The following Fedora EPEL 9 Security updates need testing: Age URL 3 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2024-d996eeff0f rust-routinator-0.13.2-1.el9 The following builds have been pushed to Fedora EPEL 9 updates-testing Pencil2D-0.6.6-24.el9 baresip-3.10.0-1.el9 bird-2.15-1.el9 chromium-122.0.6261.111-1.el9 ganglia-3.7.2-48.el9 hardinfo2-2.0.15-1.el9 libre-3.10.0-1.el9 pythoncapi-compat-0^20240309git7539c7f-1.el9 rust-askalono-0.4.6-7.el9 rust-askalono-cli-0.4.6-8.el9 rust-structopt-derive0.2-0.2.18-14.el9 rust-structopt0.2-0.2.18-16.el9 rust-yaml-rust0.3-0.3.5-26.el9 Details about builds: ================================================================================ Pencil2D-0.6.6-24.el9 (FEDORA-EPEL-2024-fff4203018) Create traditional hand-drawn animation using both bitmap and vector graphics -------------------------------------------------------------------------------- Update Information: Add developer ID to AppData XML -------------------------------------------------------------------------------- ChangeLog: * Sat Mar 9 2024 Benjamin A. Beasley <code@xxxxxxxxxxxxxxxxxx> - 0.6.6-24 - Add developer ID to AppData XML; fix FTBFS with appstream 1.0.2 * Sat Mar 9 2024 Benjamin A. Beasley <code@xxxxxxxxxxxxxxxxxx> - 0.6.6-23 - Add qt5-qtsvg dependency (fix blank/missing icons) * Sat Mar 9 2024 Benjamin A. Beasley <code@xxxxxxxxxxxxxxxxxx> - 0.6.6-22 - Ask appstreamcli to explain validation findings * Sat Mar 9 2024 Benjamin A. Beasley <code@xxxxxxxxxxxxxxxxxx> - 0.6.6-21 - Correct appstreamcli invocation (--nonet no longer works) -------------------------------------------------------------------------------- ================================================================================ baresip-3.10.0-1.el9 (FEDORA-EPEL-2024-ae2db443c3) Modular SIP user-agent with audio and video support -------------------------------------------------------------------------------- Update Information: Baresip v3.10.0 (2024-03-06) cmake: use default value for CMAKE_C_EXTENSIONS cmake: add /usr/{local,}/include/re and /usr/{local,}/lib{64,} to FindRE.cmake test/main: fix NULL pointer arg on err ci: add Fedora workflow to avoid e.g. rpath issues mediatrack/start: add audio_decoder_set config: support distribution-specific/default CA paths readme: cosmetic changes ci/fedora: fix dependency config: add default CA path for Android transp,tls: add TLS client verification account,message,ua: secure incoming SIP MESSAGEs aufile: avoid race condition in case of fast destruction aufile: join thread if write fails video: add video_req_keyframe api call: start streams in sipsess_estab_handler webrtc: add av1 codec cmake: fix relative source dir find paths echo: fix re_snprintf pointer ARG cmake: Add include PATH so that GST is found also on Debian 11 call: improve glare handling call: set estdir in call_set_media_direction audio,aur: start audio player after early-video ctrl_dbus: add busctl example to module documentation debian: bump to v3.9.0 release v3.10.0 libre v3.10.0 (2024-03-06) transp: deref qent only if qentp is not set sipsess: fix doxygen comments aufile: fix doxygen comment ci/codeql: bump action v3 misc: text2pcap helpers (RTP/RTCP capturing) ci/mingw: bump upload/download-artifact and cache versions transp,tls: add TLS client verification fmt/text2pcap: cleanup ci/android: cache openssl build ci/misc: fix double push/pull runs fmt/text2pcap: fix coverity return value warning sipsess/listen: improve glare handling conf: add conf_get_i32 debian: bump version v3.9.0 sip/transp: reset tcp timeout on websocket receive release v3.10.0 -------------------------------------------------------------------------------- ChangeLog: * Sun Mar 10 2024 Robert Scheck <robert@xxxxxxxxxxxxxxxxx> 3.10.0-1 - Upgrade to 3.10.0 (#2268424) * Wed Feb 7 2024 Pete Walter <pwalter@xxxxxxxxxxxxxxxxx> - 3.9.0-2 - Rebuild for libvpx 1.14.x -------------------------------------------------------------------------------- References: [ 1 ] Bug #2268236 - libre-3.10.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=2268236 [ 2 ] Bug #2268424 - baresip-3.10.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=2268424 -------------------------------------------------------------------------------- ================================================================================ bird-2.15-1.el9 (FEDORA-EPEL-2024-904b5b9a19) BIRD Internet Routing Daemon -------------------------------------------------------------------------------- Update Information: BIRD 2.15 (2024-03-10) BGP: Send hold timer BGP: New options to specify required BGP capabilities BFD: Improvements to show bfd sessions command RPKI: New local address configuration option Linux: Support for more route attributes, including TCP congestion control algorithm Support for UDP logging Static routes can have both nexthop and interface specified Completion of command options in BIRD client Many bugfixes and improvements -------------------------------------------------------------------------------- ChangeLog: * Sun Mar 10 2024 Robert Scheck <robert@xxxxxxxxxxxxxxxxx> - 2.15-1 - Upgrade to 2.15 (#2268900) * Tue Jan 23 2024 Fedora Release Engineering <releng@xxxxxxxxxxxxxxxxx> - 2.14-3 - Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild * Fri Jan 19 2024 Fedora Release Engineering <releng@xxxxxxxxxxxxxxxxx> - 2.14-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild -------------------------------------------------------------------------------- References: [ 1 ] Bug #2268900 - bird-2.15 is available https://bugzilla.redhat.com/show_bug.cgi?id=2268900 -------------------------------------------------------------------------------- ================================================================================ chromium-122.0.6261.111-1.el9 (FEDORA-EPEL-2024-c8094838a7) A WebKit (Blink) powered web browser that Google doesn't want you to use -------------------------------------------------------------------------------- Update Information: Upstream security release 122.0.6261.111 * High CVE-2024-2173: Out of bounds memory access in V8 * High CVE-2024-2174: Inappropriate implementation in V8 * High CVE-2024-2176: Use after free in FedCM -------------------------------------------------------------------------------- ChangeLog: * Wed Mar 6 2024 Than Ngo <than@xxxxxxxxxx> - 122.0.6261.111-1 - upstream security release 122.0.6261.111 * High CVE-2024-2173: Out of bounds memory access in V8 * High CVE-2024-2174: Inappropriate implementation in V8 * High CVE-2024-2176: Use after free in FedCM -------------------------------------------------------------------------------- References: [ 1 ] Bug #2268541 - CVE-2024-2173 CVE-2024-2174 CVE-2024-2176 chromium: various flaws [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2268541 -------------------------------------------------------------------------------- ================================================================================ ganglia-3.7.2-48.el9 (FEDORA-EPEL-2024-817acb9184) Distributed Monitoring System -------------------------------------------------------------------------------- Update Information: Update to latest version available in upstream git repo Update to new version of ganglia web improving compatibility with PHP8. -------------------------------------------------------------------------------- ChangeLog: * Sun Mar 10 2024 Terje Rosten <terje.rosten@xxxxxxx> - 3.7.2-48 - Update to commit 185ab6b * Sun Mar 3 2024 Terje Rosten <terje.rosten@xxxxxxx> - 3.7.2-47 - Add more PHP8 patches -------------------------------------------------------------------------------- References: [ 1 ] Bug #2180500 - ganglia-web not working due to changes in PHP 8 https://bugzilla.redhat.com/show_bug.cgi?id=2180500 [ 2 ] Bug #2257251 - Regression: machine_type_func() returns uninitialized local variable value on aarch64 https://bugzilla.redhat.com/show_bug.cgi?id=2257251 -------------------------------------------------------------------------------- ================================================================================ hardinfo2-2.0.15-1.el9 (FEDORA-EPEL-2024-e080b91480) System Information and Benchmark for Linux Systems -------------------------------------------------------------------------------- Update Information: update -------------------------------------------------------------------------------- ChangeLog: * Sun Mar 10 2024 topazus <topazus@xxxxxxxxxxx> - 2.0.15-1 - initial import -------------------------------------------------------------------------------- ================================================================================ libre-3.10.0-1.el9 (FEDORA-EPEL-2024-ae2db443c3) Generic library for real-time communications -------------------------------------------------------------------------------- Update Information: Baresip v3.10.0 (2024-03-06) cmake: use default value for CMAKE_C_EXTENSIONS cmake: add /usr/{local,}/include/re and /usr/{local,}/lib{64,} to FindRE.cmake test/main: fix NULL pointer arg on err ci: add Fedora workflow to avoid e.g. rpath issues mediatrack/start: add audio_decoder_set config: support distribution-specific/default CA paths readme: cosmetic changes ci/fedora: fix dependency config: add default CA path for Android transp,tls: add TLS client verification account,message,ua: secure incoming SIP MESSAGEs aufile: avoid race condition in case of fast destruction aufile: join thread if write fails video: add video_req_keyframe api call: start streams in sipsess_estab_handler webrtc: add av1 codec cmake: fix relative source dir find paths echo: fix re_snprintf pointer ARG cmake: Add include PATH so that GST is found also on Debian 11 call: improve glare handling call: set estdir in call_set_media_direction audio,aur: start audio player after early-video ctrl_dbus: add busctl example to module documentation debian: bump to v3.9.0 release v3.10.0 libre v3.10.0 (2024-03-06) transp: deref qent only if qentp is not set sipsess: fix doxygen comments aufile: fix doxygen comment ci/codeql: bump action v3 misc: text2pcap helpers (RTP/RTCP capturing) ci/mingw: bump upload/download-artifact and cache versions transp,tls: add TLS client verification fmt/text2pcap: cleanup ci/android: cache openssl build ci/misc: fix double push/pull runs fmt/text2pcap: fix coverity return value warning sipsess/listen: improve glare handling conf: add conf_get_i32 debian: bump version v3.9.0 sip/transp: reset tcp timeout on websocket receive release v3.10.0 -------------------------------------------------------------------------------- ChangeLog: * Sun Mar 10 2024 Robert Scheck <robert@xxxxxxxxxxxxxxxxx> 3.10.0-1 - Upgrade to 3.10.0 (#2268236) -------------------------------------------------------------------------------- References: [ 1 ] Bug #2268236 - libre-3.10.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=2268236 [ 2 ] Bug #2268424 - baresip-3.10.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=2268424 -------------------------------------------------------------------------------- ================================================================================ pythoncapi-compat-0^20240309git7539c7f-1.el9 (FEDORA-EPEL-2024-1e0f163141) Python C API compatibility -------------------------------------------------------------------------------- Update Information: Update to 0^20240309git7539c7f Add hash constants: PyHASH_BITS, PyHASH_IMAG, PyHASH_INF, PyHASH_MODULUS -------------------------------------------------------------------------------- ChangeLog: * Sun Mar 10 2024 Benjamin A. Beasley <code@xxxxxxxxxxxxxxxxxx> - 0^20240309git7539c7f-1 - Update to 0^20240309git7539c7f - Add hash constants: `PyHASH_BITS`, `PyHASH_IMAG`, `PyHASH_INF`, `PyHASH_MODULUS` -------------------------------------------------------------------------------- ================================================================================ rust-askalono-0.4.6-7.el9 (FEDORA-EPEL-2024-b0b14a67cc) Library to detect the contents of license files -------------------------------------------------------------------------------- Update Information: Initial import of askalono-cli for EPEL 9. -------------------------------------------------------------------------------- ChangeLog: * Fri Nov 24 2023 Fabio Valentini <decathorpe@xxxxxxxxx> - 0.4.6-7 - Regenerate with rust2rpm v25 * Fri Jul 21 2023 Fedora Release Engineering <releng@xxxxxxxxxxxxxxxxx> - 0.4.6-6 - Rebuilt for https://fedoraproject.org/wiki/Fedora_39_Mass_Rebuild * Thu Feb 23 2023 Fabio Valentini <decathorpe@xxxxxxxxx> - 0.4.6-5 - Bump to zstd 0.12 * Fri Feb 17 2023 Michel Alexandre Salim <salimma@xxxxxxxxxxxxxxxxx> - 0.4.6-4 - Add missing patch * Fri Feb 17 2023 Michel Alexandre Salim <salimma@xxxxxxxxxxxxxxxxx> - 0.4.6-3 - Rebuild for rmp-serde 1.x * Fri Jan 20 2023 Fedora Release Engineering <releng@xxxxxxxxxxxxxxxxx> - 0.4.6-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_38_Mass_Rebuild * Sat Aug 6 2022 Fabio Valentini <decathorpe@xxxxxxxxx> - 0.4.6-1 - Update to version 0.4.6; Fixes RHBZ#2073720 * Sat Jul 23 2022 Fedora Release Engineering <releng@xxxxxxxxxxxxxxxxx> - 0.4.4-4 - Rebuilt for https://fedoraproject.org/wiki/Fedora_37_Mass_Rebuild * Thu Apr 14 2022 Fabio Valentini <decathorpe@xxxxxxxxx> - 0.4.4-3 - Bump zstd from 0.9 to 0.10 * Fri Jan 21 2022 Fedora Release Engineering <releng@xxxxxxxxxxxxxxxxx> - 0.4.4-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_36_Mass_Rebuild * Wed Dec 15 2021 Fabio Valentini <decathorpe@xxxxxxxxx> - 0.4.4-1 - Update to version 0.4.4; Fixes RHBZ#2025328 -------------------------------------------------------------------------------- ================================================================================ rust-askalono-cli-0.4.6-8.el9 (FEDORA-EPEL-2024-b0b14a67cc) Tool to detect the contents of license files -------------------------------------------------------------------------------- Update Information: Initial import of askalono-cli for EPEL 9. -------------------------------------------------------------------------------- ChangeLog: * Sun Mar 10 2024 Fabio Valentini <decathorpe@xxxxxxxxx> - 0.4.6-8 - Revert spdx-license-list cache to v3.22 * Tue Mar 5 2024 Maxwell G <maxwell@xxxxxxx> - 0.4.6-7 - Update spdx-license-list cache to 3.23 * Fri Jan 26 2024 Fedora Release Engineering <releng@xxxxxxxxxxxxxxxxx> - 0.4.6-6 - Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild * Fri Nov 24 2023 Fabio Valentini <decathorpe@xxxxxxxxx> - 0.4.6-5 - Update included SPDX license-list-data to version 3.22 * Fri Jul 21 2023 Fedora Release Engineering <releng@xxxxxxxxxxxxxxxxx> - 0.4.6-4 - Rebuilt for https://fedoraproject.org/wiki/Fedora_39_Mass_Rebuild * Sat Feb 4 2023 Fabio Valentini <decathorpe@xxxxxxxxx> - 0.4.6-3 - Rebuild for fixed frame pointer compiler flags in Rust RPM macros * Fri Jan 20 2023 Fedora Release Engineering <releng@xxxxxxxxxxxxxxxxx> - 0.4.6-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_38_Mass_Rebuild * Sat Aug 6 2022 Fabio Valentini <decathorpe@xxxxxxxxx> - 0.4.6-1 - Update to version 0.4.6; Fixes RHBZ#2073721 * Sat Jul 23 2022 Fedora Release Engineering <releng@xxxxxxxxxxxxxxxxx> - 0.4.4-5 - Rebuilt for https://fedoraproject.org/wiki/Fedora_37_Mass_Rebuild -------------------------------------------------------------------------------- ================================================================================ rust-structopt-derive0.2-0.2.18-14.el9 (FEDORA-EPEL-2024-b0b14a67cc) Parse command line argument by defining a struct, derive crate -------------------------------------------------------------------------------- Update Information: Initial import of askalono-cli for EPEL 9. -------------------------------------------------------------------------------- ChangeLog: * Sat Jan 27 2024 Fedora Release Engineering <releng@xxxxxxxxxxxxxxxxx> - 0.2.18-14 - Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild * Fri Jul 21 2023 Fedora Release Engineering <releng@xxxxxxxxxxxxxxxxx> - 0.2.18-13 - Rebuilt for https://fedoraproject.org/wiki/Fedora_39_Mass_Rebuild * Fri Apr 14 2023 Fabio Valentini <decathorpe@xxxxxxxxx> - 0.2.18-12 - Regenerate with rust2rpm v24 * Sat Jan 21 2023 Fedora Release Engineering <releng@xxxxxxxxxxxxxxxxx> - 0.2.18-9 - Rebuilt for https://fedoraproject.org/wiki/Fedora_38_Mass_Rebuild * Sat Jul 23 2022 Fedora Release Engineering <releng@xxxxxxxxxxxxxxxxx> - 0.2.18-8 - Rebuilt for https://fedoraproject.org/wiki/Fedora_37_Mass_Rebuild -------------------------------------------------------------------------------- ================================================================================ rust-structopt0.2-0.2.18-16.el9 (FEDORA-EPEL-2024-b0b14a67cc) Parse command line argument by defining a struct -------------------------------------------------------------------------------- Update Information: Initial import of askalono-cli for EPEL 9. -------------------------------------------------------------------------------- ChangeLog: * Sat Jan 27 2024 Fedora Release Engineering <releng@xxxxxxxxxxxxxxxxx> - 0.2.18-16 - Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild * Fri Jul 21 2023 Fedora Release Engineering <releng@xxxxxxxxxxxxxxxxx> - 0.2.18-15 - Rebuilt for https://fedoraproject.org/wiki/Fedora_39_Mass_Rebuild * Thu May 18 2023 Fabio Valentini <decathorpe@xxxxxxxxx> - 0.2.18-14 - Regenerate with rust2rpm v24 * Sat Jan 21 2023 Fedora Release Engineering <releng@xxxxxxxxxxxxxxxxx> - 0.2.18-11 - Rebuilt for https://fedoraproject.org/wiki/Fedora_38_Mass_Rebuild * Sat Jul 23 2022 Fedora Release Engineering <releng@xxxxxxxxxxxxxxxxx> - 0.2.18-10 - Rebuilt for https://fedoraproject.org/wiki/Fedora_37_Mass_Rebuild -------------------------------------------------------------------------------- ================================================================================ rust-yaml-rust0.3-0.3.5-26.el9 (FEDORA-EPEL-2024-b0b14a67cc) YAML 1.2 parser for rust -------------------------------------------------------------------------------- Update Information: Initial import of askalono-cli for EPEL 9. -------------------------------------------------------------------------------- ChangeLog: * Sat Jan 27 2024 Fedora Release Engineering <releng@xxxxxxxxxxxxxxxxx> - 0.3.5-26 - Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild * Sat Jul 22 2023 Fedora Release Engineering <releng@xxxxxxxxxxxxxxxxx> - 0.3.5-25 - Rebuilt for https://fedoraproject.org/wiki/Fedora_39_Mass_Rebuild * Tue May 16 2023 Fabio Valentini <decathorpe@xxxxxxxxx> - 0.3.5-24 - Regenerate with rust2rpm v24 * Sat Jan 21 2023 Fedora Release Engineering <releng@xxxxxxxxxxxxxxxxx> - 0.3.5-22 - Rebuilt for https://fedoraproject.org/wiki/Fedora_38_Mass_Rebuild * Sat Jul 23 2022 Fedora Release Engineering <releng@xxxxxxxxxxxxxxxxx> - 0.3.5-21 - Rebuilt for https://fedoraproject.org/wiki/Fedora_37_Mass_Rebuild -------------------------------------------------------------------------------- -- _______________________________________________ epel-devel mailing list -- epel-devel@xxxxxxxxxxxxxxxxxxxxxxx To unsubscribe send an email to epel-devel-leave@xxxxxxxxxxxxxxxxxxxxxxx Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/epel-devel@xxxxxxxxxxxxxxxxxxxxxxx Do not reply to spam, report it: https://pagure.io/fedora-infrastructure/new_issue