Fedora 23 updates-testing report

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



The following Fedora 23 Security updates need testing:
 Age  URL
 166  https://bodhi.fedoraproject.org/updates/FEDORA-2015-16240   nagios-4.0.8-1.fc23
 124  https://bodhi.fedoraproject.org/updates/FEDORA-2015-81ded368fe   miniupnpc-1.9-6.fc23
  97  https://bodhi.fedoraproject.org/updates/FEDORA-2015-27392b3324   jbig2dec-0.12-2.fc23
  47  https://bodhi.fedoraproject.org/updates/FEDORA-2015-dd52a54fa1   python-pymongo-3.0.3-1.fc23
  47  https://bodhi.fedoraproject.org/updates/FEDORA-2015-06a7c972e8   thttpd-2.25b-37.fc23
  36  https://bodhi.fedoraproject.org/updates/FEDORA-2016-a69ee02554   xulrunner-44.0-1.fc23
  18  https://bodhi.fedoraproject.org/updates/FEDORA-2016-40401300ed   389-ds-base-1.3.4.8-1.fc23
  18  https://bodhi.fedoraproject.org/updates/FEDORA-2016-65a1f22818   community-mysql-5.6.29-1.fc23
  18  https://bodhi.fedoraproject.org/updates/FEDORA-2016-94b0b50351   gummi-0.6.6-1.fc23
  12  https://bodhi.fedoraproject.org/updates/FEDORA-2016-637618fcd4   mingw-nsis-2.50-1.fc23
   7  https://bodhi.fedoraproject.org/updates/FEDORA-2016-8411497132   drupal6-6.38-1.fc23
   5  https://bodhi.fedoraproject.org/updates/FEDORA-2016-eeb0f0c94f   drupal7-7.43-1.fc23
   5  https://bodhi.fedoraproject.org/updates/FEDORA-2016-ae14784e4e   libmodbus-3.0.6-1.fc23
   5  https://bodhi.fedoraproject.org/updates/FEDORA-2016-120b194a75   qpid-cpp-0.34-6.fc23
   2  https://bodhi.fedoraproject.org/updates/FEDORA-2016-6b977c4737   php-htmLawed-1.1.21-1.fc23
   2  https://bodhi.fedoraproject.org/updates/FEDORA-2016-040577033c   python-django-1.8.10-1.fc23
   1  https://bodhi.fedoraproject.org/updates/FEDORA-2016-3e4408f350   squid-3.5.10-1.fc23
   1  https://bodhi.fedoraproject.org/updates/FEDORA-2016-c0853ea24e   php-5.6.19-1.fc23
   1  https://bodhi.fedoraproject.org/updates/FEDORA-2016-641c8b4eb2   jenkins-1.625.3-3.fc23 jenkins-remoting-2.53.3-1.fc23
   1  https://bodhi.fedoraproject.org/updates/FEDORA-2016-e062971917   exim-4.86.2-1.fc23
   1  https://bodhi.fedoraproject.org/updates/FEDORA-2016-657a1305aa   websvn-2.3.3-12.fc23
   0  https://bodhi.fedoraproject.org/updates/FEDORA-2016-db944c5072   hamster-time-tracker-2.0-0.5.rc1.fc23
   0  https://bodhi.fedoraproject.org/updates/FEDORA-2016-65da02b95c   php-udan11-sql-parser-3.4.0-1.fc23 phpMyAdmin-4.5.5.1-1.fc23


The following Fedora 23 Critical Path updates have yet to be approved:
 Age URL
  36  https://bodhi.fedoraproject.org/updates/FEDORA-2016-a69ee02554   xulrunner-44.0-1.fc23
  12  https://bodhi.fedoraproject.org/updates/FEDORA-2016-8dde5e377c   lxsession-0.5.2-8.fc23
  12  https://bodhi.fedoraproject.org/updates/FEDORA-2016-2400dcd3d1   virtuoso-opensource-6.1.6-10.fc23
   2  https://bodhi.fedoraproject.org/updates/FEDORA-2016-9850932586   sqlite-3.11.0-3.fc23
   2  https://bodhi.fedoraproject.org/updates/FEDORA-2016-5fb0d8ce68   sendmail-8.15.2-3.fc23
   2  https://bodhi.fedoraproject.org/updates/FEDORA-2016-553640374c   lxmenu-data-0.1.5-1.fc23 lxpanel-0.8.2-1.fc23 lxde-common-0.99.1-1.fc23
   0  https://bodhi.fedoraproject.org/updates/FEDORA-2016-330f55b1a8   gnutls-3.4.10-1.fc23
   0  https://bodhi.fedoraproject.org/updates/FEDORA-2016-462b3247db   xfsprogs-4.3.0-1.fc23
   0  https://bodhi.fedoraproject.org/updates/FEDORA-2016-c0dd92d1ad   pungi-4.0.7-1.fc23
   0  https://bodhi.fedoraproject.org/updates/FEDORA-2016-d057957548   mutter-3.18.3-1.fc23 gnome-shell-extensions-3.18.4-1.fc23 gnome-shell-3.18.4-1.fc23
   0  https://bodhi.fedoraproject.org/updates/FEDORA-2016-7fc7d51465   openssh-7.2p1-2.fc23


The following builds have been pushed to Fedora 23 updates-testing

    am-utils-6.2.0-12.fc23
    audacity-2.1.2-3.fc23
    bugyou_plugins-0.1.1-1.fc23
    cdsclient-3.83-1.fc23
    composer-1.0.0-0.21.beta1.fc23
    davix-0.6.0-1.fc23
    fedfind-2.1.1-1.fc23
    fedmsg-0.16.4-1.fc23
    fvwm-2.6.5-12.fc23
    gflags-2.1.2-1.fc23
    gnome-shell-3.18.4-1.fc23
    gnome-shell-extensions-3.18.4-1.fc23
    gnutls-3.4.10-1.fc23
    hamster-time-tracker-2.0-0.5.rc1.fc23
    letsencrypt-0.4.2-1.fc23
    libpwiz-3.0.9393-1.fc23
    mMass-5.5.0-17.fc23
    mutter-3.18.3-1.fc23
    mysqltuner-1.6.0-3.git.a154701.fc23
    openssh-7.2p1-2.fc23
    perl-Test-File-Contents-0.22-1.fc23
    php-udan11-sql-parser-3.4.0-1.fc23
    phpMyAdmin-4.5.5.1-1.fc23
    pungi-4.0.7-1.fc23
    python-acme-0.4.2-1.fc23
    python-bugzilla2fedmsg-0.3.0-1.fc23
    python-cached_property-1.3.0-4.fc23
    python-gssapi-1.2.0-1.fc23
    python-importanize-0.4.1-4.fc23
    python-openstackdocstheme-1.2.7-2.fc23
    python-pygments-2.1.3-1.fc23
    python-trollius-redis-0.1.4-5.fc23
    python-wikitcms-2.0.0-1.fc23
    relval-2.0.2-1.fc23
    rygel-0.28.3-1.fc23
    writerperfect-0.9.5-1.fc23
    xfsprogs-4.3.0-1.fc23
    zathura-0.3.5-1.fc23
    zathura-cb-0.1.5-1.fc23
    zathura-djvu-0.2.5-1.fc23
    zathura-pdf-mupdf-0.3.0-1.fc23
    zathura-pdf-poppler-0.2.6-1.fc23
    zathura-ps-0.2.3-1.fc23

Details about builds:


================================================================================
 am-utils-6.2.0-12.fc23 (FEDORA-2016-b896e6cff5)
 Automount utilities including an updated version of Amd
--------------------------------------------------------------------------------
Update Information:

- fix Linux NFS recognition of umounts. - add systemd dependency on nfs-
lock.service - add get_nfs_xprt() and put_nfs_xprt() functions. - use new
get_nfs_xprt() and put_nfs_xprt() functions. - add NFSv3 nfs_quick_reply()
functionality. - add NFSv3 rpc request validation. - fix wcc attr usage in
unlink3_or_rmdir3(). - use Linux libtirpc if present.
--------------------------------------------------------------------------------


================================================================================
 audacity-2.1.2-3.fc23 (FEDORA-2016-ee19511560)
 Multitrack audio editor
--------------------------------------------------------------------------------
Update Information:

Rebuild for new Soundtouch required to fix symbol lookup error, which is causing
Audacity to fail during startup.  Also upgrades Audacity to 2.1.2.   ----
Audacity 2.1.2 Release Candidate 2.  Minor fixes which mainly apply to windows
builds.
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #1288349 - [abrt] audacity: dequeue_pending_request(): audacity killed by SIGABRT
        https://bugzilla.redhat.com/show_bug.cgi?id=1288349
  [ 2 ] Bug #1303417 - audacity: all edit and select functions suddenly grayed
        https://bugzilla.redhat.com/show_bug.cgi?id=1303417
  [ 3 ] Bug #1301390 - Audacity 2.1.1 application crashes during recording a second track due to ALSA lib pcm.c:7905:(snd_pcm_recover) underrun occurred
        https://bugzilla.redhat.com/show_bug.cgi?id=1301390
  [ 4 ] Bug #1294242 - audacity-2.1.2-0.7.rc1.fc23.x86_64 segfaults on startup
        https://bugzilla.redhat.com/show_bug.cgi?id=1294242
  [ 5 ] Bug #1310502 - Audacity fails to start with symbol lookup error
        https://bugzilla.redhat.com/show_bug.cgi?id=1310502
  [ 6 ] Bug #1293476 - Crash when recording the 2nd track with overdub
        https://bugzilla.redhat.com/show_bug.cgi?id=1293476
  [ 7 ] Bug #1294499 - [abrt] audacity: strlen(): audacity killed by SIGSEGV
        https://bugzilla.redhat.com/show_bug.cgi?id=1294499
--------------------------------------------------------------------------------


================================================================================
 bugyou_plugins-0.1.1-1.fc23 (FEDORA-2016-188e72e58b)
 Plugins for Bugyou
--------------------------------------------------------------------------------
Update Information:

Update setup.py script, remove sample configuration files  ----  Add missing
dependency, python-libpagure  ----  Initial packaging.
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #1309782 - Review Request: bugyou_plugins - Plugins and Services for Bugyou
        https://bugzilla.redhat.com/show_bug.cgi?id=1309782
--------------------------------------------------------------------------------


================================================================================
 cdsclient-3.83-1.fc23 (FEDORA-2016-2db4aac233)
 Tools to query databases at CDS
--------------------------------------------------------------------------------
Update Information:

new version (3.83)
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #1314752 - cdsclient-3.83 is available
        https://bugzilla.redhat.com/show_bug.cgi?id=1314752
--------------------------------------------------------------------------------


================================================================================
 composer-1.0.0-0.21.beta1.fc23 (FEDORA-2016-7f755c3fc5)
 Dependency Manager for PHP
--------------------------------------------------------------------------------
Update Information:

**Version 1.0.0-beta1**  *    Break: By default we now disable any non-secure
protocols (http, git, svn). This may lead to issues if you rely on those. See
secure-http config option. *    Break: show / list command now only show
installed packages by default. An --all option is added to show all packages. *
Added VCS repo support for the GitLab API, see also gitlab-oauth and gitlab-
domains config options *    Added prohibits / why-not command to show what
blocks an upgrade to a given package:version pair *    Added --tree / -t to the
show command to see all your installed packages in a tree view *    Added
--interactive / -i to the update command, which lets you pick packages to update
interactively *    Added exec command to run binaries while having bin-dir in
the PATH for convenience *    Added --root-reqs to the update command to update
only your direct, first degree dependencies *    Added cafile and capath config
options to control HTTPS certificate authority *    Added pubkey verification of
composer.phar when running self-update *    Added possibility to configure per-
package preferred-install types for more flexibility between prefer-source and
prefer-dist *    Added unpushed-changes detection when updating dependencies and
in the status command *    Added COMPOSER_AUTH env var that lets you pass a json
configuration like the auth.json file *    Added secure-http and disable-tls
config options to control HTTPS/HTTP *    Added warning when Xdebug is enabled
as it reduces performance quite a bit, hide it with
COMPOSER_DISABLE_XDEBUG_WARN=1 if you must *    Added duplicate key detection
when loading composer.json *    Added sort-packages config option to force
sorting of the requirements when using the require command *    Added support
for the XDG Base Directory spec on linux *    Added XzDownloader for xz file
support *    Fixed SSL support to fully verify peers in all PHP versions,
unsecure HTTP is also disabled by default *    Fixed stashing and cleaning up of
untracked files when updating packages *    Fixed plugins being enabled after
installation even when --no-plugins *    Many small bug fixes and additions
--------------------------------------------------------------------------------


================================================================================
 davix-0.6.0-1.fc23 (FEDORA-2016-1fab6d48f3)
 Toolkit for Http-based file management
--------------------------------------------------------------------------------
Update Information:

davix 0.6.0 release, see RELEASE-NOTES for changes
--------------------------------------------------------------------------------


================================================================================
 fedfind-2.1.1-1.fc23 (FEDORA-2016-754337a04b)
 Fedora Finder finds Fedora
--------------------------------------------------------------------------------
Update Information:

This update provides the latest releases of fedfind, python-wikitcms and relval.
The updated python-cached_property (a dependency of fedfind and python-wikitcms)
fixes the package naming and provisions to be consistent between Python 2 and
Python 3 and avoid dependency issues. This new 2.x series involves major changes
to all three packages to adapt to the [new Fedora compose
process](https://www.happyassassin.net/2016/02/15/pungi-4-the-new-generation-of-
the-fedora-compose-tools-and-what-it-means-for-qa/). fedfind, in particular, is
more incompatible than not with its 1.x series. The interface for python-
wikitcms has changed much less (just some additions; there should be no
incompatible changes). The `nightly` and `report-auto` subcommands have been
removed from relval and the `compose` subcommand can now handle nightly events
(without any of the checking the `nightly` subcommand used to do; unattended
creation of nightly commands is being moved to a separate fedmsg consumer
daemon). `relval` now runs under Python 3 rather than Python 2. All remaining
subcommands should be fully compatible with invocations that worked earlier.
These major changes are disruptive, but are vital to keep the tools working with
the changed compose process. Please see the project pages (and the changelogs
included on them) for more details:  *
[fedfind](https://www.happyassassin.net/fedfind) * [python-
wikitcms](https://www.happyassassin.net/wikitcms) *
[relval](https://www.happyassassin.net/relval)
--------------------------------------------------------------------------------


================================================================================
 fedmsg-0.16.4-1.fc23 (FEDORA-2016-124e1e4cb1)
 Tools for Fedora Infrastructure real-time messaging
--------------------------------------------------------------------------------
Update Information:

https://github.com/fedora-infra/fedmsg/blob/develop/CHANGELOG.rst#0164
--------------------------------------------------------------------------------


================================================================================
 fvwm-2.6.5-12.fc23 (FEDORA-2016-0e095aba1f)
 Highly configurable multiple virtual desktop window manager
--------------------------------------------------------------------------------
Update Information:

* Hopefully fixes crash in browser
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #823499 - fvwm crashes on clicking on browser back button
        https://bugzilla.redhat.com/show_bug.cgi?id=823499
--------------------------------------------------------------------------------


================================================================================
 gflags-2.1.2-1.fc23 (FEDORA-2016-78ed83f8d8)
 Library for commandline flag processing
--------------------------------------------------------------------------------
Update Information:

* Ver. 2.1.2
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #1312597 - Review request: upgrade gflags from 2.1.1 to 2.1.2
        https://bugzilla.redhat.com/show_bug.cgi?id=1312597
--------------------------------------------------------------------------------


================================================================================
 gnome-shell-3.18.4-1.fc23 (FEDORA-2016-d057957548)
 Window management and application launching for GNOME
--------------------------------------------------------------------------------
Update Information:

Update to latest stable upstream releases.
--------------------------------------------------------------------------------


================================================================================
 gnome-shell-extensions-3.18.4-1.fc23 (FEDORA-2016-d057957548)
 Modify and extend GNOME Shell functionality and behavior
--------------------------------------------------------------------------------
Update Information:

Update to latest stable upstream releases.
--------------------------------------------------------------------------------


================================================================================
 gnutls-3.4.10-1.fc23 (FEDORA-2016-330f55b1a8)
 A TLS protocol implementation
--------------------------------------------------------------------------------
Update Information:

New upstream release (#1314576)
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #1314576 - gnutls-3.4.10 is available
        https://bugzilla.redhat.com/show_bug.cgi?id=1314576
--------------------------------------------------------------------------------


================================================================================
 hamster-time-tracker-2.0-0.5.rc1.fc23 (FEDORA-2016-db944c5072)
 The Linux time tracker
--------------------------------------------------------------------------------
Update Information:

fix a possible ZeroDivisionError when there are bogus database entries
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #1309613 - [abrt] hamster-time-tracker: connection.py:651:call_blocking:DBusException: org.freedesktop.DBus.Python.ZeroDivisionError: Traceback (most recent call last):
        https://bugzilla.redhat.com/show_bug.cgi?id=1309613
--------------------------------------------------------------------------------


================================================================================
 letsencrypt-0.4.2-1.fc23 (FEDORA-2016-f875147676)
 A free, automated certificate authority client
--------------------------------------------------------------------------------
Update Information:

Updated to 0.4.2
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #1314756 - letsencrypt-0.4.2 is available
        https://bugzilla.redhat.com/show_bug.cgi?id=1314756
--------------------------------------------------------------------------------


================================================================================
 libpwiz-3.0.9393-1.fc23 (FEDORA-2016-dd35b1b8c5)
 ProteoWizard software library
--------------------------------------------------------------------------------
Update Information:

- Update to snapshot 9393
--------------------------------------------------------------------------------


================================================================================
 mMass-5.5.0-17.fc23 (FEDORA-2016-199debaa8f)
 Open Source Mass Spectrometry Tool
--------------------------------------------------------------------------------
Update Information:

- LIPID MAPS Database updated
--------------------------------------------------------------------------------


================================================================================
 mutter-3.18.3-1.fc23 (FEDORA-2016-d057957548)
 Window and compositing manager based on Clutter
--------------------------------------------------------------------------------
Update Information:

Update to latest stable upstream releases.
--------------------------------------------------------------------------------


================================================================================
 mysqltuner-1.6.0-3.git.a154701.fc23 (FEDORA-2016-17c03956d1)
 MySQL configuration assistant
--------------------------------------------------------------------------------
Update Information:

New upstream release.
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #1283136 - Query cache efficiency: wrong selects count
        https://bugzilla.redhat.com/show_bug.cgi?id=1283136
  [ 2 ] Bug #1267523 - Use of uninitialized value $mycalc{"total_aria_indexes"}
        https://bugzilla.redhat.com/show_bug.cgi?id=1267523
--------------------------------------------------------------------------------


================================================================================
 openssh-7.2p1-2.fc23 (FEDORA-2016-7fc7d51465)
 An open source implementation of SSH protocol versions 1 and 2
--------------------------------------------------------------------------------
Update Information:

This update provides new upstream release of openssh-7.2p1. This is mostly
bugfix release, but note that:  * the minimum modulus size supported for diffie-
hellman-group-exchange was increased to 2048 bits, * several legacy
cryptographic algorithms and MD5-based and truncated HMAC algorithms were
disabled on client side.  More information about this release can be found in
[upstream release notes](http://www.openssh.com/txt/release-7.2). Few more notes
on the [mainling-list HEADS UP](https://lists.fedoraproject.org/archives/list/de
vel@xxxxxxxxxxxxxxxxxxxxxxx/thread/WNYBILDLT3RN7XDNWFIAVSC5WMSZ6ERZ/).
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #1312870 - openssh-7.2p1 is available
        https://bugzilla.redhat.com/show_bug.cgi?id=1312870
--------------------------------------------------------------------------------


================================================================================
 perl-Test-File-Contents-0.22-1.fc23 (FEDORA-2016-3864515c81)
 Test routines for examining the contents of files
--------------------------------------------------------------------------------
Update Information:

A new version of Test-File-Contents is available.  See
http://cpansearch.perl.org/src/DWHEELER/Test-File-Contents-0.22/Changes for the
summary of changes in this release.
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #1314803 - perl-Test-File-Contents-0.22 is available
        https://bugzilla.redhat.com/show_bug.cgi?id=1314803
  [ 2 ] Bug #1314802 - perl-Test-File-Contents-0.21-6.fc25 FTBFS: tests fail
        https://bugzilla.redhat.com/show_bug.cgi?id=1314802
--------------------------------------------------------------------------------


================================================================================
 php-udan11-sql-parser-3.4.0-1.fc23 (FEDORA-2016-65da02b95c)
 A validating SQL lexer and parser with a focus on MySQL dialect
--------------------------------------------------------------------------------
Update Information:

phpMyAdmin 4.5.5.1 (2016-02-29) ===============================  This release
fixes multiple XSS vulnerabilities, please see PMASA-2016-10, PMASA-2016-11, and
PMASA-2016-12 for details; additionally it fixes a vulnerability allowing man-
in-the-middle attack on an API call to GitHub, see PMASA-2016-13 for details.
It also inclues fixes for the following bugs:  - issue #11971 CREATE UNIQUE
INDEX index type is not recognized by parser. - issue #11982 Row count wrong
when grouping joined tables. - issue #12012 Column definition with default value
and comment in CREATE TABLE exported faulty. - issue #12020 New statement but no
delimiter and unexpected token with REPLACE. - issue #12029 Fixed incorrect
usage of SQL parser context in SQL export - issue #12048 Fixed inclusion of
gettext library from SQL parser
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #1313696 - CVE-2016-2562 phpMyAdmin: man-in-the-middle attack on API call to GitHub (PMASA-2016-13)
        https://bugzilla.redhat.com/show_bug.cgi?id=1313696
  [ 2 ] Bug #1313695 - CVE-2016-2559 phpMyAdmin: XSS vulnerability in SQL parser (PMASA-2016-10)
        https://bugzilla.redhat.com/show_bug.cgi?id=1313695
  [ 3 ] Bug #1313224 - CVE-2016-2561 phpMyAdmin: multiple XSS vulnerabilities (PMASA-2016-12)
        https://bugzilla.redhat.com/show_bug.cgi?id=1313224
  [ 4 ] Bug #1313221 - CVE-2016-2560 phpMyAdmin: multiple XSS vulnerabilities (PMASA-2016-11)
        https://bugzilla.redhat.com/show_bug.cgi?id=1313221
--------------------------------------------------------------------------------


================================================================================
 phpMyAdmin-4.5.5.1-1.fc23 (FEDORA-2016-65da02b95c)
 Handle the administration of MySQL over the World Wide Web
--------------------------------------------------------------------------------
Update Information:

phpMyAdmin 4.5.5.1 (2016-02-29) ===============================  This release
fixes multiple XSS vulnerabilities, please see PMASA-2016-10, PMASA-2016-11, and
PMASA-2016-12 for details; additionally it fixes a vulnerability allowing man-
in-the-middle attack on an API call to GitHub, see PMASA-2016-13 for details.
It also inclues fixes for the following bugs:  - issue #11971 CREATE UNIQUE
INDEX index type is not recognized by parser. - issue #11982 Row count wrong
when grouping joined tables. - issue #12012 Column definition with default value
and comment in CREATE TABLE exported faulty. - issue #12020 New statement but no
delimiter and unexpected token with REPLACE. - issue #12029 Fixed incorrect
usage of SQL parser context in SQL export - issue #12048 Fixed inclusion of
gettext library from SQL parser
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #1313696 - CVE-2016-2562 phpMyAdmin: man-in-the-middle attack on API call to GitHub (PMASA-2016-13)
        https://bugzilla.redhat.com/show_bug.cgi?id=1313696
  [ 2 ] Bug #1313695 - CVE-2016-2559 phpMyAdmin: XSS vulnerability in SQL parser (PMASA-2016-10)
        https://bugzilla.redhat.com/show_bug.cgi?id=1313695
  [ 3 ] Bug #1313224 - CVE-2016-2561 phpMyAdmin: multiple XSS vulnerabilities (PMASA-2016-12)
        https://bugzilla.redhat.com/show_bug.cgi?id=1313224
  [ 4 ] Bug #1313221 - CVE-2016-2560 phpMyAdmin: multiple XSS vulnerabilities (PMASA-2016-11)
        https://bugzilla.redhat.com/show_bug.cgi?id=1313221
--------------------------------------------------------------------------------


================================================================================
 pungi-4.0.7-1.fc23 (FEDORA-2016-c0dd92d1ad)
 Distribution compose tool
--------------------------------------------------------------------------------
Update Information:

Limit the ivariants with config option 'tree_variants' (dennis) [createrepo-
wrapper] Fix --deltas argument (lsedlar) - [createrepo-wrapper] Add tests
(lsedlar) - [koji-wrapper] Retry watching on connection errors (lsedlar) -
[createrepo-wrapper] Refactor code (lsedlar) - [paths] Use variant.uid
explicitly (lsedlar) - [createrepo] Add tests (lsedlar) - [createrepo] Refactor
code (lsedlar) - [image-build] Fix resolving git urls (lsedlar) - [testphase]
Don't run repoclosure for empty variants (lsedlar) - [live-images] No manifest
for appliances (lsedlar)  ----  push the 4.0 docs to a 4.0 branch (dennis) -
[live-images] Rename log file (lsedlar) - [buildinstall] Use -dvd- in volume ids
instead of -boot- (lsedlar) - [buildinstall] Hardlink boot isos (lsedlar) -
[doc] Write documentation for kickstart Git URLs (lsedlar) - [util] Resolve
branches in git urls (lsedlar) - [live-images] Fix crash when repo_from is not a
list (lsedlar) - [buildinstall] Don't copy files for empty variants (lsedlar)
----  [tests] Fix wrong checks in buildinstall tests (lsedlar) [tests] Use
temporary files for buildinstall (lsedlar) [tests] Do not mock open for koji
wrapper tests (lsedlar) Merge #179 `Update makefile targets for testing` (ausil)
Update makefile targets for testing (lsedlar) [live-images] Set type to raw-xz
for appliances (lsedlar) [live-images] Correctly create format (lsedlar) [tests]
Dummy compose is no longer private (lsedlar) [tests] Move buildinstall tests to
new infrastructure (lsedlar) [tests] Use real paths module in testing (lsedlar)
[tests] Move dummy testing compose into separate module (lsedlar) [live-images]
Create image dir if needed (lsedlar) [live-images] Add images to manifest
(lsedlar) [live-images] Fix path processing (lsedlar) [live-images] Move repo
calculation to separate method (lsedlar) [koji-wrapper] Fix getting results from
spin-appliance (lsedlar) [live-images] Filter non-image results (lsedlar) [live-
images] Rename repos_from to repo_from (lsedlar) [koji-wrapper] Add test for
passing release to image-build (lsedlar) [live-images] Automatically populate
release with date and respin (lsedlar) [live-media] Respect release set in
configuration (lsedlar) [live-images] Build all images specified in config
(lsedlar) [live-media] Don't create $basedir arch (lsedlar) Update tests
(lsedlar) do not ad to image build and live tasks the variant if it is empty
(dennis) when a variant is empty do not add it to the repolist for livemedia
(dennis) [live-media] Update tests to use $basearch (lsedlar) [buildinstall]
Don't run lorax for empty variants (lsedlar) Merge #159 `use $basearch not $arch
in livemedia tasks` (lubomir.sedlar) Merge #158 `do not uses pipes.quotes in
livemedia tasks` (lubomir.sedlar) Add documentation for signing support that was
added by previous commit (tmlcoch) Support signing of rpm wrapped live images
(tmlcoch) Fix terminology - Koji uses sigkey not level (tmlcoch) use $basearch
not $arch in livemedia tasks (dennis) do not uses pipes.quotes in livemedia
tasks (dennis) [live-images] Don't tweak kickstarts (lsedlar) Allow specifying
empty variants (lsedlar) [createrepo] Remove dead assignments (lsedlar) Keep
empty query string in resolved git url (lsedlar) [image-build] Use dashes as
arch separator in log (lsedlar) [buildinstall] Stop parsing task_id (lsedlar)
[koji-wrapper] Get task id from failed runroot (lsedlar) [live-media] Pass ksurl
to koji (lsedlar) Merge #146 `[live-media] Properly calculate iso dir` (ausil)
[live-media] Properly calculate iso dir (lsedlar) [image-build] Fix tests
(lsedlar) add image-build sections (lkocman) [koji-wrapper] Add tests for
get_create_image_cmd (lsedlar) [live-images] Add support for spin-appliance
(lsedlar) [live-media] Koji option is ksfile, not kickstart (lsedlar) [live-
media] Use install tree from another variant (lsedlar) [live-media] Put images
into iso dir (lsedlar) [image-build] Koji expects arches as a comma separated
string (lsedlar) Merge #139 `Log more details when any deliverable fails`
(ausil) [live-media] Version is required argument (lsedlar) [koji-wrapper] Only
parse output on success (lsedlar) [koji-wrapper] Add tests for runroot wrapper
(lsedlar) [buildinstall] Improve logging (lsedlar) Log more details about failed
deliverable (lsedlar) [image-build] Fix failable tests (lsedlar) Merge #135 `Add
live media support` (ausil) Merge #133 `media_split: add logger support. Helps
with debugging space issues on dvd media` (ausil) [live-media] Add live media
phase (lsedlar) [koji-wrapper] Add support for spin-livemedia (lsedlar) [koji-
wrapper] Use more descriptive method names (lsedlar) [image-build] Remove dead
code (lsedlar) media_split: add logger support. Helps with debugging space
issues on dvd media (lkocman) [image-build] Allow running image build scratch
tasks (lsedlar) [image-build] Allow dynamic release for images (lsedlar) [tests]
Fix wrong checks in buildinstall tests (lsedlar)  ----  [tests] Fix wrong checks
in buildinstall tests (lsedlar) [tests] Use temporary files for buildinstall
(lsedlar) [tests] Do not mock open for koji wrapper tests (lsedlar) Merge #179
`Update makefile targets for testing` (ausil) Update makefile targets for
testing (lsedlar) [live-images] Set type to raw-xz for appliances (lsedlar)
[live-images] Correctly create format (lsedlar) [tests] Dummy compose is no
longer private (lsedlar) [tests] Move buildinstall tests to new infrastructure
(lsedlar) [tests] Use real paths module in testing (lsedlar) [tests] Move dummy
testing compose into separate module (lsedlar) [live-images] Create image dir if
needed (lsedlar) [live-images] Add images to manifest (lsedlar) [live-images]
Fix path processing (lsedlar) [live-images] Move repo calculation to separate
method (lsedlar) [koji-wrapper] Fix getting results from spin-appliance
(lsedlar) [live-images] Filter non-image results (lsedlar) [live-images] Rename
repos_from to repo_from (lsedlar) [koji-wrapper] Add test for passing release to
image-build (lsedlar) [live-images] Automatically populate release with date and
respin (lsedlar) [live-media] Respect release set in configuration (lsedlar)
[live-images] Build all images specified in config (lsedlar) [live-media] Don't
create $basedir arch (lsedlar) Update tests (lsedlar) do not ad to image build
and live tasks the variant if it is empty (dennis) when a variant is empty do
not add it to the repolist for livemedia (dennis) [live-media] Update tests to
use $basearch (lsedlar) [buildinstall] Don't run lorax for empty variants
(lsedlar) Merge #159 `use $basearch not $arch in livemedia tasks`
(lubomir.sedlar) Merge #158 `do not uses pipes.quotes in livemedia tasks`
(lubomir.sedlar) Add documentation for signing support that was added by
previous commit (tmlcoch) Support signing of rpm wrapped live images (tmlcoch)
Fix terminology - Koji uses sigkey not level (tmlcoch) use $basearch not $arch
in livemedia tasks (dennis) do not uses pipes.quotes in livemedia tasks (dennis)
[live-images] Don't tweak kickstarts (lsedlar) Allow specifying empty variants
(lsedlar) [createrepo] Remove dead assignments (lsedlar) Keep empty query string
in resolved git url (lsedlar) [image-build] Use dashes as arch separator in log
(lsedlar) [buildinstall] Stop parsing task_id (lsedlar) [koji-wrapper] Get task
id from failed runroot (lsedlar) [live-media] Pass ksurl to koji (lsedlar) Merge
#146 `[live-media] Properly calculate iso dir` (ausil) [live-media] Properly
calculate iso dir (lsedlar) [image-build] Fix tests (lsedlar) add image-build
sections (lkocman) [koji-wrapper] Add tests for get_create_image_cmd (lsedlar)
[live-images] Add support for spin-appliance (lsedlar) [live-media] Koji option
is ksfile, not kickstart (lsedlar) [live-media] Use install tree from another
variant (lsedlar) [live-media] Put images into iso dir (lsedlar) [image-build]
Koji expects arches as a comma separated string (lsedlar) Merge #139 `Log more
details when any deliverable fails` (ausil) [live-media] Version is required
argument (lsedlar) [koji-wrapper] Only parse output on success (lsedlar) [koji-
wrapper] Add tests for runroot wrapper (lsedlar) [buildinstall] Improve logging
(lsedlar) Log more details about failed deliverable (lsedlar) [image-build] Fix
failable tests (lsedlar) Merge #135 `Add live media support` (ausil) Merge #133
`media_split: add logger support. Helps with debugging space issues on dvd
media` (ausil) [live-media] Add live media phase (lsedlar) [koji-wrapper] Add
support for spin-livemedia (lsedlar) [koji-wrapper] Use more descriptive method
names (lsedlar) [image-build] Remove dead code (lsedlar) media_split: add logger
support. Helps with debugging space issues on dvd media (lkocman) [image-build]
Allow running image build scratch tasks (lsedlar) [image-build] Allow dynamic
release for images (lsedlar) [tests] Fix wrong checks in buildinstall tests
(lsedlar)
--------------------------------------------------------------------------------


================================================================================
 python-acme-0.4.2-1.fc23 (FEDORA-2016-f875147676)
 Python library for the ACME protocol
--------------------------------------------------------------------------------
Update Information:

Updated to 0.4.2
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #1314756 - letsencrypt-0.4.2 is available
        https://bugzilla.redhat.com/show_bug.cgi?id=1314756
--------------------------------------------------------------------------------


================================================================================
 python-bugzilla2fedmsg-0.3.0-1.fc23 (FEDORA-2016-0815e69072)
 Consume BZ messages over STOMP and republish to fedmsg
--------------------------------------------------------------------------------
Update Information:

Ignore any non-Fedora components, and adjust for our new queue.
--------------------------------------------------------------------------------


================================================================================
 python-cached_property-1.3.0-4.fc23 (FEDORA-2016-754337a04b)
 A cached-property for decorating methods in Python classes
--------------------------------------------------------------------------------
Update Information:

This update provides the latest releases of fedfind, python-wikitcms and relval.
The updated python-cached_property (a dependency of fedfind and python-wikitcms)
fixes the package naming and provisions to be consistent between Python 2 and
Python 3 and avoid dependency issues. This new 2.x series involves major changes
to all three packages to adapt to the [new Fedora compose
process](https://www.happyassassin.net/2016/02/15/pungi-4-the-new-generation-of-
the-fedora-compose-tools-and-what-it-means-for-qa/). fedfind, in particular, is
more incompatible than not with its 1.x series. The interface for python-
wikitcms has changed much less (just some additions; there should be no
incompatible changes). The `nightly` and `report-auto` subcommands have been
removed from relval and the `compose` subcommand can now handle nightly events
(without any of the checking the `nightly` subcommand used to do; unattended
creation of nightly commands is being moved to a separate fedmsg consumer
daemon). `relval` now runs under Python 3 rather than Python 2. All remaining
subcommands should be fully compatible with invocations that worked earlier.
These major changes are disruptive, but are vital to keep the tools working with
the changed compose process. Please see the project pages (and the changelogs
included on them) for more details:  *
[fedfind](https://www.happyassassin.net/fedfind) * [python-
wikitcms](https://www.happyassassin.net/wikitcms) *
[relval](https://www.happyassassin.net/relval)
--------------------------------------------------------------------------------


================================================================================
 python-gssapi-1.2.0-1.fc23 (FEDORA-2016-1a6e740ce4)
 Python Bindings for GSSAPI (RFC 2743/2744 and extensions)
--------------------------------------------------------------------------------
Update Information:

New upstream version fixes issue with delegated credential storage.  For more
information, please see [our upstream release
notes](https://github.com/pythongssapi/python-gssapi/releases/tag/v1.2.0)
--------------------------------------------------------------------------------


================================================================================
 python-importanize-0.4.1-4.fc23 (FEDORA-2016-d662304333)
 Utility for organizing Python imports using PEP8 or custom rules
--------------------------------------------------------------------------------
Update Information:

Bug 1314537 - requires both python2 and python3
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #1314537 - python-importanize - requires both python2 and python3
        https://bugzilla.redhat.com/show_bug.cgi?id=1314537
--------------------------------------------------------------------------------


================================================================================
 python-openstackdocstheme-1.2.7-2.fc23 (FEDORA-2016-517ab8446c)
 OpenStack Docs Theme
--------------------------------------------------------------------------------
Update Information:

New package python-openstackdocstheme
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #1314401 - Review Request: python-openstackdocstheme - OpenStack Docs Theme
        https://bugzilla.redhat.com/show_bug.cgi?id=1314401
--------------------------------------------------------------------------------


================================================================================
 python-pygments-2.1.3-1.fc23 (FEDORA-2016-1192a81705)
 Syntax highlighting engine written in Python
--------------------------------------------------------------------------------
Update Information:

Update for upstream release.
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #1299284 - python-pygments-2.1.3 is available
        https://bugzilla.redhat.com/show_bug.cgi?id=1299284
--------------------------------------------------------------------------------


================================================================================
 python-trollius-redis-0.1.4-5.fc23 (FEDORA-2016-71c7e38fba)
 Redis client for the Python event loop PEP3156 for Trollius.
--------------------------------------------------------------------------------
Update Information:

Add a python3 sub-package
--------------------------------------------------------------------------------


================================================================================
 python-wikitcms-2.0.0-1.fc23 (FEDORA-2016-754337a04b)
 Fedora QA wiki test management Python library
--------------------------------------------------------------------------------
Update Information:

This update provides the latest releases of fedfind, python-wikitcms and relval.
The updated python-cached_property (a dependency of fedfind and python-wikitcms)
fixes the package naming and provisions to be consistent between Python 2 and
Python 3 and avoid dependency issues. This new 2.x series involves major changes
to all three packages to adapt to the [new Fedora compose
process](https://www.happyassassin.net/2016/02/15/pungi-4-the-new-generation-of-
the-fedora-compose-tools-and-what-it-means-for-qa/). fedfind, in particular, is
more incompatible than not with its 1.x series. The interface for python-
wikitcms has changed much less (just some additions; there should be no
incompatible changes). The `nightly` and `report-auto` subcommands have been
removed from relval and the `compose` subcommand can now handle nightly events
(without any of the checking the `nightly` subcommand used to do; unattended
creation of nightly commands is being moved to a separate fedmsg consumer
daemon). `relval` now runs under Python 3 rather than Python 2. All remaining
subcommands should be fully compatible with invocations that worked earlier.
These major changes are disruptive, but are vital to keep the tools working with
the changed compose process. Please see the project pages (and the changelogs
included on them) for more details:  *
[fedfind](https://www.happyassassin.net/fedfind) * [python-
wikitcms](https://www.happyassassin.net/wikitcms) *
[relval](https://www.happyassassin.net/relval)
--------------------------------------------------------------------------------


================================================================================
 relval-2.0.2-1.fc23 (FEDORA-2016-754337a04b)
 Tool for interacting with Fedora QA wiki pages
--------------------------------------------------------------------------------
Update Information:

This update provides the latest releases of fedfind, python-wikitcms and relval.
The updated python-cached_property (a dependency of fedfind and python-wikitcms)
fixes the package naming and provisions to be consistent between Python 2 and
Python 3 and avoid dependency issues. This new 2.x series involves major changes
to all three packages to adapt to the [new Fedora compose
process](https://www.happyassassin.net/2016/02/15/pungi-4-the-new-generation-of-
the-fedora-compose-tools-and-what-it-means-for-qa/). fedfind, in particular, is
more incompatible than not with its 1.x series. The interface for python-
wikitcms has changed much less (just some additions; there should be no
incompatible changes). The `nightly` and `report-auto` subcommands have been
removed from relval and the `compose` subcommand can now handle nightly events
(without any of the checking the `nightly` subcommand used to do; unattended
creation of nightly commands is being moved to a separate fedmsg consumer
daemon). `relval` now runs under Python 3 rather than Python 2. All remaining
subcommands should be fully compatible with invocations that worked earlier.
These major changes are disruptive, but are vital to keep the tools working with
the changed compose process. Please see the project pages (and the changelogs
included on them) for more details:  *
[fedfind](https://www.happyassassin.net/fedfind) * [python-
wikitcms](https://www.happyassassin.net/wikitcms) *
[relval](https://www.happyassassin.net/relval)
--------------------------------------------------------------------------------


================================================================================
 rygel-0.28.3-1.fc23 (FEDORA-2016-9335b0a7e1)
 A collection of UPnP/DLNA services
--------------------------------------------------------------------------------
Update Information:

Rygel 0.28.3 bug fix release. For details, see https://mail.gnome.org/archives
/ftp-release-list/2016-March/msg00027.html
--------------------------------------------------------------------------------


================================================================================
 writerperfect-0.9.5-1.fc23 (FEDORA-2016-4a54c54098)
 A collection of tools to transform various file formats into ODF
--------------------------------------------------------------------------------
Update Information:

new upstream release
--------------------------------------------------------------------------------


================================================================================
 xfsprogs-4.3.0-1.fc23 (FEDORA-2016-462b3247db)
 Utilities for managing the XFS filesystem
--------------------------------------------------------------------------------
Update Information:

Kernel v4.4 and later detects an XFS log problem which is only fixed by xfsprogs
v4.3 or later.  If you have encountered the inability to mount an xfs filesystem
such as: > XFS (dm-3): Mounting V5 Filesystem  > XFS (dm-3): Corruption warning:
Metadata has LSN (1:16) ahead of current LSN (1:2).  > Please unmount and run
xfs_repair (>= v4.3) to resolve.  > XFS (dm-3): log mount/recovery failed: error
-22 XFS (dm-3): log mount failed  please update to this version of xfsprogs and
run xfs_repair against the filesystem. See also [this email
thread](http://marc.info/?l=linux-kernel&m=144785713726096&w=2).
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #1314795 - Kernel 4.4.3 fails to boot the system on XFS root, erroneous errors due to old xfsprogs
        https://bugzilla.redhat.com/show_bug.cgi?id=1314795
  [ 2 ] Bug #1314605 - xfs_repair will "corrupt" your data
        https://bugzilla.redhat.com/show_bug.cgi?id=1314605
--------------------------------------------------------------------------------


================================================================================
 zathura-0.3.5-1.fc23 (FEDORA-2016-07c8caacbc)
 A lightweight document viewer
--------------------------------------------------------------------------------
Update Information:

A new version of zathura is available, with various bugfixes and improvements.
--------------------------------------------------------------------------------


================================================================================
 zathura-cb-0.1.5-1.fc23 (FEDORA-2016-fe5e1ab360)
 Comic book support for zathura
--------------------------------------------------------------------------------
Update Information:

A new version of zathura-cb is available.  This release advertises support for
URLs.
--------------------------------------------------------------------------------


================================================================================
 zathura-djvu-0.2.5-1.fc23 (FEDORA-2016-a6159449d7)
 DjVu support for zathura
--------------------------------------------------------------------------------
Update Information:

A new version of zathura-djvu is available.  This release advertises support for
URLs.
--------------------------------------------------------------------------------


================================================================================
 zathura-pdf-mupdf-0.3.0-1.fc23 (FEDORA-2016-8ecc358c52)
 PDF support for zathura via mupdf
--------------------------------------------------------------------------------
Update Information:

A new version of zathura-pdf-mupdf is available.  This release uses the correct
color space.
--------------------------------------------------------------------------------


================================================================================
 zathura-pdf-poppler-0.2.6-1.fc23 (FEDORA-2016-05ee6356e4)
 PDF support for zathura via poppler
--------------------------------------------------------------------------------
Update Information:

A new version of zathura-pdf-poppler is available.  This release advertises
support for URLs.
--------------------------------------------------------------------------------


================================================================================
 zathura-ps-0.2.3-1.fc23 (FEDORA-2016-99ad38fbc5)
 PS support for zathura via libspectre
--------------------------------------------------------------------------------
Update Information:

A new version of zathura-ps is available.  This release advertises support for
URLs.
--------------------------------------------------------------------------------
--
test mailing list
test@xxxxxxxxxxxxxxxxxxxxxxx
To unsubscribe:
http://lists.fedoraproject.org/admin/lists/test@xxxxxxxxxxxxxxxxxxxxxxx





[Index of Archives]     [Fedora Desktop]     [Fedora SELinux]     [Photo Sharing]     [Yosemite Forum]     [KDE Users]

  Powered by Linux