The following Fedora 30 Security updates need testing: Age URL 27 https://bodhi.fedoraproject.org/updates/FEDORA-2019-71b2273a9f libarchive-3.3.3-7.fc30 9 https://bodhi.fedoraproject.org/updates/FEDORA-2019-69da274284 grub2-2.02-87.fc30 6 https://bodhi.fedoraproject.org/updates/FEDORA-2019-9d83929ffa libyang-1.0.101-1.fc30 6 https://bodhi.fedoraproject.org/updates/FEDORA-2019-86bceb61b3 openslp-2.0.0-22.fc30 6 https://bodhi.fedoraproject.org/updates/FEDORA-2019-11dddb785b samba-4.10.11-0.fc30 6 https://bodhi.fedoraproject.org/updates/FEDORA-2019-1cec196e20 git-2.21.1-1.fc30 4 https://bodhi.fedoraproject.org/updates/FEDORA-2019-533a72fec5 fribidi-1.0.5-5.fc30 4 https://bodhi.fedoraproject.org/updates/FEDORA-2019-46b6bd2459 libssh-0.9.3-1.fc30 4 https://bodhi.fedoraproject.org/updates/FEDORA-2019-6bf27b45b3 cacti-1.2.8-1.fc30 cacti-spine-1.2.8-1.fc30 3 https://bodhi.fedoraproject.org/updates/FEDORA-2019-8f27a14efa chromium-79.0.3945.79-1.fc30 3 https://bodhi.fedoraproject.org/updates/FEDORA-2019-2e12bd3a9a xen-4.11.3-2.fc30 3 https://bodhi.fedoraproject.org/updates/FEDORA-2019-1051e10c1e wordpress-5.3.1-1.fc30 3 https://bodhi.fedoraproject.org/updates/FEDORA-2019-3230b2aae9 spamassassin-3.4.3-1.fc30 3 https://bodhi.fedoraproject.org/updates/FEDORA-2019-c7b5103d2a unbound-1.9.6-1.fc30 1 https://bodhi.fedoraproject.org/updates/FEDORA-2019-c4177f74f5 drupal7-l10n_update-2.3-1.fc30 1 https://bodhi.fedoraproject.org/updates/FEDORA-2019-6abe00cae1 drupal7-webform-4.21-1.fc30
The following Fedora 30 Critical Path updates have yet to be approved: Age URL 159 https://bodhi.fedoraproject.org/updates/FEDORA-2019-c05e4425d1 dash-0.5.10.2-3.fc30 27 https://bodhi.fedoraproject.org/updates/FEDORA-2019-71b2273a9f libarchive-3.3.3-7.fc30 19 https://bodhi.fedoraproject.org/updates/FEDORA-2019-ed226e6112 xorg-x11-server-1.20.6-1.fc30 13 https://bodhi.fedoraproject.org/updates/FEDORA-2019-5444d14308 hwdata-0.330-1.fc30 13 https://bodhi.fedoraproject.org/updates/FEDORA-2019-388010ce63 alsa-firmware-1.2.1-2.fc30 alsa-lib-1.2.1.2-3.fc30 alsa-plugins-1.2.1-1.fc30 alsa-utils-1.2.1-3.fc30 11 https://bodhi.fedoraproject.org/updates/FEDORA-2019-1c4b3119a7 passwd-0.80-7.fc30 11 https://bodhi.fedoraproject.org/updates/FEDORA-2019-0d122cc67a dnf-4.2.17-1.fc30 dnf-plugins-core-4.0.12-1.fc30 libcomps-0.1.14-1.fc30 libdnf-0.39.1-1.fc30 microdnf-3.3.0-1.fc30 9 https://bodhi.fedoraproject.org/updates/FEDORA-2019-32a8da0e3a bash-5.0.11-1.fc30 9 https://bodhi.fedoraproject.org/updates/FEDORA-2019-69da274284 grub2-2.02-87.fc30 9 https://bodhi.fedoraproject.org/updates/FEDORA-2019-b436a3156c gnupg2-2.2.18-2.fc30 9 https://bodhi.fedoraproject.org/updates/FEDORA-2019-df017ddeb7 pungi-4.1.41-3.fc30 8 https://bodhi.fedoraproject.org/updates/FEDORA-2019-decb570505 python-jsonschema-3.2.0-1.fc30 6 https://bodhi.fedoraproject.org/updates/FEDORA-2019-bd81ed62bf make-4.2.1-14.fc30 6 https://bodhi.fedoraproject.org/updates/FEDORA-2019-1cec196e20 git-2.21.1-1.fc30 6 https://bodhi.fedoraproject.org/updates/FEDORA-2019-3454e38e8c supermin-5.1.20-11.fc30 6 https://bodhi.fedoraproject.org/updates/FEDORA-2019-212afebfaf emacs-26.3-1.fc30 6 https://bodhi.fedoraproject.org/updates/FEDORA-2019-11dddb785b samba-4.10.11-0.fc30 6 https://bodhi.fedoraproject.org/updates/FEDORA-2019-8bcab526a8 tigervnc-1.10.0-2.fc30 6 https://bodhi.fedoraproject.org/updates/FEDORA-2019-395944db07 glib-networking-2.60.4-1.fc30 6 https://bodhi.fedoraproject.org/updates/FEDORA-2019-11d1e41933 librepo-1.11.1-1.fc30 4 https://bodhi.fedoraproject.org/updates/FEDORA-2019-6a84b238e6 libedit-3.1-30.20191211cvs.fc30 4 https://bodhi.fedoraproject.org/updates/FEDORA-2019-46b6bd2459 libssh-0.9.3-1.fc30 3 https://bodhi.fedoraproject.org/updates/FEDORA-2019-2e12bd3a9a xen-4.11.3-2.fc30 3 https://bodhi.fedoraproject.org/updates/FEDORA-2019-daed517e5f vim-8.1.2424-1.fc30 1 https://bodhi.fedoraproject.org/updates/FEDORA-2019-ac42964ba4 kernel-5.3.16-200.fc30
The following builds have been pushed to Fedora 30 updates-testing
OpenIPMI-2.0.28-1.fc30 conda-4.6.14-1.fc30 cyrus-imapd-3.0.13-1.fc30 drupal7-7.68-2.fc30 electron-cash-4.0.12-1.fc30 libmicrohttpd-0.9.69-1.fc30 libsigrokdecode-0.5.3-1.fc30 nv-codec-headers-9.0.18.3-1.fc30 pcp-5.0.2-1.fc30 python-iso3166-1.0.1-1.fc30 python3-3.7.5-2.fc30 taigo-0.3-1.fc30
Details about builds:
================================================================================ OpenIPMI-2.0.28-1.fc30 (FEDORA-2019-5a0ece4925) IPMI (Intelligent Platform Management Interface) library and tools -------------------------------------------------------------------------------- Update Information:
New OpenIPMI version (mostly minor bugfixes) -------------------------------------------------------------------------------- ChangeLog:
* Mon Dec 16 2019 Vaclav Dolezal vdolezal@redhat.com - 2.0.28-1 - New upstream release 2.0.28 * Thu Oct 3 2019 Miro Hron��ok mhroncok@redhat.com - 2.0.27-5 - Rebuilt for Python 3.8.0rc1 (#1748018) * Mon Aug 19 2019 Miro Hron��ok mhroncok@redhat.com - 2.0.27-4 - Rebuilt for Python 3.8 --------------------------------------------------------------------------------
================================================================================ conda-4.6.14-1.fc30 (FEDORA-2019-e2b89d8da8) Cross-platform, Python-agnostic binary package manager -------------------------------------------------------------------------------- Update Information:
- Update to 4.6.14 - Make "conda shell.bash hook" work (bz#1737165) - Use system py-cpuinfo - Unbundle more libraries -------------------------------------------------------------------------------- ChangeLog:
* Sun Dec 15 2019 Orion Poplawski orion@nwra.com - 4.6.14-1 - Update 4.6.14 - Make "conda shell.bash hook" work (bz#1737165) - Use system py-cpuinfo - Unbundle more libraries -------------------------------------------------------------------------------- References:
[ 1 ] Bug #1737165 - "conda shell.bash hook" command fails https://bugzilla.redhat.com/show_bug.cgi?id=1737165 --------------------------------------------------------------------------------
================================================================================ cyrus-imapd-3.0.13-1.fc30 (FEDORA-2019-7938c21723) A high-performance email, contacts and calendar server -------------------------------------------------------------------------------- Update Information:
Update to new upstream version 3.0.13, which includes a fix for CVE-2019-19783 and other minor fixes. Release notes: https://www.cyrusimap.org/imap/download/release-notes/3.0/x/3.0.13.html -------------------------------------------------------------------------------- ChangeLog:
* Mon Dec 16 2019 Jason L Tibbitts III tibbs@math.uh.edu - 3.0.13-1 - Update to 3.0.13, fixing CVE-2019-19783. -------------------------------------------------------------------------------- References:
[ 1 ] Bug #1783836 - cyrus-imapd-3.0.13 is available https://bugzilla.redhat.com/show_bug.cgi?id=1783836 --------------------------------------------------------------------------------
================================================================================ drupal7-7.68-2.fc30 (FEDORA-2019-5f1a2cc839) An open-source content-management platform -------------------------------------------------------------------------------- Update Information:
RPM notes: - All docs are now in `/usr/share/doc/drupal7/` - All licenses are now in `/usr/share/licenses/drupal7/` - Requires have been updated to include all [phpcompatinfo](http://php5.laurent-laville.org/compatinfo/) extension findings ### 7.68 Maintenance release of the Drupal 7 series. Includes bug fixes and small API/feature improvements only (no major, non-backwards- compatible new functionality). No security fixes are included in this release. **This is the first release to fully support PHP 7.3. Please test and report any bugs in the issue queue.** No changes have been made to robots.txt in this release, so upgrading custom versions of that file is not necessary. However, changes have been made to .htaccess, web.config and sites/default/default.settings.php in this release. The .htaccess and web.config changes are detailed in this Change Record: - Access to web.config is blocked in .htaccess (and vice-versa): https://www.drupal.org/node/3098687 Upgrading custom versions of .htaccess and web.config to incorporate this change is recommended, but not required. There is one change to the sites/default/default.settings.php file in this release, but the only change is to file permissions: - [Regression] Fix default.settings.php permission: https://www.drupal.org/node/3035772 #### Major changes since 7.67 - Fully support PHP 7.3 - drupal_http_request() accepts data as an array in Drupal 7 - Access to web.config is blocked in .htaccess (and vice-versa) - New "scripts" element - theme_table() takes an optional footer variable and produces <tfoot> #### All changes since 7.67 - #3098664 by mcdruid: drupal_http_build_query() only accepts arrays (followup to #3059391) - #3097342 by mcdruid, Fabianx: Prepare Drupal 7.68 (CHANGELOG.txt) - #3088938 by DamienMcKenna, webchick, mcdruid: Update the D7 maintainers list - #2902430 by stefanos.petrakis, joseph.olstad, SergFromSD, kiamlaluno, Ayesh, mcdruid, alexpott: [PHP 7.1] A non-numeric value encountered in theme_pager() - #2472025 by stupiddingo, stefanos.petrakis: [D7] Hide toolbar when printing - #2171113 by Pol, wiifm, mw4ll4c3, David_Rothstein, douggreen, Fabianx: Settings returned via ajax are not run through hook_js_alter() - #3059391 by Liam Morland: Use drupal_http_build_query() in drupal_http_request() - #2966335 by mcdruid, dvandijk, David_Rothstein: Avoid DrupalRequestSanitizer not found fatal error when bootstrap phase order is changed - #3025335 by mcdruid, mfb, joseph.olstad, Fabianx, kiamlaluno, Pol: [PHP 7.3] Cannot change session id when session is active - #3055805 by mcdruid, greggles, Ayesh, Darren Oh, David_Rothstein, sidharrell, pwolanin, mkalkbrenner, Sweetchuck, YesCT: file.inc generated .htaccess does not cover PHP 7 - #3047412 by mcdruid, Chi, beckydev, DKAN, alexpott, sammuell, rabbitlair, longwave, greggles, interX: Block web.config in .htaccess (and vice-versa) - #3047844 by mfb, jordanwood, Taran2L: Fix test failures on PHP 5.3 - #3088557: Add mcdruid as provisional Drupal 7 branch maintainer - #3051370 by Pol, markcarver, Fabianx: Create "scripts" element to align rendering workflow to how "styles" are handled - #2814031 by Liam Morland: In drupal_http_request(), allow passing data as array - #1861604 by hefox, joseph.olstad, Sivaji, mgifford, webchick: Skip module_invoke/module_hook in calling hook_watchdog (excessive function_exist) - #2666908 by iamEAP, cilefen: HTTP status 200 returned for ���Additional uncaught exception thrown while handling exception��� - #1892654 by Pol, willvincent, Fabianx: D7 Backport: theme_table() should take an optional footer variable and produce - #3009351 by Pol, mfb, BrianLP: [PHP ��� 7.2] "session_id(): Cannot change session id" - #2684337 by geoffray, Pol, jweowu, Fabianx: Warning: uasort() expects parameter 1 to be array, null given in node_view_multiple() - #3035772 by Pol: [Regression] Fix default.settings.php permission -------------------------------------------------------------------------------- ChangeLog:
* Mon Dec 16 2019 Shawn Iwinski shawn.iwinski@gmail.com - 7.68-2 - Fix ssh2 dependency (`php-ssh2` => `php-pecl(ssh2)`) * Sat Dec 14 2019 Shawn Iwinski shawn.iwinski@gmail.com - 7.68-1 - Update to 7.68 (RHBZ #1779680) - Use official drupal.org source - Expand requires to include full phpcompatinfo findings - Spec, docs, licenses, and %files revamp -------------------------------------------------------------------------------- References:
[ 1 ] Bug #1779680 - drupal7-7.68 is available https://bugzilla.redhat.com/show_bug.cgi?id=1779680 --------------------------------------------------------------------------------
================================================================================ electron-cash-4.0.12-1.fc30 (FEDORA-2019-8b2e562ac8) A lightweight Bitcoin Cash client -------------------------------------------------------------------------------- Update Information:
Updated to 4.0.12 -------------------------------------------------------------------------------- ChangeLog:
* Sat Dec 14 2019 Jonny Heggheim hegjon@gmail.com - 4.0.12-1 - Updated to version 4.0.12 --------------------------------------------------------------------------------
================================================================================ libmicrohttpd-0.9.69-1.fc30 (FEDORA-2019-5cd9281cd0) Lightweight library for embedding a webserver in applications -------------------------------------------------------------------------------- Update Information:
Update to 0.9.69-1 -------------------------------------------------------------------------------- ChangeLog:
* Mon Dec 16 2019 Martin Gansser martinkg@fedoraproject.org - 1:0.9.69-1 - Update to 1:0.9.69 --------------------------------------------------------------------------------
================================================================================ libsigrokdecode-0.5.3-1.fc30 (FEDORA-2019-eef37a5ef1) Basic API for running protocol decoders -------------------------------------------------------------------------------- Update Information:
https://www.sigrok.org/blog/libsigrokdecode-053-released -------------------------------------------------------------------------------- ChangeLog:
* Mon Dec 16 2019 Dan Hor��k <dan[at]danny.cz> - 0.5.3-1 - updated to 0.5.3 * Mon Aug 19 2019 Miro Hron��ok mhroncok@redhat.com - 0.5.2-4 - Rebuilt for Python 3.8 * Thu Jul 25 2019 Fedora Release Engineering releng@fedoraproject.org - 0.5.2-3 - Rebuilt for https://fedoraproject.org/wiki/Fedora_31_Mass_Rebuild --------------------------------------------------------------------------------
================================================================================ nv-codec-headers-9.0.18.3-1.fc30 (FEDORA-2019-56ab0b3b3a) FFmpeg version of Nvidia Codec SDK headers -------------------------------------------------------------------------------- Update Information:
- Update -------------------------------------------------------------------------------- ChangeLog:
* Mon Dec 16 2019 Leigh Scott leigh123linux@gmail.com - 9.0.18.3-1 - Update to 9.0.18.3 --------------------------------------------------------------------------------
================================================================================ pcp-5.0.2-1.fc30 (FEDORA-2019-ccf3d6be10) System-level performance monitoring and performance management -------------------------------------------------------------------------------- Update Information:
- Server-side utilities and log management scripts: pmproxy: REST API to report all label values by name pmproxy: fix memory leak when re- using http connections pmproxy: fix memory leak on a failed REST API call pmproxy: improvements to the instrumentation mechanism pmproxy: add support for AF_UNIX local client connections logutil: fix pmlogger service timeout on new installations pmie: on SIGTERM, exit 0 for a normal shutdown rather than exit 15 pmcd: add labels PDUs into the trace set - PMDA additions, enhancements and bug fixes: pmdaproc: support for kernel cgroups v2 (and systemd using same) pmdalinux: update per-device read_bytes, write_bytes metric types pmdabpftrace: implement label callback pmdabpftrace: clear context tab on endcontext pmdanetcheck: run as pcp user, document ICMP Echo socket permissions pmdaperfevent: fix memory leaks and remove some unused code - Client tools and utilities: pcp-atop: update to latest upstream atop v2.5.0 sources pcp-dstat: no stack trace when dstat exits due to a signal pcp-dstat: fix handling of very large numbers of disk devices pcp-dstat: exit with code zero when archive end reached pmieconf: add a pcp-zeroconf option for enabling all_threads pmseries: fix pointer arithmetic on series ID set intersection pmseries: add new option to report all label values by name pmseries: fix and test regular expression pattern matching - libpcp, libpcp_pmda, libpcp_mmv, libpcp_web and language bindings libpcp: fix potential use-after-free in labels code libpcp_web: fix file descriptor and memory leaks in discovery code libpcp_web: resolve valgrind issues observed in qa tests libpcp_pmda: show PM_ERR_VALUE errors only if libpmda debug flag set python API: add endcontext callback for PMDAs python API: resolve pylint warnings on all python modules python API: add missing fields to pmLabelSets structure - Misc build, infrastructure and packaging updates: configure: make build reproducible configure: make zlib available for hdr_histogram checks build: do not create dstat symlink when non-python build requested build: add perl-High-Res rpm dependency for pcp-pmda-postfix build: update deb packaging to allow for python3-only builds build: resolve several rpm spec differences that have crept in build: fix chan lib dependency of pcp-pmda-statsd rpm build: fix hostname dependency of pcp rpm - Security Enhanced Linux: pmdaunbound: add selinux policy for unbound PMDA metrics pmdanetcheck: resolve failure on latest f31 pmdabpftrace: resolve failure on latest f31 pmdabcc: fix AVC error when running /var/lib/pcp/pmdas/bcc/Install pmie: add fsetid to pmie start script policy as done for pmlogger - Documentation and QA infrastructure: CI: initial new version using custom Azure Pipelines agents and Ansible CI: simplified architecture, added pipeline definitions CI: create JUnit test results file for Azure Pipelines CI: run platform builds and tests in parallel docs: Added to pmseries(1) man page docs: Added Redis setup notes to the quickstart guide docs: Complete coverage in man pages of long options in PCP utilities. docs: Numerous man page consistency fixes docs: details for pmSeriesSetup(3) and related async APIs docs: details for pmDiscoverSetup(3) and related async APIs docs: details for pmSeriesQuery(3) and related time series APIs docs: details for pmSeriesDescs(3) and other time series metadata APIs -------------------------------------------------------------------------------- ChangeLog:
* Wed Dec 11 2019 Nathan Scott nathans@redhat.com - 5.0.2-1 - Resolve fresh install pmlogger timeout bug (BZ 1721223) - Fix dstat exception writing to a closed fd (BZ 1768619) - Fix chan lib dependency of pcp-pmda-statsd (BZ 1770815) - Update to latest PCP sources. --------------------------------------------------------------------------------
================================================================================ python-iso3166-1.0.1-1.fc30 (FEDORA-2019-e6b6fe8740) Self-contained ISO 3166-1 country definitions -------------------------------------------------------------------------------- Update Information:
Include test files in source distribution -------------------------------------------------------------------------------- ChangeLog:
* Mon Dec 16 2019 Mohamed El Morabity melmorabity@fedoraproject.org - 1.0.1-1 - Update to 1.0.1 - Add tests -------------------------------------------------------------------------------- References:
[ 1 ] Bug #1783490 - python-iso3166-1.0.1 is available https://bugzilla.redhat.com/show_bug.cgi?id=1783490 --------------------------------------------------------------------------------
================================================================================ python3-3.7.5-2.fc30 (FEDORA-2019-888f4b53e8) Interpreter of the Python programming language -------------------------------------------------------------------------------- Update Information:
Backport `-k` and `-a` options for `pathfix.py` to allow keeping and adding shebang flags. -------------------------------------------------------------------------------- ChangeLog:
* Thu Dec 5 2019 Patrik Kopkan pkopkan@redhat.com - 3.7.5-2 - pathfix.py: add -k (keep) and -a (add) command line options, assume all .py files are Python scripts when working recursively - This changes will lead to having macros that will fix (#1335203) --------------------------------------------------------------------------------
================================================================================ taigo-0.3-1.fc30 (FEDORA-2019-6b91c16cf9) Virtual pet for your desktop built with GTK+, Vala, and love -------------------------------------------------------------------------------- Update Information:
Update to latest version -------------------------------------------------------------------------------- ChangeLog:
* Mon Dec 16 2019 Artem Polishchuk ego.cordatus@gmail.com - 0.3-1 - Update to 0.3 --------------------------------------------------------------------------------