The following Fedora 30 Security updates need testing: Age URL 12 https://bodhi.fedoraproject.org/updates/FEDORA-2019-aba3cca74a python3-3.7.5-1.fc30 4 https://bodhi.fedoraproject.org/updates/FEDORA-2019-74ba24605e python2-2.7.17-1.fc30 python2-docs-2.7.17-1.fc30 4 https://bodhi.fedoraproject.org/updates/FEDORA-2019-a2110fa094 varnish-6.3.1-1.fc30 4 https://bodhi.fedoraproject.org/updates/FEDORA-2019-7bb07c3b02 php-7.3.11-1.fc30 4 https://bodhi.fedoraproject.org/updates/FEDORA-2019-d3221d69e0 mingw-libidn2-2.2.0-1.fc30 4 https://bodhi.fedoraproject.org/updates/FEDORA-2019-8934d55352 nspr-4.23.0-1.fc30 nss-3.47.0-2.fc30 4 https://bodhi.fedoraproject.org/updates/FEDORA-2019-73919e71f8 aspell-0.60.8-1.fc30 4 https://bodhi.fedoraproject.org/updates/FEDORA-2019-97dcb2762a file-5.36-5.fc30 2 https://bodhi.fedoraproject.org/updates/FEDORA-2019-b2156dcba6 t1utils-1.41-1.fc30 2 https://bodhi.fedoraproject.org/updates/FEDORA-2019-119312dbfc java-latest-openjdk-13.0.1.9-2.rolling.fc30 0 https://bodhi.fedoraproject.org/updates/FEDORA-2019-99db7a510e webkit2gtk3-2.26.1-3.fc30
The following Fedora 30 Critical Path updates have yet to be approved: Age URL 111 https://bodhi.fedoraproject.org/updates/FEDORA-2019-c05e4425d1 dash-0.5.10.2-3.fc30 40 https://bodhi.fedoraproject.org/updates/FEDORA-2019-7cac16652c harfbuzz-2.6.1-2.fc30 19 https://bodhi.fedoraproject.org/updates/FEDORA-2019-75aec6d68e libappstream-glib-0.7.16-1.fc30 14 https://bodhi.fedoraproject.org/updates/FEDORA-2019-a28a633a0b vte291-0.56.4-1.fc30 13 https://bodhi.fedoraproject.org/updates/FEDORA-2019-ae9aa274f2 cups-2.2.12-3.fc30 12 https://bodhi.fedoraproject.org/updates/FEDORA-2019-aba3cca74a python3-3.7.5-1.fc30 4 https://bodhi.fedoraproject.org/updates/FEDORA-2019-97dcb2762a file-5.36-5.fc30 4 https://bodhi.fedoraproject.org/updates/FEDORA-2019-8934d55352 nspr-4.23.0-1.fc30 nss-3.47.0-2.fc30 4 https://bodhi.fedoraproject.org/updates/FEDORA-2019-bb9ea29ef2 linux-firmware-20191022-103.fc30 4 https://bodhi.fedoraproject.org/updates/FEDORA-2019-a07ea39a27 pungi-4.1.40-1.fc30 4 https://bodhi.fedoraproject.org/updates/FEDORA-2019-751c65ba68 librsvg2-2.46.3-1.fc30 4 https://bodhi.fedoraproject.org/updates/FEDORA-2019-6dc3b05887 libreport-2.11.2-1.fc30 4 https://bodhi.fedoraproject.org/updates/FEDORA-2019-40dba3d36e plymouth-0.9.4-11.20191022git32c097c.fc30 4 https://bodhi.fedoraproject.org/updates/FEDORA-2019-1b16b0e9ae sssd-2.2.2-3.fc30 4 https://bodhi.fedoraproject.org/updates/FEDORA-2019-059be8496f mesa-19.1.8-1.fc30 4 https://bodhi.fedoraproject.org/updates/FEDORA-2019-8c712089e1 sudo-1.8.28p1-1.fc30 4 https://bodhi.fedoraproject.org/updates/FEDORA-2019-640a6c99c0 vim-8.1.2198-1.fc30 4 https://bodhi.fedoraproject.org/updates/FEDORA-2019-25ba44eac2 fedora-release-30-6 4 https://bodhi.fedoraproject.org/updates/FEDORA-2019-74ba24605e python2-2.7.17-1.fc30 python2-docs-2.7.17-1.fc30 4 https://bodhi.fedoraproject.org/updates/FEDORA-2019-7b32145751 initial-setup-0.3.69-2.fc30 2 https://bodhi.fedoraproject.org/updates/FEDORA-2019-af5e9f72a8 libedit-3.1-29.20191025cvs.fc30 2 https://bodhi.fedoraproject.org/updates/FEDORA-2019-f83217e2bf selinux-policy-3.14.3-51.fc30 0 https://bodhi.fedoraproject.org/updates/FEDORA-2019-6ca9241892 glusterfs-6.6-1.fc30 0 https://bodhi.fedoraproject.org/updates/FEDORA-2019-e42a5ed21e polkit-0.116-2.fc30.2
The following builds have been pushed to Fedora 30 updates-testing
abcde-2.9.3-2.fc30 ansible-2.8.6-1.fc30 did-0.14-2.fc30 gpxsee-7.16-1.fc30 jss-4.6.2-2.fc30 keepassxc-2.5.0-1.fc30 libacars-1.3.1-1.fc30 libcorrect-0-1.20181010gitf5a28c7.fc30 octave-jsonlab-1.9.8-1.fc30 perl-CPAN-Perl-Releases-4.18-1.fc30 php-zendframework-zend-session-2.9.1-1.fc30 php-zendframework-zend-validator-2.12.2-1.fc30 pioneers-15.5-1.fc30 python-enlighten-1.4.0-1.fc30 python-fsleyes-0.31.2-1.fc30 python-fsleyes-props-1.6.7-1.fc30 python-fsleyes-widgets-0.8.4-1.fc30 python-fslpy-2.6.2-1.fc30 python-html2text-2019.9.26-2.fc30 python3-docs-3.7.5-1.fc30 python35-3.5.8-1.fc30 snapd-2.42-2.fc30 system-config-printer-1.5.12-2.fc30 toolbox-0.0.16-1.fc30 whois-5.5.2-2.fc30 xapian-core-1.4.13-2.fc30 zabbix-4.0.13-1.fc30 zlib-1.2.11-19.fc30
Details about builds:
================================================================================ abcde-2.9.3-2.fc30 (FEDORA-2019-c40a199886) A Better CD Encoder -------------------------------------------------------------------------------- Update Information:
MusicBrainz has [discontinued](https://wiki.musicbrainz.org/History:FreeDB_Gateway) their FreeDB gateway, so **abcde** has to switch to using the **MusicBrainz** backend directly to remain functional. Thanks to @gbcox for packaging the missing perl modules. -------------------------------------------------------------------------------- ChangeLog:
* Tue Oct 29 2019 Dominik Mierzejewski rpm@greysector.net - 2.9.3-2 - MusicBrainz lookup support for abcde (#1758816) - use gpgverify macro - add missing BR: perl-generators to generate perl dependencies - add Requires: hostname which might be missing on minimal installs -------------------------------------------------------------------------------- References:
[ 1 ] Bug #1758816 - RFE: MusicBrainz lookup support for abcde https://bugzilla.redhat.com/show_bug.cgi?id=1758816 --------------------------------------------------------------------------------
================================================================================ ansible-2.8.6-1.fc30 (FEDORA-2019-a9195834a9) SSH-based configuration management, deployment, and task execution system -------------------------------------------------------------------------------- Update Information:
Uppdate to bugfix release 2.8.6. -------------------------------------------------------------------------------- ChangeLog:
* Thu Oct 17 2019 Kevin Fenzi kevin@scrye.com - 2.8.6-1 - Update to 2.8.6. - Rework spec file to drop old conditionals. * Thu Oct 10 2019 Kevin Fenzi kevin@scrye.com - 2.8.5-2 - Make python3-paramiko and python3-winrm Recommended so they install on Fedora and not RHEL8 -------------------------------------------------------------------------------- References:
[ 1 ] Bug #1679254 - [abrt] ansible: default(): encoder.py:179:default:TypeError: Object of type AnsibleVaultEncryptedUnicode is not JSON serializable https://bugzilla.redhat.com/show_bug.cgi?id=1679254 [ 2 ] Bug #1727813 - TypeError: argument of type 'int' is not iterable, as vlanid (int) is not changed into string https://bugzilla.redhat.com/show_bug.cgi?id=1727813 --------------------------------------------------------------------------------
================================================================================ did-0.14-2.fc30 (FEDORA-2019-0365ac27ff) What did you do last week, month, year? -------------------------------------------------------------------------------- Update Information:
* Include setup.py, use auto build/install, tests * Fix 'did --test' when no config is present * Update spec file and shebang for Python 3 * Update shebang to explicitly use python3 * Goodbye Python 2! Thanks and have a good night ;-) * Support for custom plugin location [#160] -------------------------------------------------------------------------------- ChangeLog:
* Tue Oct 29 2019 Petr ��pl��chal psplicha@redhat.com - 0.14-2 - Include python3-setuptools in the BuildRequires - Use info level to log problems with plugin import * Tue Oct 22 2019 Petr ��pl��chal psplicha@redhat.com - 0.14-1 - Include setup.py, use auto build/install, enable tests - Fix 'did --test' when no config is present - Update spec file for Python 3 - Update shebang to explicitly use python3 - Fix mixed tabs and spaces in docs/conf.py - Goodbye Python 2! Thanks and have a good night ;-) - Cleanup built docs directly - Do not remove python's egg when doing the cleanup - Document the custom plugin configuration - A couple of custom plugins feature adjustments - Support for custom plugin location [#160] - Fix typo in the license classifier * Tue Oct 1 2019 Petr ��pl��chal psplicha@redhat.com - 0.13-1 - Support for the full file path config [#140] - Add the 'last friday' command [#197] - New plugin with basic confluence support [#199] - Improve redmine documentation [#195] - Add a new 'wip' option for gerrit [#194] - Include project name in gerrit stats [#192] - Fix the configuration examples for gerrit - Simplify Pagure search for created issues - Extended query for verified bugs [fix #189] - Fix for reviewed gerrit changes [#188] - Add gerrit work-in-progress changes [#187] - Fix for gerrit log strings [#186] - Improve gerrit search limit [#185] - Document API key auth for bugzilla [fix #180] - Mock bugzilla module to fix generating docs - Update feedparser requires - Fix for gerrit plugin typo [#179] -------------------------------------------------------------------------------- References:
[ 1 ] Bug #1715384 - did: dependency is missing on fedora 30 https://bugzilla.redhat.com/show_bug.cgi?id=1715384 --------------------------------------------------------------------------------
================================================================================ gpxsee-7.16-1.fc30 (FEDORA-2019-a6bf3dc865) GPS log file viewer and analyzer -------------------------------------------------------------------------------- Update Information:
**News in version 7.16** - Added support for Garmin GPI files - Hyperlink + copy&paste enabled tool tips - Various minor bug fixes in data loading -------------------------------------------------------------------------------- ChangeLog:
* Tue Oct 29 2019 Nikola Forr�� nforro@redhat.com - 7.16-1 - Update to version 7.16 resolves: #1766422 -------------------------------------------------------------------------------- References:
[ 1 ] Bug #1766422 - gpxsee-7.16 is available https://bugzilla.redhat.com/show_bug.cgi?id=1766422 --------------------------------------------------------------------------------
================================================================================ jss-4.6.2-2.fc30 (FEDORA-2019-4129cdf50b) Java Security Services (JSS) -------------------------------------------------------------------------------- Update Information:
Bugfix for rhbz#1766451 - occasional NativeProxy NPE -------------------------------------------------------------------------------- ChangeLog:
* Tue Oct 29 2019 Dogtag PKI Team pki-devel@redhat.com - 4.6.2-2 - Fix for rhbz#1766451 --------------------------------------------------------------------------------
================================================================================ keepassxc-2.5.0-1.fc30 (FEDORA-2019-c00509422e) Cross-platform password manager -------------------------------------------------------------------------------- Update Information:
2.5.0 release -------------------------------------------------------------------------------- ChangeLog:
* Mon Oct 28 2019 Gwyn Ciesla gwync@protonmail.com - 2.5.0-1 - 2.5.0 -------------------------------------------------------------------------------- References:
[ 1 ] Bug #1759158 - Auto-type into firefox no longer works in F31 under wayland https://bugzilla.redhat.com/show_bug.cgi?id=1759158 [ 2 ] Bug #1653435 - KeePassXC database takes longer to open on F29 https://bugzilla.redhat.com/show_bug.cgi?id=1653435 [ 3 ] Bug #1765885 - keepassxc-2.5.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=1765885 --------------------------------------------------------------------------------
================================================================================ libacars-1.3.1-1.fc30 (FEDORA-2019-853b91e43a) A library for decoding various ACARS message payloads -------------------------------------------------------------------------------- Update Information:
Added new lib. --------------------------------------------------------------------------------
================================================================================ libcorrect-0-1.20181010gitf5a28c7.fc30 (FEDORA-2019-dd6f8a4781) C library for Convolutional codes and Reed-Solomon -------------------------------------------------------------------------------- Update Information:
Adding new lib. --------------------------------------------------------------------------------
================================================================================ octave-jsonlab-1.9.8-1.fc30 (FEDORA-2019-cb499a8c45) A JSON/UBJSON/MessagePack encoder/decoder for MATLAB/Octave -------------------------------------------------------------------------------- Update Information:
Update to latest release -------------------------------------------------------------------------------- ChangeLog:
* Thu Oct 24 2019 Qianqian Fang fangqq@gmail.com - 1.9.8-1 - Update to 1.9.8 * Thu Jul 25 2019 Fedora Release Engineering releng@fedoraproject.org - 1.8-5 - Rebuilt for https://fedoraproject.org/wiki/Fedora_31_Mass_Rebuild * Sun Jun 16 2019 Orion Poplawski orion@nwra.com - 1.8-4 - Rebuild for octave 5.1 -------------------------------------------------------------------------------- References:
[ 1 ] Bug #1736366 - octave-jsonlab: FTBFS in Fedora rawhide/f31 https://bugzilla.redhat.com/show_bug.cgi?id=1736366 [ 2 ] Bug #1707144 - octave-jsonlab-1.9.8 is available https://bugzilla.redhat.com/show_bug.cgi?id=1707144 --------------------------------------------------------------------------------
================================================================================ perl-CPAN-Perl-Releases-4.18-1.fc30 (FEDORA-2019-fefb9634b1) Mapping Perl releases on CPAN to the location of the tarballs -------------------------------------------------------------------------------- Update Information:
Updated to the latest version -------------------------------------------------------------------------------- ChangeLog:
* Tue Oct 29 2019 Jitka Plesnikova jplesnik@redhat.com - 4.18-1 - 4.18 bump -------------------------------------------------------------------------------- References:
[ 1 ] Bug #1765952 - perl-CPAN-Perl-Releases-4.18 is available https://bugzilla.redhat.com/show_bug.cgi?id=1765952 --------------------------------------------------------------------------------
================================================================================ php-zendframework-zend-session-2.9.1-1.fc30 (FEDORA-2019-457b03dd8d) Zend Framework Session component -------------------------------------------------------------------------------- Update Information:
**Version 2.9.1** - 2019-10-28 **Fixed** - [#123](https://github.com/zendframework/zend-session/pull/123) fixes a bug preventing two first hash functions from `hash_algos()` (usually `md2` and `md4`) from being used in `SessionConfig::setHashFunction`. -------------------------------------------------------------------------------- ChangeLog:
* Tue Oct 29 2019 Remi Collet remi@remirepo.net - 2.9.1-1 - update to 2.9.1 --------------------------------------------------------------------------------
================================================================================ php-zendframework-zend-validator-2.12.2-1.fc30 (FEDORA-2019-07dc9f8474) Zend Framework Validator component -------------------------------------------------------------------------------- Update Information:
**Version 2.12.2** - 2019-10-29 **Fixed** - [#277](https://github.com/zendframework/zend-validator/pull/277) fixes `File\Hash` validator in case when the file hash contains only digits. - [#277](https://github.com/zendframework/zend-validator/pull/277) fixes `File\Hash` validator to match hash with the given hashing algorithm. -------------------------------------------------------------------------------- ChangeLog:
* Tue Oct 29 2019 Remi Collet remi@remirepo.net - 2.12.2-1 - update to 2.12.2 --------------------------------------------------------------------------------
================================================================================ pioneers-15.5-1.fc30 (FEDORA-2019-f9befb66f0) Turnbased board strategy game (colonize an island) -------------------------------------------------------------------------------- Update Information:
+Updated to 15.5 -------------------------------------------------------------------------------- ChangeLog:
* Mon Oct 28 2019 Avram Lubkin aviso@rockhopper.net - 15.5-1 +- Updated to 15.5 * Fri Jul 26 2019 Fedora Release Engineering releng@fedoraproject.org - 15.3-11 - Rebuilt for https://fedoraproject.org/wiki/Fedora_31_Mass_Rebuild --------------------------------------------------------------------------------
================================================================================ python-enlighten-1.4.0-1.fc30 (FEDORA-2019-a8fa5cad12) Enlighten Progress Bar -------------------------------------------------------------------------------- Update Information:
Update to 1.4.0 -------------------------------------------------------------------------------- ChangeLog:
* Tue Oct 29 2019 Avram Lubkin aviso@rockhopper.net - 1.4.0-1 - Update to 1.4.0 * Thu Oct 3 2019 Miro Hron��ok mhroncok@redhat.com - 1.3.0-4 - Rebuilt for Python 3.8.0rc1 (#1748018) * Mon Aug 19 2019 Miro Hron��ok mhroncok@redhat.com - 1.3.0-3 - Rebuilt for Python 3.8 * Fri Jul 26 2019 Fedora Release Engineering releng@fedoraproject.org - 1.3.0-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_31_Mass_Rebuild --------------------------------------------------------------------------------
================================================================================ python-fsleyes-0.31.2-1.fc30 (FEDORA-2019-df6f26de73) FSLeyes, the FSL image viewer -------------------------------------------------------------------------------- Update Information:
Update fsleyes and related dependencies to latest releases. -------------------------------------------------------------------------------- ChangeLog:
* Mon Oct 28 2019 Ankur Sinha <ankursinha AT fedoraproject DOT org> - 0.31.2-1 - Update to 0.31.2 -------------------------------------------------------------------------------- References:
[ 1 ] Bug #1759708 - python-fsleyes-0.31.2 is available https://bugzilla.redhat.com/show_bug.cgi?id=1759708 [ 2 ] Bug #1759624 - python-fslpy-2.6.2 is available https://bugzilla.redhat.com/show_bug.cgi?id=1759624 [ 3 ] Bug #1758610 - python-fsleyes-widgets-0.8.4 is available https://bugzilla.redhat.com/show_bug.cgi?id=1758610 [ 4 ] Bug #1758558 - python-fsleyes-props-1.6.7 is available https://bugzilla.redhat.com/show_bug.cgi?id=1758558 --------------------------------------------------------------------------------
================================================================================ python-fsleyes-props-1.6.7-1.fc30 (FEDORA-2019-df6f26de73) [wx]Python event programming framework -------------------------------------------------------------------------------- Update Information:
Update fsleyes and related dependencies to latest releases. -------------------------------------------------------------------------------- ChangeLog:
* Mon Oct 28 2019 Ankur Sinha <ankursinha AT fedoraproject DOT org> - 1.6.7-1 - Update to 1.6.7 - use conditional for unreliable tests * Mon Oct 28 2019 Ankur Sinha <ankursinha AT fedoraproject DOT org> - 1.6.6-2 - Remove python2 code from spec -------------------------------------------------------------------------------- References:
[ 1 ] Bug #1759708 - python-fsleyes-0.31.2 is available https://bugzilla.redhat.com/show_bug.cgi?id=1759708 [ 2 ] Bug #1759624 - python-fslpy-2.6.2 is available https://bugzilla.redhat.com/show_bug.cgi?id=1759624 [ 3 ] Bug #1758610 - python-fsleyes-widgets-0.8.4 is available https://bugzilla.redhat.com/show_bug.cgi?id=1758610 [ 4 ] Bug #1758558 - python-fsleyes-props-1.6.7 is available https://bugzilla.redhat.com/show_bug.cgi?id=1758558 --------------------------------------------------------------------------------
================================================================================ python-fsleyes-widgets-0.8.4-1.fc30 (FEDORA-2019-df6f26de73) A collection of custom wx widgets and utilities used by FSLeyes -------------------------------------------------------------------------------- Update Information:
Update fsleyes and related dependencies to latest releases. -------------------------------------------------------------------------------- ChangeLog:
* Mon Oct 28 2019 Ankur Sinha <ankursinha AT fedoraproject DOT org> - 0.8.4-1 - Update to 0.8.4 - Make tests conditional -------------------------------------------------------------------------------- References:
[ 1 ] Bug #1759708 - python-fsleyes-0.31.2 is available https://bugzilla.redhat.com/show_bug.cgi?id=1759708 [ 2 ] Bug #1759624 - python-fslpy-2.6.2 is available https://bugzilla.redhat.com/show_bug.cgi?id=1759624 [ 3 ] Bug #1758610 - python-fsleyes-widgets-0.8.4 is available https://bugzilla.redhat.com/show_bug.cgi?id=1758610 [ 4 ] Bug #1758558 - python-fsleyes-props-1.6.7 is available https://bugzilla.redhat.com/show_bug.cgi?id=1758558 --------------------------------------------------------------------------------
================================================================================ python-fslpy-2.6.2-1.fc30 (FEDORA-2019-df6f26de73) The FSL Python Library -------------------------------------------------------------------------------- Update Information:
Update fsleyes and related dependencies to latest releases. -------------------------------------------------------------------------------- ChangeLog:
* Mon Oct 28 2019 Ankur Sinha <ankursinha AT fedoraproject DOT org> - 2.6.2-1 - Update to 2.6.2 -------------------------------------------------------------------------------- References:
[ 1 ] Bug #1759708 - python-fsleyes-0.31.2 is available https://bugzilla.redhat.com/show_bug.cgi?id=1759708 [ 2 ] Bug #1759624 - python-fslpy-2.6.2 is available https://bugzilla.redhat.com/show_bug.cgi?id=1759624 [ 3 ] Bug #1758610 - python-fsleyes-widgets-0.8.4 is available https://bugzilla.redhat.com/show_bug.cgi?id=1758610 [ 4 ] Bug #1758558 - python-fsleyes-props-1.6.7 is available https://bugzilla.redhat.com/show_bug.cgi?id=1758558 --------------------------------------------------------------------------------
================================================================================ python-html2text-2019.9.26-2.fc30 (FEDORA-2019-a92355aba1) Convert HTML to Markdown-formatted text -------------------------------------------------------------------------------- Update Information:
Update to 2019.9.26 version python 3 only -------------------------------------------------------------------------------- ChangeLog:
* Tue Oct 29 2019 S��rgio Basto sergio@serjux.com - 2019.9.26-2 - Python3 only this version remove support for Python <= 3.4 * Tue Oct 29 2019 S��rgio Basto sergio@serjux.com - 2019.9.26-1 - Update to 2019.9.26 - Python3 only this version remove support for Python <= 3.4 * Mon Oct 21 2019 Miro Hron��ok mhroncok@redhat.com - 2019.8.11-2 - Do not bring Python 2 BuildRequires when not building the Python 2 package -------------------------------------------------------------------------------- References:
[ 1 ] Bug #1765768 - html2text: AttributeError: 'str' object has no attribute 'decode' https://bugzilla.redhat.com/show_bug.cgi?id=1765768 --------------------------------------------------------------------------------
================================================================================ python3-docs-3.7.5-1.fc30 (FEDORA-2019-b6ad19bbab) Documentation for the Python 3 programming language -------------------------------------------------------------------------------- Update Information:
Documentation update for Python 3.7.5. -------------------------------------------------------------------------------- ChangeLog:
* Tue Oct 29 2019 Miro Hron��ok mhroncok@redhat.com - 3.7.5-1 - Update to 3.7.5 * Fri Jul 26 2019 Fedora Release Engineering releng@fedoraproject.org - 3.7.4-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_31_Mass_Rebuild --------------------------------------------------------------------------------
================================================================================ python35-3.5.8-1.fc30 (FEDORA-2019-b06ec6159b) Version 3.5 of the Python programming language -------------------------------------------------------------------------------- Update Information:
Python 3.5 has now entered "security fixes only" mode, and as such the only changes since Python 3.5.4 are security fixes. https://www.python.org/downloads/release/python-358/ https://docs.python.org/3.5/whatsnew/changelog.html#python-3-5-8 Security fix for CVE-2019-9740, CVE-2019-10160, CVE-2019-16935, CVE-2019-18348 , CVE-2019-16056. -------------------------------------------------------------------------------- ChangeLog:
* Tue Oct 29 2019 Miro Hron��ok mhroncok@redhat.com - 3.5.8-1 - Update to 3.5.8 * Sat Oct 12 2019 Miro Hron��ok mhroncok@redhat.com - 3.5.8~rc2-1 - Update to 3.5.8rc2 * Mon Sep 9 2019 Miro Hron��ok mhroncok@redhat.com - 3.5.8~rc1-1 - Update to 3.5.8rc1 * Sat Aug 10 2019 Miro Hron��ok mhroncok@redhat.com - 3.5.7-4 - Build against OpenSSL 1.1.x, not 1.0.x * Fri Jul 26 2019 Fedora Release Engineering releng@fedoraproject.org - 3.5.7-3 - Rebuilt for https://fedoraproject.org/wiki/Fedora_31_Mass_Rebuild * Tue Apr 2 2019 Victor Stinner vstinner@redhat.com - 3.5.7-2 - Skip test_ssl and test_asyncio tests failing with OpenSSL 1.1.1 (rhbz#1685609) -------------------------------------------------------------------------------- References:
[ 1 ] Bug #1749839 - CVE-2019-16056 python: email.utils.parseaddr wrongly parses email addresses https://bugzilla.redhat.com/show_bug.cgi?id=1749839 [ 2 ] Bug #1727276 - CVE-2019-18348 python: CRLF injection via the host part of the url passed to urlopen() https://bugzilla.redhat.com/show_bug.cgi?id=1727276 [ 3 ] Bug #1763229 - CVE-2019-16935 python: XSS vulnerability in the documentation XML-RPC server in server_title field https://bugzilla.redhat.com/show_bug.cgi?id=1763229 [ 4 ] Bug #1718388 - CVE-2019-10160 python: regression of CVE-2019-9636 due to functional fix to allow port numbers in netloc https://bugzilla.redhat.com/show_bug.cgi?id=1718388 [ 5 ] Bug #1688169 - CVE-2019-9740 python: CRLF injection via the query part of the url passed to urlopen() https://bugzilla.redhat.com/show_bug.cgi?id=1688169 --------------------------------------------------------------------------------
================================================================================ snapd-2.42-2.fc30 (FEDORA-2019-db27fd82a8) A transactional software package manager -------------------------------------------------------------------------------- Update Information:
Update to snapd 2.42 -------------------------------------------------------------------------------- ChangeLog:
* Tue Oct 29 2019 Maciek Borzecki maciek.borzecki@gmail.com - 2.42-2 - Drop valgrind BR on ppc64le (RH#1766519) - Redirect stderr in dynamic executable check * Fri Oct 4 2019 Maciek Borzecki maciek.borzecki@gmail.com - 2.42-1 - Release snapd 2.42 to Fedora - Drop libtool patch - Drop cgroupv2 patch, changes are available in the release * Tue Oct 1 2019 Michael Vogt mvo@ubuntu.com - New upstream release 2.42 - tests: disable {contacts,calendar}-service tests on debian-sid - tests/main/snap-run: disable strace test cases on Arch - cmd/system-shutdown: include correct prototype for die - snap/naming: add test for hook name connect-plug-i2c - cmd/snap-confine: allow digits in hook names - gadget: do not fail the update when old gadget snap is missing bare content - tests: disable {contacts,calendar}-service tests on Arch Linux - tests: move "centos-7" to unstable systems - interfaces/docker-support,kubernetes-support: misc updates for strict k8s - packaging: remove obsolete usr.lib.snapd.snap-confine in postinst - tests: add test that ensures our snapfuse binary actually works - packaging: use snapfuse_ll to speed up snapfuse performance - usersession/userd: make sure to export DBus interfaces before requesting a name - data/selinux: allow snapd to issue sigkill to journalctl - store: download propagates options to delta download - wrappers: allow snaps to install icon theme icons - debug: state-inspect debugging utility - sandbox/cgroup: introduce cgroup wrappers package - snap-confine: fix return value checks for udev functions - cmd/model: output tweaks, add'l tests - wrappers/services: add ServicesEnableState + unit tests - tests: fix newline and wrong test name pointed out in previous PRs - tests: extend mount-ns test to handle mimics - run-checks, tests/main/go: allow gofmt checks to be skipped on 19.10 - tests/main/interfaces-{calendar,contacts}-service: disable on 19.10 - tests: part3 making tests work on ubuntu-core-18 - tests: fix interfaces-timeserver-control on 19.10 - overlord/snapstate: config revision code cleanup and extra tests - devicestate: allow remodel to different kernels - overlord,daemon: adjust startup timeout via EXTEND_TIMEOUT_USEC using an estimate - tests/main/many: increase kill-timeout to 5m - interfaces/kubernetes-support: allow systemd-run to ptrace read unconfined - snapstate: auto transition on experimental.snapd-snap=true - tests: retry checking until the written file on desktop-portal- filechooser - tests: unit test for a refresh failing on configure hook - tests: remove mount_id and parent_id from mount-ns test data - tests: move classic-ubuntu-core-transition* to nightly - tests/mountinfo-tool: proper formatting of opt_fields - overlord/configstate: special-case "null" in transaction Changes() - snap-confine: fallback gracefully on a cgroup v2 only system - tests: debian sid now ships new seccomp, adjust tests - tests: explicitly restore after using LXD - snapstate: make progress reporting less granular - bootloader: little kernel support - fixme: rename ubuntu*architectures to dpkg*architectures - tests: run dbus-launch inside a systemd unit - channel: introduce Resolve and ResolveLocked - tests: run failing tests on ubuntu eoan due to is now set as unstable - systemd: detach rather than unmount .mount units - cmd/snap-confine: add unit tests for sc_invocation, cleanup memory leaks in tests - boot,dirs,image: introduce boot.MakeBootable, use it in image instead of ad hoc code - cmd/snap-update-ns: clarify sharing comment - tests/overlord/snapstate: refactor for cleaner test failures - cmd/snap-update-ns: don't propagate detaching changes - interfaces: allow reading mutter Xauthority file - cmd/snap-confine: fix /snap duplication in legacy mode - tests: fix mountinfo-tool filtering when used with rewriting - seed,image,o/devicestate: extract seed loading to seed/seed16.go - many: pass the rootdir and options to bootloader.Find - tests: part5 making tests work on ubuntu-core-18 - cmd/snap-confine: keep track of snap instance name and the snap name - cmd: unify die() across C programs - tests: add functions to make an abstraction for the snaps - packaging/fedora, tests/lib/prepare-restore: helper tool for packing sources for RPM - cmd/snap: improve help and error msg for snapshot commands - hookstate/ctlcmd: fix snapctl set help message - cmd/snap: don't append / to snap name just because a dir exists - tests: support fastly-global.cdn.snapcraft.io url on proxy-no-core test - tests: add --quiet switch to retry-tool - tests: add unstable stage for travis execution - tests: disable interfaces-timeserver-control on 19.10 - tests: don't guess in is_classic_confinement_supported - boot, etc: simplify BootParticipant (etc) usage - tests: verify retry-tool not retrying missing commands - tests: rewrite "retry" command as retry-tool - tests: move debug section after restore - cmd/libsnap-confine-private, cmd/s-c: use constants for snap/instance name lengths - tests: measure behavior of the device cgroup - boot, bootloader, o/devicestate: boot env manip goes in boot - tests: enabling ubuntu 19.10-64 on spread.yaml - tests: fix ephemeral mount table in left over by prepare - tests: add version-tool for comparing versions - cmd/libsnap: make feature flag enum 1<<N style - many: refactor boot/boottest and move to bootloader/bootloadertest - tests/cross/go-build: use go list rather than shell trickery - HACKING.md: clarify where "make fmt" is needed - osutil: make flock test more robust - features, overlord: make parallel-installs exported, export flags on startup - overlord/devicestate: support the device service returning a stream of assertions - many: add snap model command, add /v2/model, /v2/model/serial REST APIs - debian: set GOCACHE dir during build to fix FTBFS on eoan - boot, etc.: refactor boot to have a lookup with different imps - many: add the start of Core 20 extensions support to the model assertion - overlord/snapstate: revert track-risk behavior change and validation on install - cmd/snap,image,seed: move image.ValidateSeed to seed.ValidateFromYaml - image,o/devicestate,seed: oops, make sure to clear seedtest helpers - tests/main/snap-info: update check.py for test-snapd-tools 2.0 - tests: moving tests to nightly suite - overlord/devicestate,seed: small step, introduce seed.LoadAssertions and use it from firstboot - snapstate: add comment to checkVersion vs strutil.VersionCompare - tests: add unit tests for cmd_whoami - tests: add debug section to interfaces-contacts-service - many: introduce package seed and seedtest - interfaces/bluez: enable communication between bluetoothd and meshd via dbus - cmd/snap: fix snap switch message - overlord/snapstate: check channel names on install - tests: check snap_daemon user and group on system-usernames- illegal test are not created - cmd/snap-confine: fix group and permission of .info files - gadget: do not error on gadget refreshes with multiple volumes - snap: use deterministic paths to find the built deb - tests: just build snapd commands on go-build test - tests: re-enable mount-ns test on classic - tests: rename fuse_support to fuse-support - tests: move restore-project-each code to existing function - tests: simplify interfaces-account-control test - i18n, vendor, packaging: drop github.com/ojii/gettext.go, use github.com/snapcore/go-gettext - tests: always say 'restore: |' - tests: new test to check the output after refreshing/reverting core - snapstate: validate all system-usernames before creating them - tests: fix system version check on listing test for external backend - tests: add check for snap_daemon user/group - tests: don't look for lxcfs in mountinfo - tests: adding support for arm devices on ubuntu-core-device-reg test - snap: explicitly forbid trying to parallel install from seed - tests: remove trailing spaces from shell scripts - tests: remove locally installed revisions of core - tests: fix removal of snaps on ubuntu-core - interfaces: support Tegra display drivers - tests: move interfaces-contacts-service to /tmp - interfaces/network-manager: allow using org.freedesktop.DBus.ObjectManager - tests: restore dpkg selections after upgrade-from-2.15 test - tests: pass --remove to userdel on core - snap/naming: simplify SnapSet somewhat - devicestate/firstboot: check for missing bases early - httputil: rework protocol error detection - tests: unmount fuse connections only if not initially mounted - snap: prevent duplicated snap name and snap files when parsing seed.yaml - tests: re-implement user tool in python - image: improve/tweak some warning/error messages - cmd/libsnap-confine-private: add checks for parallel instances feature flag - tests: wait_for_service shows status after actual first minute - sanity: report proper errror when fuse is needed but not available - snap/naming: introduce SnapRef, Snap, and SnapSet - image: support prepare-image --classic for snapd snap only imagesConsequently: - tests/main/mount-ns: account for clone_children in cpuset cgroup on 18.04 - many: merging asserts.Batch Precheck with CommitTo and other clarifications - devicestate: add missing test for remodeling possibly removing required flag - tests: use user-tool to remove test user in the non-home test - overlord/configstate: sort patch keys to have deterministic order with snap set - many: generalize assertstate.Batch to asserts.Batch, have assertstate.AddBatch - gadget, overlord/devicestate: rename Position/Layout - store, image, cmd: make 'snap download' leave partials - httputil: improve http2 PROTOCOL_ERROR detection - tests: add new "user-tool" helper and use in system-user tests - tests: clean up after NFS tests - ifacestate: optimize auto-connect by setting profiles once after all connects - hookstate/ctlcmd: snapctl unset command - tests: allow test user XDG_RUNTIME_DIR to phase out - tests: cleanup "snap_daemon" user in system-usernames-install- twice - cmd/snap-mgmt: set +x on startup - interfaces/wayland,x11: allow reading an Xwayland Xauth file - many: move channel parsing to snap/channel - check-pr-title.py: allow {} in pr prefix - tests: spam test logs less while waiting for systemd unit to stop - tests: remove redundant activation check for snapd.socket snapd.service - tests: trivial snapctl test cleanup - tests: ubuntu 18.10 removed from the google-sru backend on the spread.yaml - tests: add new cases into arch_test - tests: clean user and group for test system-usernames-install- twice - interfaces: k8s worker node updates - asserts: move Model to its own model.go - tests: unmount binfmt_misc on cleanup - tests: restore nsdelegate clobbered by LXD - cmd/snap: fix snap unset help string - tests: unmount fusectl after testing - cmd/snap: fix remote snap info for parallel installed snaps --------------------------------------------------------------------------------
================================================================================ system-config-printer-1.5.12-2.fc30 (FEDORA-2019-80ef0aec1c) A printer administration tool -------------------------------------------------------------------------------- Update Information:
1765915 - abrt in udev-configure-printer -------------------------------------------------------------------------------- ChangeLog:
* Tue Oct 29 2019 Zdenek Dohnal zdohnal@redhat.com - 1.5.12-2 - 1765915 - abrt in udev-configure-printer --------------------------------------------------------------------------------
================================================================================ toolbox-0.0.16-1.fc30 (FEDORA-2019-837a21f4ba) Unprivileged development environment -------------------------------------------------------------------------------- Update Information:
* Add a reset command * Document requirements for distro support * Don't use a toolbox container until after it has been configured * Drop the coloured heading from 'list' * Miscellaneous fixes to Bash completion * Remove the hidden --sudo option and the /etc/sudoers.d snippet * Try to migrate to a supported OCI runtime if 'podman start' suggests so * Unbreak 'run' if container lacks files that are redirected to the host -------------------------------------------------------------------------------- ChangeLog:
* Tue Oct 29 2019 Debarshi Ray rishi@fedoraproject.org - 0.0.16-1 - Update to 0.0.16 --------------------------------------------------------------------------------
================================================================================ whois-5.5.2-2.fc30 (FEDORA-2019-333bbac0dd) Improved WHOIS client -------------------------------------------------------------------------------- Update Information:
This release corrects replacing whois-mkpasswd package when upgrading from Fedora 29. -------------------------------------------------------------------------------- ChangeLog:
* Tue Oct 29 2019 Petr Pisar ppisar@redhat.com - 5.5.2-2 - Adjusts obsoletance for whois-mkpasswd-5.5.2 (bug #1684112) -------------------------------------------------------------------------------- References:
[ 1 ] Bug #1684112 - unable to upgrade to F30 due to broken package dependency https://bugzilla.redhat.com/show_bug.cgi?id=1684112 --------------------------------------------------------------------------------
================================================================================ xapian-core-1.4.13-2.fc30 (FEDORA-2019-2ad42d6ebf) The Xapian Probabilistic Information Retrieval Library -------------------------------------------------------------------------------- Update Information:
Upstream fix for pruning under a positional check (rhbz 1766219) -------------------------------------------------------------------------------- ChangeLog:
* Tue Oct 29 2019 Peter Robinson pbrobinson@gmail.com - 1.4.13-2 - Upstream fix for pruning under a positional check (rhbz 1766219) -------------------------------------------------------------------------------- References:
[ 1 ] Bug #1766219 - Upgrading to xapian-core-1.4.13-1.fc30 breaks notmuch https://bugzilla.redhat.com/show_bug.cgi?id=1766219 --------------------------------------------------------------------------------
================================================================================ zabbix-4.0.13-1.fc30 (FEDORA-2019-e034c235a4) Open-source monitoring solution for your IT infrastructure -------------------------------------------------------------------------------- Update Information:
* https://www.zabbix.com/rn/rn4.0.12 * https://www.zabbix.com/rn/rn4.0.13 * https://www.zabbix.com/documentation/4.0/manual/installation/upgrade_notes_4... * https://www.zabbix.com/documentation/4.0/manual/api/changes_4.0 -------------------------------------------------------------------------------- ChangeLog:
* Tue Oct 29 2019 Volker Froehlich volker27@gmx.at - 1:4.0.13-1 - New upstream release --------------------------------------------------------------------------------
================================================================================ zlib-1.2.11-19.fc30 (FEDORA-2019-839f4316e6) The compression and decompression library -------------------------------------------------------------------------------- Update Information:
- Added -DDFLTCC parameter to configure to enable Z hardware-accelerated deflate for s390x architectures -------------------------------------------------------------------------------- ChangeLog:
* Tue Oct 29 2019 Ondrej Dubaj odubaj@redhat.com - 1.2.11-19 - Added -DDFLTCC parameter to configure to enable - Z hardware-accelerated deflate for s390x architectures --------------------------------------------------------------------------------