The following Fedora 20 Security updates need testing: Age URL 67 https://admin.fedoraproject.org/updates/FEDORA-2013-23636/rubygem-actionpack-4.0.0-2.fc20 59 https://admin.fedoraproject.org/updates/FEDORA-2013-24018/varnish-3.0.5-1.fc20 41 https://admin.fedoraproject.org/updates/FEDORA-2014-0792/libinfinity-0.5.5-1.fc20 27 https://admin.fedoraproject.org/updates/FEDORA-2014-1742/quassel-0.9.2-1.fc20 15 https://admin.fedoraproject.org/updates/FEDORA-2014-2221/NetworkManager-ssh-0.9.2-0.2.20140209git46247c2.fc20 13 https://admin.fedoraproject.org/updates/FEDORA-2014-2264/python-tahrir-0.5.1-1.fc20 13 https://admin.fedoraproject.org/updates/FEDORA-2014-2263/python-tahrir-0.5.2-1.fc20 11 https://admin.fedoraproject.org/updates/FEDORA-2014-2452/augeas-1.2.0-1.fc20 10 https://admin.fedoraproject.org/updates/FEDORA-2014-2562/drupal7-ctools-1.4-1.fc20 9 https://admin.fedoraproject.org/updates/FEDORA-2014-2611/drupal6-image_resize_filter-1.14-1.fc20 8 https://admin.fedoraproject.org/updates/FEDORA-2014-2648/drupal6-filefield-3.12-1.fc20 6 https://admin.fedoraproject.org/updates/FEDORA-2014-2693/openstack-glance-2013.2.2-1.fc20 5 https://admin.fedoraproject.org/updates/FEDORA-2014-2751/zabbix-2.0.11-2.fc20 3 https://admin.fedoraproject.org/updates/FEDORA-2014-2802/xen-4.3.2-1.fc20 3 https://admin.fedoraproject.org/updates/FEDORA-2014-2875/oath-toolkit-2.4.1-3.fc20 3 https://admin.fedoraproject.org/updates/FEDORA-2014-2804/easy-rsa-2.2.2-1.fc20 3 https://admin.fedoraproject.org/updates/FEDORA-2014-2864/libvirt-1.1.3.4-1.fc20 0 https://admin.fedoraproject.org/updates/FEDORA-2014-3054/python-swiftclient-2.0.2-1.fc20 0 https://admin.fedoraproject.org/updates/FEDORA-2014-2999/perl-CGI-Application-4.50-9.fc20 The following Fedora 20 Critical Path updates have yet to be approved: Age URL 104 https://admin.fedoraproject.org/updates/FEDORA-2013-21163/libproxy-0.4.11-8.fc20 35 https://admin.fedoraproject.org/updates/FEDORA-2014-1197/colord-1.1.6-1.fc20 3 https://admin.fedoraproject.org/updates/FEDORA-2014-2834/evolution-data-server-3.10.4-2.fc20 3 https://admin.fedoraproject.org/updates/FEDORA-2014-2801/selinux-policy-3.12.1-126.fc20 2 https://admin.fedoraproject.org/updates/FEDORA-2014-2924/keyutils-1.5.9-1.fc20 0 https://admin.fedoraproject.org/updates/FEDORA-2014-3048/NetworkManager-0.9.9.0-31.git20131003.fc20 0 https://admin.fedoraproject.org/updates/FEDORA-2014-3046/hawkey-0.4.11-1.fc20 0 https://admin.fedoraproject.org/updates/FEDORA-2014-3065/langtable-0.0.24-1.fc20 The following builds have been pushed to Fedora 20 updates-testing NetworkManager-0.9.9.0-31.git20131003.fc20 bind-dyndb-ldap-4.1-1.fc20 csdiff-1.0.2-2.fc20 ed-1.10-1.fc20 guichan-0.8.2-7.fc20 hawkey-0.4.11-1.fc20 js-json-20140204git3d7767b-3.fc20 json4s-3.2.7-1.fc20 kde-connect-0.5-1.fc20 langtable-0.0.24-1.fc20 libxmp-4.2.4-1.fc20 nodejs-css-parse-1.7.0-2.fc20 nodejs-grunt-contrib-concat-0.3.0-1.fc20 nodejs-stylus-0.42.2-1.fc20 nodeunit-0.8.6-2.fc20 openlmi-scripts-0.2.7-0.fc20 os-apply-config-0.1.12-5.fc20 os-collect-config-0.1.11-4.fc20 os-refresh-config-0.0.8-3.fc20 owfs-2.9p2-1.fc20 perl-DBD-ODBC-1.47-2.fc20 python-glue-0.4.1-1.fc20 python-swiftclient-2.0.2-1.fc20 pywbem-0.7.0-25.20131121svn626.fc20 rubygem-awesome_spawn-1.1.1-1.fc20 rubygem-redis-3.0.7-1.fc20 tcllib-1.15-3.fc20 xfdashboard-0.1.4-1.fc20 Details about builds: ================================================================================ NetworkManager-0.9.9.0-31.git20131003.fc20 (FEDORA-2014-3048) Network connection manager and user applications -------------------------------------------------------------------------------- Update Information: Backport new dbus client bindings to F20 -------------------------------------------------------------------------------- ChangeLog: * Mon Feb 24 2014 Thomas Haller <thaller@xxxxxxxxxx> - 0.9.9.0-31.git20131003 - fix timestamps for addresses received from kernel/platform - improve platform to_string functions to show all address/route paramters - libnm-util: add dbus properties to help out bindings (bgo #715186) -------------------------------------------------------------------------------- ================================================================================ bind-dyndb-ldap-4.1-1.fc20 (FEDORA-2014-3033) LDAP back-end plug-in for BIND -------------------------------------------------------------------------------- Update Information: Update to upstream version 4.1. -------------------------------------------------------------------------------- ChangeLog: * Mon Feb 24 2014 Petr Spacek <pspacek redhat com> 4.1-1 - update to 4.1 -------------------------------------------------------------------------------- ================================================================================ csdiff-1.0.2-2.fc20 (FEDORA-2014-3062) Non-interactive tools for processing code scan results in plain-text -------------------------------------------------------------------------------- Update Information: initial packaging -------------------------------------------------------------------------------- References: [ 1 ] Bug #1066027 - Review Request: csdiff - Non-interactive tools for processing code scan results in plain-text https://bugzilla.redhat.com/show_bug.cgi?id=1066027 -------------------------------------------------------------------------------- ================================================================================ ed-1.10-1.fc20 (FEDORA-2014-3069) The GNU line editor -------------------------------------------------------------------------------- Update Information: update to upstream version 1.10 -------------------------------------------------------------------------------- ChangeLog: * Mon Feb 24 2014 Karsten Hopp <karsten@xxxxxxxxxx> 1.10-1 - update to 1.10 -------------------------------------------------------------------------------- References: [ 1 ] Bug #976977 - ed-1.10 is available https://bugzilla.redhat.com/show_bug.cgi?id=976977 -------------------------------------------------------------------------------- ================================================================================ guichan-0.8.2-7.fc20 (FEDORA-2014-3043) Portable C++ GUI library for games using Allegro, SDL and OpenGL -------------------------------------------------------------------------------- Update Information: Support for aarch64. -------------------------------------------------------------------------------- ChangeLog: * Mon Feb 24 2014 Jon Ciesla <limburgher@xxxxxxxxx> - 0.8.2-7 - Run autoreconf to support aarch64, BZ 925528. -------------------------------------------------------------------------------- References: [ 1 ] Bug #925528 - guichan: Does not support aarch64 in f19 and rawhide https://bugzilla.redhat.com/show_bug.cgi?id=925528 -------------------------------------------------------------------------------- ================================================================================ hawkey-0.4.11-1.fc20 (FEDORA-2014-3046) Library providing simplified C and Python API to libsolv -------------------------------------------------------------------------------- Update Information: - Rebuilt. - Rebuilt. -------------------------------------------------------------------------------- ChangeLog: * Mon Feb 24 2014 Aleš Kozumplik <akozumpl@xxxxxxxxxx> - 0.4.11-1 - fixed typos in tutorial-py.rst (Jan Silhan) - added glob pattern search for arch to nevra_possibilities_real (RhBug:1048788) (Jan Silhan) - Left behind references to README.md from 3b47a13. (Ales Kozumplik) - Add Radek to AUTHORS. (Ales Kozumplik) - update the README. (Ales Kozumplik) - sack: write_*() should also check fclose(). (Ales Kozumplik) -------------------------------------------------------------------------------- References: [ 1 ] Bug #1048788 - [abrt] dnf: __init__.py:183:install:ArchException: Used arch is unknown. https://bugzilla.redhat.com/show_bug.cgi?id=1048788 [ 2 ] Bug #1062703 - hy_package_get_files() does not return files for cmdline package https://bugzilla.redhat.com/show_bug.cgi?id=1062703 [ 3 ] Bug #1047087 - make the creation of the .solv files more atomic https://bugzilla.redhat.com/show_bug.cgi?id=1047087 [ 4 ] Bug #1064459 - sigsegv when argument to logging contains an "%s" https://bugzilla.redhat.com/show_bug.cgi?id=1064459 -------------------------------------------------------------------------------- ================================================================================ js-json-20140204git3d7767b-3.fc20 (FEDORA-2014-3031) An implementation of JSON encoders/decoders in JavaScript -------------------------------------------------------------------------------- Update Information: Initial package. -------------------------------------------------------------------------------- References: [ 1 ] Bug #1068937 - Review Request: js-json - An implementation of JSON encoders/decoders in JavaScript https://bugzilla.redhat.com/show_bug.cgi?id=1068937 -------------------------------------------------------------------------------- ================================================================================ json4s-3.2.7-1.fc20 (FEDORA-2014-3045) Common AST for Scala JSON parsers -------------------------------------------------------------------------------- Update Information: Initial package. -------------------------------------------------------------------------------- References: [ 1 ] Bug #1067664 - Review Request: json4s - unified AST for Scala JSON parsers https://bugzilla.redhat.com/show_bug.cgi?id=1067664 -------------------------------------------------------------------------------- ================================================================================ kde-connect-0.5-1.fc20 (FEDORA-2014-3061) KDE Connect client for communication with smartphones -------------------------------------------------------------------------------- Update Information: New release -------------------------------------------------------------------------------- ChangeLog: -------------------------------------------------------------------------------- ================================================================================ langtable-0.0.24-1.fc20 (FEDORA-2014-3065) Guessing reasonable defaults for locale, keyboard layout, territory, and language. -------------------------------------------------------------------------------- Update Information: Fall back to returning untranslated timezone id if translation for the requested language does not exist (Resolves: rhbz#1032848) -------------------------------------------------------------------------------- ChangeLog: * Mon Feb 24 2014 Mike FABIAN <mfabian@xxxxxxxxxx> - 0.0.24-1 - mark Bengali (bd) and its Probhat variant layout as not ASCII-capable (by Adam Williamson) - Also validate timezones.xml and timezoneidparts.xml in .spec file - List list_inputmethods() as public API - Fall back to returning untranslated timezone id if translation for the requested language does not exist (Resolves: rhbz#1032848) -------------------------------------------------------------------------------- References: [ 1 ] Bug #1032848 - All timezone city names appear blank when installing in Asturian (20 Final TC2 desktop live) https://bugzilla.redhat.com/show_bug.cgi?id=1032848 -------------------------------------------------------------------------------- ================================================================================ libxmp-4.2.4-1.fc20 (FEDORA-2014-3039) A multi-format module playback library -------------------------------------------------------------------------------- Update Information: http://sourceforge.net/projects/xmp/files/libxmp/4.2.4/Changelog/view Fix bugs reported by Justin Crawford: * fix XM note and envelope retrig on delay effect * fix XM keyoff reset on new note event * fix retrig effect frame counter * fix envelope update after manually set point Other changes: * fix Chiptracker pattern decoding (reported by Andreas Argirakis) * fix AMF sample loop end * fix false positives in Slamtilt format test * refactor S3M arpeggio effect memory * disabled incomplete DMF loader * disabled incomplete DTT loader * address clang-analyzer warning -------------------------------------------------------------------------------- ChangeLog: * Mon Feb 24 2014 Dominik Mierzejewski <rpm@xxxxxxxxxxxxxx> - 4.2.4-1 - update to 4.2.4 (http://sourceforge.net/projects/xmp/files/libxmp/4.2.4/Changelog/view) - drop the list of files with licenses other than LGPLv2.1+, it's growing too much -------------------------------------------------------------------------------- ================================================================================ nodejs-css-parse-1.7.0-2.fc20 (FEDORA-2014-3071) A JavaScript CSS parser for Node.js and the browser -------------------------------------------------------------------------------- Update Information: Initial package. -------------------------------------------------------------------------------- References: [ 1 ] Bug #1068990 - Review Request: nodejs-css-parse - A JavaScript CSS parser for Node.js and the browser https://bugzilla.redhat.com/show_bug.cgi?id=1068990 [ 2 ] Bug #1003367 - nodejs-stylus-0.42.2 is available https://bugzilla.redhat.com/show_bug.cgi?id=1003367 -------------------------------------------------------------------------------- ================================================================================ nodejs-grunt-contrib-concat-0.3.0-1.fc20 (FEDORA-2014-3042) Concatenate files with grunt -------------------------------------------------------------------------------- Update Information: Initial package. -------------------------------------------------------------------------------- References: [ 1 ] Bug #977123 - Review Request: nodejs-grunt-contrib-concat - Concatenate files with grunt https://bugzilla.redhat.com/show_bug.cgi?id=977123 -------------------------------------------------------------------------------- ================================================================================ nodejs-stylus-0.42.2-1.fc20 (FEDORA-2014-3071) Robust, expressive, and feature-rich CSS super-set for Node.js -------------------------------------------------------------------------------- Update Information: Initial package. -------------------------------------------------------------------------------- ChangeLog: * Sun Feb 23 2014 Jamie Nguyen <jamielinux@xxxxxxxxxxxxxxxxx> - 0.42.2-1 - update to upstream release 0.42.2 - take Source0 from GitHub as the NPM tarball has some files stripped -------------------------------------------------------------------------------- References: [ 1 ] Bug #1068990 - Review Request: nodejs-css-parse - A JavaScript CSS parser for Node.js and the browser https://bugzilla.redhat.com/show_bug.cgi?id=1068990 [ 2 ] Bug #1003367 - nodejs-stylus-0.42.2 is available https://bugzilla.redhat.com/show_bug.cgi?id=1003367 -------------------------------------------------------------------------------- ================================================================================ nodeunit-0.8.6-2.fc20 (FEDORA-2014-3070) Easy asynchronous unit testing framework for Node.js -------------------------------------------------------------------------------- Update Information: Initial package. -------------------------------------------------------------------------------- References: [ 1 ] Bug #968607 - Review Request: nodeunit - Easy asynchronous unit testing framework for Node.js https://bugzilla.redhat.com/show_bug.cgi?id=968607 -------------------------------------------------------------------------------- ================================================================================ openlmi-scripts-0.2.7-0.fc20 (FEDORA-2014-3047) Client-side python modules and command line utilities -------------------------------------------------------------------------------- Update Information: New upstream version. Added networking library. New upstream version. -------------------------------------------------------------------------------- ChangeLog: * Mon Feb 24 2014 Michal Minar <miminar@xxxxxxxxxx> 0.2.7-0 - New upstream version. - Added system library. * Wed Jan 15 2014 Michal Minar <miminar@xxxxxxxxxx> 0.2.6-5 - Added networking library. * Mon Jan 13 2014 Michal Minar <miminar@xxxxxxxxxx> 0.2.5-4 - New upstream version. -------------------------------------------------------------------------------- References: [ 1 ] Bug #1051229 - lmi lv show fails with global name 'fcmd' is not defined https://bugzilla.redhat.com/show_bug.cgi?id=1051229 -------------------------------------------------------------------------------- ================================================================================ os-apply-config-0.1.12-5.fc20 (FEDORA-2014-3058) Configure files from cloud metadata -------------------------------------------------------------------------------- Update Information: This introduces the os-apply-config package to Fedora 20. This update adds os-apply-config to the distribution. -------------------------------------------------------------------------------- ================================================================================ os-collect-config-0.1.11-4.fc20 (FEDORA-2014-3056) Collect and cache metadata running hooks on changes -------------------------------------------------------------------------------- Update Information: This package introduces os-collect-config to Fedora 20. -------------------------------------------------------------------------------- ================================================================================ os-refresh-config-0.0.8-3.fc20 (FEDORA-2014-3041) Refresh system configuration -------------------------------------------------------------------------------- Update Information: This introduces the os-refresh-config package to Fedora 20. -------------------------------------------------------------------------------- ================================================================================ owfs-2.9p2-1.fc20 (FEDORA-2014-3051) 1-Wire Virtual File System -------------------------------------------------------------------------------- Update Information: New features 1. Add support for the MAX31850 and MAX31851 thermocouple chips 2. Add support for the EDS0090 Digital IO device Fixes 1. Fix owhttpd "Bad URL" page to actually work 2. Update man pages for EDS devices and thermocouples -------------------------------------------------------------------------------- ChangeLog: * Sun Feb 23 2014 Tomasz Torcz <ttorcz@xxxxxxxxxxxxxxxxx> - 2.9p2-1 - new upstream release -------------------------------------------------------------------------------- ================================================================================ perl-DBD-ODBC-1.47-2.fc20 (FEDORA-2014-3066) ODBC Driver for DBI -------------------------------------------------------------------------------- Update Information: Updated to 1.47, plus fixed Change formatting -------------------------------------------------------------------------------- ChangeLog: * Mon Feb 24 2014 Jan Holcapek <holcapek@xxxxxxxxx> 1.47-2 - Fix formatting of Changes, which confused RPM dependency solver find-requires.sh so that it made the RPM require 'perl(the)' * Fri Feb 21 2014 Jan Holcapek <holcapek@xxxxxxxxx> 1.47-1 - Updated to upstream version 1.47. -------------------------------------------------------------------------------- ================================================================================ python-glue-0.4.1-1.fc20 (FEDORA-2014-3035) A simple command line tool to generate CSS sprites -------------------------------------------------------------------------------- Update Information: Update upstream version to 0.4.1 -------------------------------------------------------------------------------- ChangeLog: * Tue Feb 11 2014 Lorenzo Gil Sanchez <lorenzo.gil.sanchez@xxxxxxxxx> - 0.4.1-1 - Update upstream version to 0.4.1 * Wed Dec 4 2013 Lorenzo Gil Sanchez <lorenzo.gil.sanchez@xxxxxxxxx> - 0.4-1 - Update upstream version to 0.4 -------------------------------------------------------------------------------- References: [ 1 ] Bug #1063023 - python-glue-0.9.1 is available https://bugzilla.redhat.com/show_bug.cgi?id=1063023 -------------------------------------------------------------------------------- ================================================================================ python-swiftclient-2.0.2-1.fc20 (FEDORA-2014-3054) Client Library for OpenStack Object Storage API -------------------------------------------------------------------------------- Update Information: Update to upstream 2.0.2 Add SSL certificate verification by default (CVE-2013-6396) -------------------------------------------------------------------------------- ChangeLog: * Thu Feb 20 2014 Jakub Ruzicka <jruzicka@xxxxxxxxxx> 2.0.2-1 - Update to upstream 2.0.2 - Switch from pyOpenSSL to python-requests - update dependencies - Remove unneeded dependency: python-simplejson * Tue Dec 10 2013 Jakub Ruzicka <jruzicka@xxxxxxxxxx> 1.8.0-1 - Update to upstream 1.8.0 - Add SSL certificate verification by default (CVE-2013-6396) - New runtime and build dependency: pyOpenSSL - New runtime dependency: python-keystoneclient - python-pbr has been removed from runtime by upstream * Tue Oct 8 2013 Jakub Ruzicka <jruzicka@xxxxxxxxxx> - 1.7.0-1 - Update to upstream 1.7.0. -------------------------------------------------------------------------------- References: [ 1 ] Bug #1031652 - CVE-2013-6396 python-swiftclient: SSL certificate verification security issue https://bugzilla.redhat.com/show_bug.cgi?id=1031652 -------------------------------------------------------------------------------- ================================================================================ pywbem-0.7.0-25.20131121svn626.fc20 (FEDORA-2014-3067) Python WBEM Client and Provider Interface -------------------------------------------------------------------------------- Update Information: Fixed local authentication under root. -------------------------------------------------------------------------------- ChangeLog: * Mon Feb 24 2014 Michal Minar <miminar@xxxxxxxxxx> 0.7.0-25.20131121svn656 - Fixed local authentication under root. -------------------------------------------------------------------------------- References: [ 1 ] Bug #1041578 - NoneType' object has no attribute 'ChassisPackageType https://bugzilla.redhat.com/show_bug.cgi?id=1041578 -------------------------------------------------------------------------------- ================================================================================ rubygem-awesome_spawn-1.1.1-1.fc20 (FEDORA-2014-3060) A module that provides some useful features over Ruby's Kernel.spawn -------------------------------------------------------------------------------- Update Information: Update to 1.1.1 -------------------------------------------------------------------------------- References: [ 1 ] Bug #1061138 - rubygem-awesome_spawn-1.1.1 is available https://bugzilla.redhat.com/show_bug.cgi?id=1061138 -------------------------------------------------------------------------------- ================================================================================ rubygem-redis-3.0.7-1.fc20 (FEDORA-2014-3032) A Ruby client library for Redis -------------------------------------------------------------------------------- Update Information: Update to 3.0.7 -------------------------------------------------------------------------------- ChangeLog: * Mon Feb 24 2014 Achilleas Pipinellis <axilleas@xxxxxxxxxxxxxxxxx> - 3.0.7-1 - Update to 3.0.7 -------------------------------------------------------------------------------- References: [ 1 ] Bug #1016283 - rubygem-redis-3.0.7 is available https://bugzilla.redhat.com/show_bug.cgi?id=1016283 -------------------------------------------------------------------------------- ================================================================================ tcllib-1.15-3.fc20 (FEDORA-2014-3036) The standard Tcl library -------------------------------------------------------------------------------- Update Information: Fix more man files issue. Update to new 1.15 -------------------------------------------------------------------------------- ChangeLog: * Mon Feb 24 2014 Dmitrij S. Kryzhevich <krege@xxxxxxx> - 1.15-3 - Add two more man files to conflict-list. * Fri Feb 21 2014 Dmitrij S. Kryzhevich <krege@xxxxxxx> - 1.15-2 - Fix man/mann file conflict with tcl package. * Thu Feb 20 2014 Dmitrij S. Kryzhevich <krege@xxxxxxx> - 1.15-1 - Update for new 1.15. -------------------------------------------------------------------------------- References: [ 1 ] Bug #700770 - tcllib-1.15 is available https://bugzilla.redhat.com/show_bug.cgi?id=700770 -------------------------------------------------------------------------------- ================================================================================ xfdashboard-0.1.4-1.fc20 (FEDORA-2014-3034) GNOME shell like dashboard for Xfce -------------------------------------------------------------------------------- Update Information: Update to version 0.1.4. This release also provides support for themes -------------------------------------------------------------------------------- ChangeLog: * Mon Feb 24 2014 Mukundan Ragavan <nonamedotc@xxxxxxxxxxxxxxxxx> - 0.1.4-1 - Updated to the latest upstream version - Includes theming support (provides a default theme) -------------------------------------------------------------------------------- -- test mailing list test@xxxxxxxxxxxxxxxxxxxxxxx To unsubscribe: https://admin.fedoraproject.org/mailman/listinfo/test