cz> 5.8.6-1 - bump to 5.8.6 * Sat Mar 25 2023 Michal Ambroz <rebus at, seznam.cz> 5.8.5-0.3 - 5.8.5 rebuild from git, patched for segfault * Wed Mar 22 2023 Michal Ambroz <rebus at, seznam.cz> 5.8.4-2 - patch for segfault in sdb_hash * Thu Mar 16 2023 Michal Ambroz <rebus at, seznam.cz> 5.8.4-1 - bump to 5.8.4 -------------------------------------------------------------------------------- References:
[ 1 ] Bug #2157016 - CVE-2022-4843 radare2: Fix null deref in io.bank [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2157016 [ 2 ] Bug #2170036 - syscall detection is broken https://bugzilla.redhat.com/show_bug.cgi?id=2170036 [ 3 ] Bug #2178851 - radare2-5.8.6 is available https://bugzilla.redhat.com/show_bug.cgi?id=2178851 [ 4 ] Bug #2179047 - iaito-5.8.6 is available https://bugzilla.redhat.com/show_bug.cgi?id=2179047 --------------------------------------------------------------------------------
================================================================================ tmt-1.24.1-1.el8 (FEDORA-EPEL-2023-abfe39d5aa) Test Management Tool -------------------------------------------------------------------------------- Update Information:
Automatic update for tmt-1.24.1-1.el8. ##### **Changelog for tmt** ``` * Fri Jun 09 2023 Petr ��pl��chal psplicha@redhat.com - 1.24.1-1 - Revert the `Source0` url to the original value - Use correct url for the release archive, fix docs * Wed Jun 07 2023 Petr ��pl��chal psplicha@redhat.com - 1.24.0-1 - Do not display guest facts when showing a plan - Add new guide/summary for multihost testing - Define a "plugin registry" class - Hide `facts` in the `virtual` provision plugin - Cache resolved linters - Improve documentation of lint checks (#2089) - A custom wrapper for options instead of click.option() - Identify incorrect subcommand after a correct one - Remove one extra space between @ and decorator name - Assign envvars to Polarion report arguments - Expose "key address" to normalization callbacks (#1869) - Move export of special test/plan/story fields to their respective classes - Expose guest topology to tests and scripts (#2072) - Enable building downstream release using Packit - Add sections for environment variable groups - Add default envvar to plugin options - Load env TMT_WORKDIR_ROOT when running tmt status (#2087) - Opportunistically use "selectable" entry_points. - Explicitly convert tmpdir to str in test_utils.py. - Move pytest.ini contents to pyproject.toml. - Rename Require* classes to Dependency* (#2099) - Expose fmf ID of tests in results - Use the `tmt-lint` pre-commit hook - Turn finish step implementation to queue- based one (#2110) - Convert base classes to data classes (#2080) - Crashed prepare and execute steps propagate all causes - Support exceptions with multiple causes - Make "needs sudo" a guest fact (#2096) - Test data path must use safe guest/test names - Support for multi case import from Polarion and Polarion as only source (#2084) - Fix search function in docs - Make tmt test wrapper name unique to avoid race conditions - Change link-polarion argument default to false - Add export plugin for JSON (#2058) - Handle el6 as a legacy os too in virtual provision - Hint beakerlib is old when result parsing fails - Revert "Fix dry mode handling when running a remote plan" - Set a new dict instance to the Plan class - Replaces "common" object with logger in method hint logging - Parallelize prepare and execute steps - Formalizing guest "facts" storage - Support urllib3 2.x and its allowed_methods/method_whitelist - Require setuptools ``` -------------------------------------------------------------------------------- ChangeLog:
* Fri Jun 9 2023 Petr ��pl��chal psplicha@redhat.com - 1.24.1-1 - Revert the `Source0` url to the original value - Use correct url for the release archive, fix docs * Wed Jun 7 2023 Petr ��pl��chal psplicha@redhat.com - 1.24.0-1 - Do not display guest facts when showing a plan - Add new guide/summary for multihost testing - Define a "plugin registry" class - Hide `facts` in the `virtual` provision plugin - Cache resolved linters - Improve documentation of lint checks (#2089) - A custom wrapper for options instead of click.option() - Identify incorrect subcommand after a correct one - Remove one extra space between @ and decorator name - Assign envvars to Polarion report arguments - Expose "key address" to normalization callbacks (#1869) - Move export of special test/plan/story fields to their respective classes - Expose guest topology to tests and scripts (#2072) - Enable building downstream release using Packit - Add sections for environment variable groups - Add default envvar to plugin options - Load env TMT_WORKDIR_ROOT when running tmt status (#2087) - Opportunistically use "selectable" entry_points. - Explicitly convert tmpdir to str in test_utils.py. - Move pytest.ini contents to pyproject.toml. - Rename Require* classes to Dependency* (#2099) - Expose fmf ID of tests in results - Use the `tmt-lint` pre-commit hook - Turn finish step implementation to queue-based one (#2110) - Convert base classes to data classes (#2080) - Crashed prepare and execute steps propagate all causes - Support exceptions with multiple causes - Make "needs sudo" a guest fact (#2096) - Test data path must use safe guest/test names - Support for multi case import from Polarion and Polarion as only source (#2084) - Fix search function in docs - Make tmt test wrapper name unique to avoid race conditions - Change link-polarion argument default to false - Add export plugin for JSON (#2058) - Handle el6 as a legacy os too in virtual provision - Hint beakerlib is old when result parsing fails - Revert "Fix dry mode handling when running a remote plan" - Set a new dict instance to the Plan class - Replaces "common" object with logger in method hint logging - Parallelize prepare and execute steps - Formalizing guest "facts" storage - Support urllib3 2.x and its allowed_methods/method_whitelist - Require setuptools --------------------------------------------------------------------------------
epel-devel@lists.fedoraproject.org