The following Fedora 28 Security updates need testing: Age URL 29 https://bodhi.fedoraproject.org/updates/FEDORA-2018-bfdad62cd6 wireshark-2.4.5-3.fc28 5 https://bodhi.fedoraproject.org/updates/FEDORA-2018-99eed1942f remctl-3.14-1.fc28 3 https://bodhi.fedoraproject.org/updates/FEDORA-2018-a5e9a619f6 zsh-5.5-1.fc28 2 https://bodhi.fedoraproject.org/updates/FEDORA-2018-906ba26b4d drupal8-8.4.6-3.fc28 2 https://bodhi.fedoraproject.org/updates/FEDORA-2018-bbfb0f5bc9 pcs-0.9.164-1.fc28 1 https://bodhi.fedoraproject.org/updates/FEDORA-2018-2bfbd27a0b origin-3.9.0-1.fc28 1 https://bodhi.fedoraproject.org/updates/FEDORA-2018-d510cfd7eb jgraphx-3.6.0.0-6.fc28 1 https://bodhi.fedoraproject.org/updates/FEDORA-2018-dd8162c004 ruby-2.5.1-92.fc28 The following Fedora 28 Critical Path updates have yet to be approved: Age URL 1 https://bodhi.fedoraproject.org/updates/FEDORA-2018-314e066f70 python-productmd-1.11-2.fc28 The following builds have been pushed to Fedora 28 updates-testing adobe-source-han-sans-cn-fonts-1.004-6.fc28.1 adobe-source-han-sans-tw-fonts-1.004-7.fc28.1 adobe-source-han-serif-cn-fonts-1.001-4.fc28.1 adobe-source-han-serif-tw-fonts-1.001-4.fc28.1 baekmuk-ttf-fonts-2.2-45.fc28.1 botan2-2.6.0-1.fc28 cairo-1.15.12-1.fc28 cldr-emoji-annotation-33.0.0_1-1.fc28 corosync-2.4.4-1.fc28 dep-0.4.1-2.fc28 dogtag-pki-10.6.0-1.fc28 dogtag-pki-theme-10.6.0-1.fc28 environment-modules-4.1.2-1.fc28 fedora-obsolete-packages-28-4 firefox-59.0.2-1.fc28 gnome-initial-setup-3.28.0-6.fc28 gnome-shell-extension-system-monitor-applet-35-1.20180410git751d557.fc28 google-noto-cjk-fonts-20170602-6.fc28.1 gsequencer-1.4.25-1.fc28 gsi-openssh-7.7p1-2.fc28 hanazono-fonts-20170904-2.fc28.1 ipa-ex-gothic-fonts-002.01-11.fc28.1 ipa-ex-mincho-fonts-002.01-11.fc28.1 ipa-gothic-fonts-003.03-13.fc28.1 ipa-mincho-fonts-003.03-13.fc28.1 ipa-pgothic-fonts-003.03-12.fc28.1 ipa-pmincho-fonts-003.03-12.fc28.1 jsch-agent-proxy-0.0.8-8.fc28 libvarlink-8-1.fc28 libzapojit-0.0.3-13.fc28 lksctp-tools-1.0.16-9.fc28 lm_sensors-3.4.0-12.fc28 lockdev-1.0.4-0.26.20111007git.fc28 lollypop-0.9.500-1.fc28 lua-expat-1.3.0-12.fc28 mactel-boot-0.9-17.fc28 memtest86+-5.01-19.fc28 mingw-libzip-1.5.1-1.fc28 motoya-lcedar-fonts-1.00-0.16.20110406git.fc28.1 motoya-lmaru-fonts-1.00-0.16.20110406git.fc28.1 mozilla-noscript-10.1.7.5-1.fc28 mu-0.9.13-1.fc28 mythes-1.2.4-9.fc28 mythes-en-3.0-20.fc28 naver-nanum-fonts-3.020-20.20140930.fc28.1 nodejs-packaging-14-1.fc28 oath-toolkit-2.6.1-6.fc28 ocaml-ounit-2.0.8-1.fc28 openssh-7.7p1-2.fc28 passwd-0.80-2.fc28 perl-version-0.99.21-1.fc28 php-egulias-email-validator2-2.1.4-1.fc28 php-zendframework-zend-filter-2.8.0-1.fc28 php-zendframework-zend-test-3.2.0-1.fc28 pki-console-10.6.0-1.fc28 pki-core-10.6.0-1.fc28 pvs-sbcl-6.0-58.fc28 python-colorspacious-1.1.2-1.fc28 python-geoip2-2.8.0-1.fc28 python-microfs-1.2.2-1.fc28 python-nudatus-0.0.2-1.fc28 roundcubemail-1.3.6-1.fc28 sazanami-fonts-0.20040629-30.fc28.1 sbcl-1.4.6-1.fc28 sequence-library-1.0.3-1.fc28 sfact-0.0-21.20130128gitbc56c68.fc28 skeinforge-12.03.14-31.fc28 sqljet-1.1.10-10.fc28 svnkit-1.8.15-2.fc28 uflash-1.1.2-2.fc28 un-core-fonts-1.0.2-0.31.080608.fc28.1 vlgothic-fonts-20141206-10.fc28.1 xorg-x11-drv-libinput-0.27.1-2.fc28 Details about builds: ================================================================================ adobe-source-han-sans-cn-fonts-1.004-6.fc28.1 (FEDORA-2018-08671173bf) Adobe OpenType Pan-CJK font family for Simplified Chinese -------------------------------------------------------------------------------- Update Information: Revert the priority of fontconfig config file. this change is to revert https://fedoraproject.org/wiki/Changes/ChineseDefaultFontsToNoto -------------------------------------------------------------------------------- ================================================================================ adobe-source-han-sans-tw-fonts-1.004-7.fc28.1 (FEDORA-2018-08671173bf) Adobe OpenType Pan-CJK font family for Traditional Chinese -------------------------------------------------------------------------------- Update Information: Revert the priority of fontconfig config file. this change is to revert https://fedoraproject.org/wiki/Changes/ChineseDefaultFontsToNoto -------------------------------------------------------------------------------- ================================================================================ adobe-source-han-serif-cn-fonts-1.001-4.fc28.1 (FEDORA-2018-08671173bf) Adobe OpenType Pan-CJK font family for Simplified Chinese -------------------------------------------------------------------------------- Update Information: Revert the priority of fontconfig config file. this change is to revert https://fedoraproject.org/wiki/Changes/ChineseDefaultFontsToNoto -------------------------------------------------------------------------------- ================================================================================ adobe-source-han-serif-tw-fonts-1.001-4.fc28.1 (FEDORA-2018-08671173bf) Adobe OpenType Pan-CJK font family for Traditional Chinese -------------------------------------------------------------------------------- Update Information: Revert the priority of fontconfig config file. this change is to revert https://fedoraproject.org/wiki/Changes/ChineseDefaultFontsToNoto -------------------------------------------------------------------------------- ================================================================================ baekmuk-ttf-fonts-2.2-45.fc28.1 (FEDORA-2018-bf451259e1) Free Korean TrueType fonts -------------------------------------------------------------------------------- Update Information: Revert the priority of fontconfig config file. this is to revert the change of https://fedoraproject.org/wiki/Changes/KRDefaultFontsToNoto -------------------------------------------------------------------------------- ================================================================================ botan2-2.6.0-1.fc28 (FEDORA-2018-8eb34a4230) Crypto and TLS for C++11 -------------------------------------------------------------------------------- Update Information: New upstream release -------------------------------------------------------------------------------- References: [ 1 ] Bug #1563881 - botan2-2.5.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=1563881 -------------------------------------------------------------------------------- ================================================================================ cairo-1.15.12-1.fc28 (FEDORA-2018-baf586308e) A 2D graphics library -------------------------------------------------------------------------------- Update Information: cairo 1.15.12 release. For details, see https://lists.cairographics.org/archives/cairo/2018-April/028594.html -------------------------------------------------------------------------------- References: [ 1 ] Bug #1503374 - None https://bugzilla.redhat.com/show_bug.cgi?id=1503374 -------------------------------------------------------------------------------- ================================================================================ cldr-emoji-annotation-33.0.0_1-1.fc28 (FEDORA-2018-3d9f043980) Emoji annotation files in CLDR -------------------------------------------------------------------------------- Update Information: Release 33 -------------------------------------------------------------------------------- ================================================================================ corosync-2.4.4-1.fc28 (FEDORA-2018-12da088117) The Corosync Cluster Engine and Application Programming Interfaces -------------------------------------------------------------------------------- Update Information: New upstream release with security fix for CVE-2018-1084 -------------------------------------------------------------------------------- References: [ 1 ] Bug #1552830 - CVE-2018-1084 corosync: Integer overflow in exec/totemcrypto.c:authenticate_nss_2_3() function https://bugzilla.redhat.com/show_bug.cgi?id=1552830 -------------------------------------------------------------------------------- ================================================================================ dep-0.4.1-2.fc28 (FEDORA-2018-79a6ef94f7) Go dependency management tool -------------------------------------------------------------------------------- Update Information: Obsolete godep -------------------------------------------------------------------------------- References: [ 1 ] Bug #1552568 - Remove obsolete godep package https://bugzilla.redhat.com/show_bug.cgi?id=1552568 -------------------------------------------------------------------------------- ================================================================================ dogtag-pki-10.6.0-1.fc28 (FEDORA-2018-5c7037b0da) Dogtag PKI Package -------------------------------------------------------------------------------- Update Information: Update to PKI 10.6.0-1 -------------------------------------------------------------------------------- ================================================================================ dogtag-pki-theme-10.6.0-1.fc28 (FEDORA-2018-5c7037b0da) Dogtag PKI Theme Package -------------------------------------------------------------------------------- Update Information: Update to PKI 10.6.0-1 -------------------------------------------------------------------------------- ================================================================================ environment-modules-4.1.2-1.fc28 (FEDORA-2018-a0a155f383) Provides dynamic modification of a user's environment -------------------------------------------------------------------------------- Update Information: rhbz#1565697 Errors when launching new terminal in specific directory -------------------------------------------------------------------------------- References: [ 1 ] Bug #1565697 - Errors when launching new terminal in specific directory https://bugzilla.redhat.com/show_bug.cgi?id=1565697 -------------------------------------------------------------------------------- ================================================================================ fedora-obsolete-packages-28-4 (FEDORA-2018-0306107fa4) A package to obsolete retired packages -------------------------------------------------------------------------------- Update Information: bind99, mozjs17, python2-zeroconf, python2-chromecast -------------------------------------------------------------------------------- ================================================================================ firefox-59.0.2-1.fc28 (FEDORA-2018-54aa882a3f) Mozilla Firefox Web browser -------------------------------------------------------------------------------- Update Information: Update to latest upstream version. -------------------------------------------------------------------------------- ================================================================================ gnome-initial-setup-3.28.0-6.fc28 (FEDORA-2018-2866ef37b1) Bootstrapping your OS -------------------------------------------------------------------------------- Update Information: Allow setting weak passwords -------------------------------------------------------------------------------- ================================================================================ gnome-shell-extension-system-monitor-applet-35-1.20180410git751d557.fc28 (FEDORA-2018-5533ac6819) A Gnome shell system monitor extension -------------------------------------------------------------------------------- Update Information: Updated to last upstream commits -------------------------------------------------------------------------------- ================================================================================ google-noto-cjk-fonts-20170602-6.fc28.1 (FEDORA-2018-a6b5aab7f5) Google Noto Sans CJK Fonts -------------------------------------------------------------------------------- Update Information: Revert the priority of fontconfig config file. This change is to revert the google-noto-cjk-fonts part of * https://fedoraproject.org/wiki/Changes/JPDefaultFontsToNoto * https://fedoraproject.org/wiki/Changes/KRDefaultFontsToNoto * https://fedoraproject.org/wiki/Changes/ChineseDefaultFontsToNoto -------------------------------------------------------------------------------- ================================================================================ gsequencer-1.4.25-1.fc28 (FEDORA-2018-0def28b258) Audio processing engine -------------------------------------------------------------------------------- Update Information: Rebuilt for https://fedoraproject.org/wiki/Fedora_28_Mass_Rebuild -------------------------------------------------------------------------------- ================================================================================ gsi-openssh-7.7p1-2.fc28 (FEDORA-2018-c35b231862) An implementation of the SSH protocol with GSI authentication -------------------------------------------------------------------------------- Update Information: Sync with openssh update. -------------------------------------------------------------------------------- ================================================================================ hanazono-fonts-20170904-2.fc28.1 (FEDORA-2018-5b6600ea4b) Japanese Mincho-typeface TrueType font -------------------------------------------------------------------------------- Update Information: Revert the priority of fontconfig config file. this change is to revert https://fedoraproject.org/wiki/Changes/JPDefaultFontsToNoto -------------------------------------------------------------------------------- ================================================================================ ipa-ex-gothic-fonts-002.01-11.fc28.1 (FEDORA-2018-5b6600ea4b) Japanese Gothic-typeface OpenType font by IPA -------------------------------------------------------------------------------- Update Information: Revert the priority of fontconfig config file. this change is to revert https://fedoraproject.org/wiki/Changes/JPDefaultFontsToNoto -------------------------------------------------------------------------------- ================================================================================ ipa-ex-mincho-fonts-002.01-11.fc28.1 (FEDORA-2018-5b6600ea4b) Japanese Mincho-typeface OpenType font by IPA -------------------------------------------------------------------------------- Update Information: Revert the priority of fontconfig config file. this change is to revert https://fedoraproject.org/wiki/Changes/JPDefaultFontsToNoto -------------------------------------------------------------------------------- ================================================================================ ipa-gothic-fonts-003.03-13.fc28.1 (FEDORA-2018-5b6600ea4b) Japanese Gothic-typeface OpenType font by IPA -------------------------------------------------------------------------------- Update Information: Revert the priority of fontconfig config file. this change is to revert https://fedoraproject.org/wiki/Changes/JPDefaultFontsToNoto -------------------------------------------------------------------------------- ================================================================================ ipa-mincho-fonts-003.03-13.fc28.1 (FEDORA-2018-5b6600ea4b) Japanese Mincho-typeface OpenType font by IPA -------------------------------------------------------------------------------- Update Information: Revert the priority of fontconfig config file. this change is to revert https://fedoraproject.org/wiki/Changes/JPDefaultFontsToNoto -------------------------------------------------------------------------------- ================================================================================ ipa-pgothic-fonts-003.03-12.fc28.1 (FEDORA-2018-5b6600ea4b) Japanese Proportional Gothic-typeface OpenType font by IPA -------------------------------------------------------------------------------- Update Information: Revert the priority of fontconfig config file. this change is to revert https://fedoraproject.org/wiki/Changes/JPDefaultFontsToNoto -------------------------------------------------------------------------------- ================================================================================ ipa-pmincho-fonts-003.03-12.fc28.1 (FEDORA-2018-5b6600ea4b) Japanese Proportional Mincho-typeface OpenType font by IPA -------------------------------------------------------------------------------- Update Information: Revert the priority of fontconfig config file. this change is to revert https://fedoraproject.org/wiki/Changes/JPDefaultFontsToNoto -------------------------------------------------------------------------------- ================================================================================ jsch-agent-proxy-0.0.8-8.fc28 (FEDORA-2018-796a58dc00) Proxy to ssh-agent and Pageant in Java -------------------------------------------------------------------------------- Update Information: Updates SVNKit to a newer version: https://svn.svnkit.com/repos/svnkit/tags/1.8.15/CHANGES.txt Also fixes failures to build from source. -------------------------------------------------------------------------------- References: [ 1 ] Bug #1556459 - sqljet: FTBFS in F28 https://bugzilla.redhat.com/show_bug.cgi?id=1556459 [ 2 ] Bug #1556436 - sequence-library: FTBFS in F28 https://bugzilla.redhat.com/show_bug.cgi?id=1556436 [ 3 ] Bug #1556479 - svnkit: FTBFS in F28 https://bugzilla.redhat.com/show_bug.cgi?id=1556479 -------------------------------------------------------------------------------- ================================================================================ libvarlink-8-1.fc28 (FEDORA-2018-f9a1719abc) Varlink C Library -------------------------------------------------------------------------------- Update Information: Add support for maps. ---- Update the interface definition syntax for arrays. -------------------------------------------------------------------------------- ================================================================================ libzapojit-0.0.3-13.fc28 (FEDORA-2018-fc1f02961d) GLib/GObject wrapper for the OneDrive and Hotmail REST APIs -------------------------------------------------------------------------------- Update Information: Rebuilt for https://fedoraproject.org/wiki/Fedora_28_Mass_Rebuild -------------------------------------------------------------------------------- ================================================================================ lksctp-tools-1.0.16-9.fc28 (FEDORA-2018-e278abc6d1) User-space access to Linux Kernel SCTP -------------------------------------------------------------------------------- Update Information: Rebuilt for https://fedoraproject.org/wiki/Fedora_28_Mass_Rebuild -------------------------------------------------------------------------------- ================================================================================ lm_sensors-3.4.0-12.fc28 (FEDORA-2018-c15bad127c) Hardware monitoring tools -------------------------------------------------------------------------------- Update Information: Use LDFLAGS when linking executables -------------------------------------------------------------------------------- References: [ 1 ] Bug #1548691 - lm_sensors: Partial injection of Fedora build flags https://bugzilla.redhat.com/show_bug.cgi?id=1548691 -------------------------------------------------------------------------------- ================================================================================ lockdev-1.0.4-0.26.20111007git.fc28 (FEDORA-2018-f0bb2398ed) A library for locking devices -------------------------------------------------------------------------------- Update Information: Rebuilt for https://fedoraproject.org/wiki/Fedora_28_Mass_Rebuild -------------------------------------------------------------------------------- ================================================================================ lollypop-0.9.500-1.fc28 (FEDORA-2018-2ed025c287) Music player for GNOME -------------------------------------------------------------------------------- Update Information: Update to 0.9.500 ---- Changed RR from pyplast to python2-pylast -------------------------------------------------------------------------------- ================================================================================ lua-expat-1.3.0-12.fc28 (FEDORA-2018-d1e92fcf30) SAX XML parser based on the Expat library -------------------------------------------------------------------------------- Update Information: - Build flags injection is only partially successful (#1565997) ---- Rebuilt for https://fedoraproject.org/wiki/Fedora_28_Mass_Rebuild -------------------------------------------------------------------------------- References: [ 1 ] Bug #1565997 - lua-expat: Partial Fedora build flags injection https://bugzilla.redhat.com/show_bug.cgi?id=1565997 -------------------------------------------------------------------------------- ================================================================================ mactel-boot-0.9-17.fc28 (FEDORA-2018-24a5449a71) Intel Mac boot files -------------------------------------------------------------------------------- Update Information: Rebuilt for https://fedoraproject.org/wiki/Fedora_28_Mass_Rebuild -------------------------------------------------------------------------------- ================================================================================ memtest86+-5.01-19.fc28 (FEDORA-2018-c1896ff6b9) Stand-alone memory tester for x86 and x86-64 computers -------------------------------------------------------------------------------- Update Information: Rebuilt for https://fedoraproject.org/wiki/Fedora_28_Mass_Rebuild -------------------------------------------------------------------------------- ================================================================================ mingw-libzip-1.5.1-1.fc28 (FEDORA-2018-46180b6ae9) C library for reading, creating, and modifying zip archives -------------------------------------------------------------------------------- Update Information: Update to libzip-1.5.1, see https://libzip.org/news/release-1.5.1.html for details. -------------------------------------------------------------------------------- ================================================================================ motoya-lcedar-fonts-1.00-0.16.20110406git.fc28.1 (FEDORA-2018-5b6600ea4b) Japanese Gothic-typeface TrueType fonts by MOTOYA Co,LTD -------------------------------------------------------------------------------- Update Information: Revert the priority of fontconfig config file. this change is to revert https://fedoraproject.org/wiki/Changes/JPDefaultFontsToNoto -------------------------------------------------------------------------------- ================================================================================ motoya-lmaru-fonts-1.00-0.16.20110406git.fc28.1 (FEDORA-2018-5b6600ea4b) Japanese Round Gothic-typeface TrueType fonts by MOTOYA Co,LTD -------------------------------------------------------------------------------- Update Information: Revert the priority of fontconfig config file. this change is to revert https://fedoraproject.org/wiki/Changes/JPDefaultFontsToNoto -------------------------------------------------------------------------------- ================================================================================ mozilla-noscript-10.1.7.5-1.fc28 (FEDORA-2018-a119d5d7df) JavaScript white list extension for Mozilla Firefox -------------------------------------------------------------------------------- Update Information: **NOTE**: All packaged Firefox add-ons are affected by Firefox bug fedora#1508827 . A workaround is provided in the bug report. Please do not give negative karma just because of that bug. # Changes in 10.x (Quantum) ## 10.1.7.5 * Fixed edge case CSP injection bug (thanks Rob Wu) * Optimized dynamic script injection (thanks Rob Wu) * Fixed potential leak on dynamic script injection (thanks Rob Wu for report) * Now NoScript's UI on privileged pages explains permissions cannot be configured there, rather than bluntly opening the Options page (thanks Rob Wu for suggestion) ## 10.1.7.4 * Fixed script enablement status not correctly detected on some pages rolling their own CSP (causing NOSCRIPT element and META refresh emulation not to be triggered) * Fixed "Appearance" NoScript Options tab missing on Android * [XSS] Fixed semicolon-separated JSON payloads DDOSing the JSON-optimizer, e.g. with syndication.twitter.com subframes (thanks KonomiKitten and pal1000 for reports) * [UI] Renamed "Scripts globally allowed (dangerous)" option to "No permissions enforcement (dangerous)" to better reflect its actual effect * [UI] Better feedback about "No permission enforcement" by disabling the "Preset customization" section and and the "Per-site Permissions" tab * [UI] Moved XSS-related options to the "Advanced" tab * Fixed disabled webgl breaking feeds on script-enabled sites (thanks pal1000 for reporting) * Enhanced dynamic script injection if browser.contentScripts API is available * Expanded support for webgl canvas placeholders # Changes in 5.x (Classic) ## 5.1.8.5 * Fixed edge case ABE Anon action loop with e10s enabled on reload after new rule (thanks barbaz for reporting) * Fixed JSON interactive view disabled by cascading restrictions (thanks jester for reporting) * Fixed ABE Anon action loop with e10s enabled (thanks barbaz for reporting) -------------------------------------------------------------------------------- References: [ 1 ] Bug #1557592 - mozilla-noscript-10.1.7.5 is available https://bugzilla.redhat.com/show_bug.cgi?id=1557592 -------------------------------------------------------------------------------- ================================================================================ mu-0.9.13-1.fc28 (FEDORA-2018-368e017dd6) A simple Python editor not only for micro:bit -------------------------------------------------------------------------------- Update Information: New version of the mu editor. It's now suitable for local Python development as well. -------------------------------------------------------------------------------- References: [ 1 ] Bug #1565626 - Review Request: python-nudatus - Strip comments from Python scripts https://bugzilla.redhat.com/show_bug.cgi?id=1565626 [ 2 ] Bug #1565603 - Review Request: python-microfs - CLI and Python module to work with BBC micro:bit filesystem https://bugzilla.redhat.com/show_bug.cgi?id=1565603 -------------------------------------------------------------------------------- ================================================================================ mythes-1.2.4-9.fc28 (FEDORA-2018-ef70a5fe7c) A thesaurus library -------------------------------------------------------------------------------- Update Information: Rebuilt for https://fedoraproject.org/wiki/Fedora_28_Mass_Rebuild -------------------------------------------------------------------------------- ================================================================================ mythes-en-3.0-20.fc28 (FEDORA-2018-87c668d68e) English thesaurus -------------------------------------------------------------------------------- Update Information: Rebuilt for https://fedoraproject.org/wiki/Fedora_28_Mass_Rebuild -------------------------------------------------------------------------------- ================================================================================ naver-nanum-fonts-3.020-20.20140930.fc28.1 (FEDORA-2018-bf451259e1) Nanum family of Korean TrueType fonts -------------------------------------------------------------------------------- Update Information: Revert the priority of fontconfig config file. this is to revert the change of https://fedoraproject.org/wiki/Changes/KRDefaultFontsToNoto -------------------------------------------------------------------------------- ================================================================================ nodejs-packaging-14-1.fc28 (FEDORA-2018-791b17a4fb) RPM Macros and Utilities for Node.js Packaging -------------------------------------------------------------------------------- Update Information: Only match top level modules for requires and provides generation -------------------------------------------------------------------------------- ================================================================================ oath-toolkit-2.6.1-6.fc28 (FEDORA-2018-e38334274e) One-time password components -------------------------------------------------------------------------------- Update Information: Rebuilt for https://fedoraproject.org/wiki/Fedora_28_Mass_Rebuild -------------------------------------------------------------------------------- ================================================================================ ocaml-ounit-2.0.8-1.fc28 (FEDORA-2018-fd226e358c) Unit test framework for OCaml -------------------------------------------------------------------------------- Update Information: Upstream Update -------------------------------------------------------------------------------- ================================================================================ openssh-7.7p1-2.fc28 (FEDORA-2018-4bcb8b924a) An open source implementation of SSH protocol version 2 -------------------------------------------------------------------------------- Update Information: Do not break quotes parsing in configuration file (#1566295) ---- This update brings new upstream release and improved PKCS#11 support. -------------------------------------------------------------------------------- References: [ 1 ] Bug #1566295 - vagrant ssh does not work passwordless with openssh-7.7 https://bugzilla.redhat.com/show_bug.cgi?id=1566295 [ 2 ] Bug #1563223 - openssh-7.7p1 is available https://bugzilla.redhat.com/show_bug.cgi?id=1563223 [ 3 ] Bug #1354510 - RFE: ECDSA support in PKCS #11 https://bugzilla.redhat.com/show_bug.cgi?id=1354510 -------------------------------------------------------------------------------- ================================================================================ passwd-0.80-2.fc28 (FEDORA-2018-3bc89b07e0) An utility for setting or changing passwords using PAM -------------------------------------------------------------------------------- Update Information: Removed autotools dependencies. -------------------------------------------------------------------------------- ================================================================================ perl-version-0.99.21-1.fc28 (FEDORA-2018-b01190cfb2) Perl extension for Version Objects -------------------------------------------------------------------------------- Update Information: This release fixes a compiler warning. ---- Updated to the latest version -------------------------------------------------------------------------------- References: [ 1 ] Bug #1566497 - perl-version-0.9921 is available https://bugzilla.redhat.com/show_bug.cgi?id=1566497 [ 2 ] Bug #1564935 - perl-version-0.9920 is available https://bugzilla.redhat.com/show_bug.cgi?id=1564935 -------------------------------------------------------------------------------- ================================================================================ php-egulias-email-validator2-2.1.4-1.fc28 (FEDORA-2018-b2cd22693a) A library for validating emails -------------------------------------------------------------------------------- Update Information: **Version 2.1.4** * DNS check should convert unicode domains first (#166) * fix checkdnsrr not handling unicode domains properly * fix for php7.2 -------------------------------------------------------------------------------- ================================================================================ php-zendframework-zend-filter-2.8.0-1.fc28 (FEDORA-2018-dc1a06cac7) Zend Framework Filter component -------------------------------------------------------------------------------- Update Information: **Version 2.8.0** - 2018-04-11 * **Added** - [#26](https://github.com/zendframework/zend-filter/pull/26) adds the interface `Zend\Filter\FilterProviderInterface`, which can be used to provide configuration for the `FilterPluginManager` via zend-mvc `Module` classes. - [#61](https://github.com/zendframework/zend-filter/pull/61) adds support for PHP 7.2. * **Removed** - [#61](https://github.com/zendframework/zend- filter/pull/61) removes support for PHP 5.5. - [#61](https://github.com/zendframework/zend-filter/pull/61) removes support for HHVM. - [#61](https://github.com/zendframework/zend-filter/pull/61) removes support for zend-crypt versions prior to 3.0. This was done as PHP deprecated the mcrypt extension starting in PHP 7.1, and does not ship it by default starting in PHP 7.2. zend-crypt 3.0 adds an OpenSSL adapter for its BlockCipher capabilities, and acts as a polyfill for mcrypt usage. Since this functionality has been used by default since 2.7.2, users should be able to upgrade seamlessly. -------------------------------------------------------------------------------- ================================================================================ php-zendframework-zend-test-3.2.0-1.fc28 (FEDORA-2018-14862a7239) Zend Framework Test component -------------------------------------------------------------------------------- Update Information: **Version 3.2.0** - 2018-04-07 * **Added** - [#60](https://github.com/zendframework/zend-test/pull/60) Added support for PHPUnit 7 - [#65](https://github.com/zendframework/zend-test/pull/65) Added support for query parameters in DELETE request in AbstractControllerTestCase * **Fixed** - [#63](https://github.com/zendframework/zend-test/pull/63) Fixed compatibility with PHP 7.2 -------------------------------------------------------------------------------- ================================================================================ pki-console-10.6.0-1.fc28 (FEDORA-2018-5c7037b0da) Dogtag PKI Console Package -------------------------------------------------------------------------------- Update Information: Update to PKI 10.6.0-1 -------------------------------------------------------------------------------- ================================================================================ pki-core-10.6.0-1.fc28 (FEDORA-2018-5c7037b0da) Dogtag PKI Core Package -------------------------------------------------------------------------------- Update Information: Update to PKI 10.6.0-1 -------------------------------------------------------------------------------- ================================================================================ pvs-sbcl-6.0-58.fc28 (FEDORA-2018-afc9dfa6ee) Interactive theorem prover from SRI -------------------------------------------------------------------------------- Update Information: Update to latest sbcl release, http://www.sbcl.org/all-news.html#1.4.6 -------------------------------------------------------------------------------- ================================================================================ python-colorspacious-1.1.2-1.fc28 (FEDORA-2018-ed4ee4ca97) Perform colorspace conversions accurately and easily -------------------------------------------------------------------------------- Update Information: Fixed bugs: * The coefficients for CAM02-LCD and CAM02-SCD should be the other way around. * Correct DIM and DARK surround N_c values. -------------------------------------------------------------------------------- References: [ 1 ] Bug #1562763 - python-colorspacious-1.1.1 is available https://bugzilla.redhat.com/show_bug.cgi?id=1562763 [ 2 ] Bug #1564870 - python-colorspacious-1.1.2 is available https://bugzilla.redhat.com/show_bug.cgi?id=1564870 -------------------------------------------------------------------------------- ================================================================================ python-geoip2-2.8.0-1.fc28 (FEDORA-2018-a92cf93fba) MaxMind GeoIP2 API -------------------------------------------------------------------------------- Update Information: Update to 2.8.0 -------------------------------------------------------------------------------- References: [ 1 ] Bug #1566486 - python-geoip2-v2.8.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=1566486 -------------------------------------------------------------------------------- ================================================================================ python-microfs-1.2.2-1.fc28 (FEDORA-2018-368e017dd6) CLI and Python module to work with BBC micro:bit filesystem -------------------------------------------------------------------------------- Update Information: New version of the mu editor. It's now suitable for local Python development as well. -------------------------------------------------------------------------------- References: [ 1 ] Bug #1565626 - Review Request: python-nudatus - Strip comments from Python scripts https://bugzilla.redhat.com/show_bug.cgi?id=1565626 [ 2 ] Bug #1565603 - Review Request: python-microfs - CLI and Python module to work with BBC micro:bit filesystem https://bugzilla.redhat.com/show_bug.cgi?id=1565603 -------------------------------------------------------------------------------- ================================================================================ python-nudatus-0.0.2-1.fc28 (FEDORA-2018-368e017dd6) Strip comments from Python scripts -------------------------------------------------------------------------------- Update Information: New version of the mu editor. It's now suitable for local Python development as well. -------------------------------------------------------------------------------- References: [ 1 ] Bug #1565626 - Review Request: python-nudatus - Strip comments from Python scripts https://bugzilla.redhat.com/show_bug.cgi?id=1565626 [ 2 ] Bug #1565603 - Review Request: python-microfs - CLI and Python module to work with BBC micro:bit filesystem https://bugzilla.redhat.com/show_bug.cgi?id=1565603 -------------------------------------------------------------------------------- ================================================================================ roundcubemail-1.3.6-1.fc28 (FEDORA-2018-c279b3696f) Round Cube Webmail is a browser-based multilingual IMAP client -------------------------------------------------------------------------------- Update Information: Upstream announcement: **Version 1.3.6** This is a security update to the stable version 1.3. It primarily fixes a recently discovered IMAP command injection vulnerability caused by insufficient input validation within the archive plugin. Details about the vulnerability are published under CVE-2018-9846. Additionally, we back-ported some minor fixes from the master branch which improve PHP 7.2 compatibility as well as PGP signing and key handling for those who use the Enigma plugin. See the complete changelog below. We strongly recommend to update all productive installations of Roundcube. Please do backup your data before updating! **CHANGELOG** * Fix parsing date strings (e.g. from a Date: mail header) with comments (#6216) * Fix PHP 7.2: count(): Parameter must be an array in enchant-based spellchecker (#6234) * Fix possible IMAP command injection and type juggling vulnerabilities (#6229) * Enigma: Fix key selection for signing * Enigma: Enable keypair generation on Internet Explorer 11 * Fix check_request() bypass in places using get_uids() [CVE-2018-9846] (#6238) * Fix bug where usernames without domain part could be malformed or converted to lower-case on logon (#6224) -------------------------------------------------------------------------------- ================================================================================ sazanami-fonts-0.20040629-30.fc28.1 (FEDORA-2018-5b6600ea4b) Sazanami Japanese TrueType fonts -------------------------------------------------------------------------------- Update Information: Revert the priority of fontconfig config file. this change is to revert https://fedoraproject.org/wiki/Changes/JPDefaultFontsToNoto -------------------------------------------------------------------------------- ================================================================================ sbcl-1.4.6-1.fc28 (FEDORA-2018-afc9dfa6ee) Steel Bank Common Lisp -------------------------------------------------------------------------------- Update Information: Update to latest sbcl release, http://www.sbcl.org/all-news.html#1.4.6 -------------------------------------------------------------------------------- ================================================================================ sequence-library-1.0.3-1.fc28 (FEDORA-2018-796a58dc00) Textual diff and merge library -------------------------------------------------------------------------------- Update Information: Updates SVNKit to a newer version: https://svn.svnkit.com/repos/svnkit/tags/1.8.15/CHANGES.txt Also fixes failures to build from source. -------------------------------------------------------------------------------- References: [ 1 ] Bug #1556459 - sqljet: FTBFS in F28 https://bugzilla.redhat.com/show_bug.cgi?id=1556459 [ 2 ] Bug #1556436 - sequence-library: FTBFS in F28 https://bugzilla.redhat.com/show_bug.cgi?id=1556436 [ 3 ] Bug #1556479 - svnkit: FTBFS in F28 https://bugzilla.redhat.com/show_bug.cgi?id=1556479 -------------------------------------------------------------------------------- ================================================================================ sfact-0.0-21.20130128gitbc56c68.fc28 (FEDORA-2018-fad19e0df2) Converts 3D model into G-Code for RepRap -------------------------------------------------------------------------------- Update Information: Fix broken pypy2 dependency. -------------------------------------------------------------------------------- References: [ 1 ] Bug #1565840 - upgrade of PYPY fails https://bugzilla.redhat.com/show_bug.cgi?id=1565840 -------------------------------------------------------------------------------- ================================================================================ skeinforge-12.03.14-31.fc28 (FEDORA-2018-b010f42633) Converts 3D model into G-Code for RepRap -------------------------------------------------------------------------------- Update Information: Fix broken pypy2 dependency. -------------------------------------------------------------------------------- References: [ 1 ] Bug #1565840 - upgrade of PYPY fails https://bugzilla.redhat.com/show_bug.cgi?id=1565840 -------------------------------------------------------------------------------- ================================================================================ sqljet-1.1.10-10.fc28 (FEDORA-2018-796a58dc00) Pure Java SQLite -------------------------------------------------------------------------------- Update Information: Updates SVNKit to a newer version: https://svn.svnkit.com/repos/svnkit/tags/1.8.15/CHANGES.txt Also fixes failures to build from source. -------------------------------------------------------------------------------- References: [ 1 ] Bug #1556459 - sqljet: FTBFS in F28 https://bugzilla.redhat.com/show_bug.cgi?id=1556459 [ 2 ] Bug #1556436 - sequence-library: FTBFS in F28 https://bugzilla.redhat.com/show_bug.cgi?id=1556436 [ 3 ] Bug #1556479 - svnkit: FTBFS in F28 https://bugzilla.redhat.com/show_bug.cgi?id=1556479 -------------------------------------------------------------------------------- ================================================================================ svnkit-1.8.15-2.fc28 (FEDORA-2018-796a58dc00) Pure Java library to manage Subversion working copies and repositories -------------------------------------------------------------------------------- Update Information: Updates SVNKit to a newer version: https://svn.svnkit.com/repos/svnkit/tags/1.8.15/CHANGES.txt Also fixes failures to build from source. -------------------------------------------------------------------------------- References: [ 1 ] Bug #1556459 - sqljet: FTBFS in F28 https://bugzilla.redhat.com/show_bug.cgi?id=1556459 [ 2 ] Bug #1556436 - sequence-library: FTBFS in F28 https://bugzilla.redhat.com/show_bug.cgi?id=1556436 [ 3 ] Bug #1556479 - svnkit: FTBFS in F28 https://bugzilla.redhat.com/show_bug.cgi?id=1556479 -------------------------------------------------------------------------------- ================================================================================ uflash-1.1.2-2.fc28 (FEDORA-2018-368e017dd6) A module and utility to flash Python onto the BBC micro:bit -------------------------------------------------------------------------------- Update Information: New version of the mu editor. It's now suitable for local Python development as well. -------------------------------------------------------------------------------- References: [ 1 ] Bug #1565626 - Review Request: python-nudatus - Strip comments from Python scripts https://bugzilla.redhat.com/show_bug.cgi?id=1565626 [ 2 ] Bug #1565603 - Review Request: python-microfs - CLI and Python module to work with BBC micro:bit filesystem https://bugzilla.redhat.com/show_bug.cgi?id=1565603 -------------------------------------------------------------------------------- ================================================================================ un-core-fonts-1.0.2-0.31.080608.fc28.1 (FEDORA-2018-bf451259e1) Un Core family of Korean TrueType fonts -------------------------------------------------------------------------------- Update Information: Revert the priority of fontconfig config file. this is to revert the change of https://fedoraproject.org/wiki/Changes/KRDefaultFontsToNoto -------------------------------------------------------------------------------- ================================================================================ vlgothic-fonts-20141206-10.fc28.1 (FEDORA-2018-5b6600ea4b) Japanese TrueType font -------------------------------------------------------------------------------- Update Information: Revert the priority of fontconfig config file. this change is to revert https://fedoraproject.org/wiki/Changes/JPDefaultFontsToNoto -------------------------------------------------------------------------------- ================================================================================ xorg-x11-drv-libinput-0.27.1-2.fc28 (FEDORA-2018-78124e6948) Xorg X11 libinput input driver -------------------------------------------------------------------------------- Update Information: Build on s390x (#1565062) ---- xorg-x11-drv-libinput 0.27.1, fixes some issues with settings getting overwritten after resume (or vt switch) -------------------------------------------------------------------------------- References: [ 1 ] Bug #1565062 - Please enable the "xorg-x11-drv-libinput" and/or "xorg-x11-drv-evdev" package for s390x, too https://bugzilla.redhat.com/show_bug.cgi?id=1565062 -------------------------------------------------------------------------------- _______________________________________________ test mailing list -- test@xxxxxxxxxxxxxxxxxxxxxxx To unsubscribe send an email to test-leave@xxxxxxxxxxxxxxxxxxxxxxx