Fedora EPEL 8 updates-testing report
by updates@fedoraproject.org
The following Fedora EPEL 8 Security updates need testing:
Age URL
6 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2023-ee729bf9b2 sympa-6.2.72-2.el8
1 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2023-d55abd83c7 perl-HTML-StripScripts-1.06-22.el8
1 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2023-e14003b86d syncthing-1.23.5-1.el8
The following builds have been pushed to Fedora EPEL 8 updates-testing
chromium-114.0.5735.106-1.el8
icewm-3.4.0-2.el8
radare2-5.8.6-1.el8
tmt-1.24.1-1.el8
Details about builds:
================================================================================
chromium-114.0.5735.106-1.el8 (FEDORA-EPEL-2023-c018b37680)
A WebKit (Blink) powered web browser that Google doesn't want you to use
--------------------------------------------------------------------------------
Update Information:
update to 114.0.5735.106. Fixes the following security issue: CVE-2023-3709
--------------------------------------------------------------------------------
ChangeLog:
* Wed Jun 7 2023 Than Ngo <than(a)redhat.com> - 114.0.5735.106-1
- update to 114.0.5735.106
* Sun May 28 2023 Than Ngo <than(a)redhat.com> - 114.0.5735.45-1
- update to 114.0.5735.45
- add qt6 linuxui backend
- backport: handle scale factor changes
- backport: fix font double_scaling
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #2212975 - CVE-2023-3079 chromium: chromium-browser: Type Confusion in V8 [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2212975
[ 2 ] Bug #2212976 - CVE-2023-3079 chromium: chromium-browser: Type Confusion in V8 [epel-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2212976
--------------------------------------------------------------------------------
================================================================================
icewm-3.4.0-2.el8 (FEDORA-EPEL-2023-6239221bd9)
Window manager designed for speed, usability, and consistency
--------------------------------------------------------------------------------
Update Information:
Update to latest version
--------------------------------------------------------------------------------
ChangeLog:
* Fri Jun 9 2023 Artem Polishchuk <ego.cordatus(a)gmail.com> - 3.4.0-1
- chore: Update to 3.4.0 (rhbz#2212455)
* Fri May 19 2023 Artem Polishchuk <ego.cordatus(a)gmail.com> - 3.3.5-1
- chore: Update to 3.3.5
--------------------------------------------------------------------------------
================================================================================
radare2-5.8.6-1.el8 (FEDORA-EPEL-2023-3dd846c7ab)
The reverse engineering framework
--------------------------------------------------------------------------------
Update Information:
Bump to 5.8.6
--------------------------------------------------------------------------------
ChangeLog:
* Tue May 23 2023 Michal Ambroz <rebus at, seznam.cz> 5.8.6-1
- bump to 5.8.6
* Sat Mar 25 2023 Michal Ambroz <rebus at, seznam.cz> 5.8.5-0.3
- 5.8.5 rebuild from git, patched for segfault
* Wed Mar 22 2023 Michal Ambroz <rebus at, seznam.cz> 5.8.4-2
- patch for segfault in sdb_hash
* Thu Mar 16 2023 Michal Ambroz <rebus at, seznam.cz> 5.8.4-1
- bump to 5.8.4
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #2157016 - CVE-2022-4843 radare2: Fix null deref in io.bank [epel-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2157016
[ 2 ] Bug #2170036 - syscall detection is broken
https://bugzilla.redhat.com/show_bug.cgi?id=2170036
[ 3 ] Bug #2178851 - radare2-5.8.6 is available
https://bugzilla.redhat.com/show_bug.cgi?id=2178851
[ 4 ] Bug #2179047 - iaito-5.8.6 is available
https://bugzilla.redhat.com/show_bug.cgi?id=2179047
--------------------------------------------------------------------------------
================================================================================
tmt-1.24.1-1.el8 (FEDORA-EPEL-2023-abfe39d5aa)
Test Management Tool
--------------------------------------------------------------------------------
Update Information:
Automatic update for tmt-1.24.1-1.el8. ##### **Changelog for tmt** ``` * Fri
Jun 09 2023 Petr ��pl��chal <psplicha(a)redhat.com> - 1.24.1-1 - Revert the
`Source0` url to the original value - Use correct url for the release archive,
fix docs * Wed Jun 07 2023 Petr ��pl��chal <psplicha(a)redhat.com> - 1.24.0-1 - Do
not display guest facts when showing a plan - Add new guide/summary for
multihost testing - Define a "plugin registry" class - Hide `facts` in the
`virtual` provision plugin - Cache resolved linters - Improve documentation of
lint checks (#2089) - A custom wrapper for options instead of click.option() -
Identify incorrect subcommand after a correct one - Remove one extra space
between @ and decorator name - Assign envvars to Polarion report arguments -
Expose "key address" to normalization callbacks (#1869) - Move export of special
test/plan/story fields to their respective classes - Expose guest topology to
tests and scripts (#2072) - Enable building downstream release using Packit -
Add sections for environment variable groups - Add default envvar to plugin
options - Load env TMT_WORKDIR_ROOT when running tmt status (#2087) -
Opportunistically use "selectable" entry_points. - Explicitly convert tmpdir to
str in test_utils.py. - Move pytest.ini contents to pyproject.toml. - Rename
Require* classes to Dependency* (#2099) - Expose fmf ID of tests in results -
Use the `tmt-lint` pre-commit hook - Turn finish step implementation to queue-
based one (#2110) - Convert base classes to data classes (#2080) - Crashed
prepare and execute steps propagate all causes - Support exceptions with
multiple causes - Make "needs sudo" a guest fact (#2096) - Test data path must
use safe guest/test names - Support for multi case import from Polarion and
Polarion as only source (#2084) - Fix search function in docs - Make tmt test
wrapper name unique to avoid race conditions - Change link-polarion argument
default to false - Add export plugin for JSON (#2058) - Handle el6 as a legacy
os too in virtual provision - Hint beakerlib is old when result parsing fails -
Revert "Fix dry mode handling when running a remote plan" - Set a new dict
instance to the Plan class - Replaces "common" object with logger in method hint
logging - Parallelize prepare and execute steps - Formalizing guest "facts"
storage - Support urllib3 2.x and its allowed_methods/method_whitelist - Require
setuptools ```
--------------------------------------------------------------------------------
ChangeLog:
* Fri Jun 9 2023 Petr ��pl��chal <psplicha(a)redhat.com> - 1.24.1-1
- Revert the `Source0` url to the original value
- Use correct url for the release archive, fix docs
* Wed Jun 7 2023 Petr ��pl��chal <psplicha(a)redhat.com> - 1.24.0-1
- Do not display guest facts when showing a plan
- Add new guide/summary for multihost testing
- Define a "plugin registry" class
- Hide `facts` in the `virtual` provision plugin
- Cache resolved linters
- Improve documentation of lint checks (#2089)
- A custom wrapper for options instead of click.option()
- Identify incorrect subcommand after a correct one
- Remove one extra space between @ and decorator name
- Assign envvars to Polarion report arguments
- Expose "key address" to normalization callbacks (#1869)
- Move export of special test/plan/story fields to their respective classes
- Expose guest topology to tests and scripts (#2072)
- Enable building downstream release using Packit
- Add sections for environment variable groups
- Add default envvar to plugin options
- Load env TMT_WORKDIR_ROOT when running tmt status (#2087)
- Opportunistically use "selectable" entry_points.
- Explicitly convert tmpdir to str in test_utils.py.
- Move pytest.ini contents to pyproject.toml.
- Rename Require* classes to Dependency* (#2099)
- Expose fmf ID of tests in results
- Use the `tmt-lint` pre-commit hook
- Turn finish step implementation to queue-based one (#2110)
- Convert base classes to data classes (#2080)
- Crashed prepare and execute steps propagate all causes
- Support exceptions with multiple causes
- Make "needs sudo" a guest fact (#2096)
- Test data path must use safe guest/test names
- Support for multi case import from Polarion and Polarion as only source (#2084)
- Fix search function in docs
- Make tmt test wrapper name unique to avoid race conditions
- Change link-polarion argument default to false
- Add export plugin for JSON (#2058)
- Handle el6 as a legacy os too in virtual provision
- Hint beakerlib is old when result parsing fails
- Revert "Fix dry mode handling when running a remote plan"
- Set a new dict instance to the Plan class
- Replaces "common" object with logger in method hint logging
- Parallelize prepare and execute steps
- Formalizing guest "facts" storage
- Support urllib3 2.x and its allowed_methods/method_whitelist
- Require setuptools
--------------------------------------------------------------------------------