python3.13-3.13.15-2.el9
- python3.13-3.13.15-2.el9
Support reparse deferral in expat
Support reparse deferral in expat
Rebuild with go 1.25.12
Automatic update for gum-2.0.0-1.fc46.
Changelog * Fri Aug 21 2026 Carl George <carlwgeorge@fedoraproject.org> - 2.0.0-1 - Update to version 2.0.0 (rhbz#2495240) - Override bundled golang.org/x/net to v0.55.0 (CVE-2026-25680 CVE-2026-25681 CVE-2026-42506)Automatic update for gum-2.0.0-1.fc45.
Changelog * Fri Aug 21 2026 Carl George <carlwgeorge@fedoraproject.org> - 2.0.0-1 - Update to version 2.0.0 (rhbz#2495240) - Override bundled golang.org/x/net to v0.55.0 (CVE-2026-25680 CVE-2026-25681 CVE-2026-42506)Includes a fix for CVE-2026-69247, refer to https://github.com/pyca/cryptography/security/advisories/GHSA-g6cj-pr64-35w5 for a more detailed description.
Full changelog: https://github.com/pyca/cryptography/blob/50.0.0/CHANGELOG.rst
IMPROVEMENT: ivy:retrieve and the 'post resolve tasks' now support the override child element. (IVY-1664)
IMPROVEMENT: ivy:makepom will now add override elements of the ivy.xml to the dependencyManagement section of the generated pom. (IVY-1663) (Thanks to Eric Milles)
IMPROVEMENT: ivy:deliver and ivy:publish now writes inherited dependencies first to preserve resolve order (IVY-1656) (Thanks to Eric Milles)
IMPROVEMENT: ModuleRevisionId.encodeToString now returns a deterministic string that doesn’t rely on a implmentation of HashMap (Thanks to Arnout Engelen)
FIX: improved Maven dependencyManagement matching for dependencies with a non-default type or classifier (IVY-1654) (Thanks to Mark Kittisopikul)
FIX: the ivy:retrieve task failed when the retrieve pattern contained some text in parentheses before the first token, for instance: /jobs/lib (JDK 17)/[artifact].[ext] (IVY-1660)
FIX: when the ivy:deliver task is configured to replace dynamic revisions, it now replaces these revisions to the resolved revision before any conflict resolution was done, which was the original behavior before Ivy 2.3.0. This way, the delivered ivy.xml can be used to have reproducible dependency resolution, especially when multiple configurations are used. It also fixes issues where the dynamic revisions were replaced by versions from other configurations. (IVY-1485, IVY-1661)
FIX: the ivy:deliver task didn’t replace dynamic revision from inherited dependencies. (IVY-1410) (Thanks to Eric Milles)
FIX: the ivy:install task didn’t take the from resolver into account when resolving Maven parent modules or source/javadoc artifacts. (Thanks to Colin Chambers)
FIX: the ivy:checkdepsupdate task could suggest a lesser version as update. (IVY-1665) (Thanks to Eric Milles)
FIX: the ivy:makepom task no longer adds a dependency to the <dependencyManagement> section. (IVY-1667) (Thanks to Eric Milles)
FIX: the ivy:deliver task didn’t include XML namespaces from a parent ivy module when merging the descriptors. (IVY-1658) (Thanks to Eric Milles)
FIX: the ivy:checkdepsupdate task no longer shows evicted versions. (IVY-1662) (Thanks to Eric Milles)
IMPROVEMENT: ivy:retrieve and the 'post resolve tasks' now support the override child element. (IVY-1664)
IMPROVEMENT: ivy:makepom will now add override elements of the ivy.xml to the dependencyManagement section of the generated pom. (IVY-1663) (Thanks to Eric Milles)
IMPROVEMENT: ivy:deliver and ivy:publish now writes inherited dependencies first to preserve resolve order (IVY-1656) (Thanks to Eric Milles)
IMPROVEMENT: ModuleRevisionId.encodeToString now returns a deterministic string that doesn’t rely on a implmentation of HashMap (Thanks to Arnout Engelen)
FIX: improved Maven dependencyManagement matching for dependencies with a non-default type or classifier (IVY-1654) (Thanks to Mark Kittisopikul)
FIX: the ivy:retrieve task failed when the retrieve pattern contained some text in parentheses before the first token, for instance: /jobs/lib (JDK 17)/[artifact].[ext] (IVY-1660)
FIX: when the ivy:deliver task is configured to replace dynamic revisions, it now replaces these revisions to the resolved revision before any conflict resolution was done, which was the original behavior before Ivy 2.3.0. This way, the delivered ivy.xml can be used to have reproducible dependency resolution, especially when multiple configurations are used. It also fixes issues where the dynamic revisions were replaced by versions from other configurations. (IVY-1485, IVY-1661)
FIX: the ivy:deliver task didn’t replace dynamic revision from inherited dependencies. (IVY-1410) (Thanks to Eric Milles)
FIX: the ivy:install task didn’t take the from resolver into account when resolving Maven parent modules or source/javadoc artifacts. (Thanks to Colin Chambers)
FIX: the ivy:checkdepsupdate task could suggest a lesser version as update. (IVY-1665) (Thanks to Eric Milles)
FIX: the ivy:makepom task no longer adds a dependency to the <dependencyManagement> section. (IVY-1667) (Thanks to Eric Milles)
FIX: the ivy:deliver task didn’t include XML namespaces from a parent ivy module when merging the descriptors. (IVY-1658) (Thanks to Eric Milles)
FIX: the ivy:checkdepsupdate task no longer shows evicted versions. (IVY-1662) (Thanks to Eric Milles)
Update to 5.4.0
Update to 5.4.0
chromium security release 151.0.7922.169
* CVE-2026-76034: Buffer overflow in WebGL * CVE-2026-76036: Buffer overflow in Dawn * CVE-2026-76033: Inappropriate implementation in CORS * CVE-2026-76037: Link following in CredentialProvider * CVE-2026-76044: Race condition in USB * CVE-2026-76039: Incorrect reference resolution in Core * CVE-2026-76040: Use after free in Browser * CVE-2026-76035: Inappropriate implementation in Media * CVE-2026-76042: Use of uninitialized resource in GPU * CVE-2026-76046: Buffer overflow in ANGLE * CVE-2026-76043: Incorrect calculation in V8 * CVE-2026-76041: Information leak in Skia * CVE-2026-76047: Type confusion in V8 * CVE-2026-76038: Type confusion in V8 * CVE-2026-76045: Use after free in WebGLchromium security release 151.0.7922.169
* CVE-2026-76034: Buffer overflow in WebGL * CVE-2026-76036: Buffer overflow in Dawn * CVE-2026-76033: Inappropriate implementation in CORS * CVE-2026-76037: Link following in CredentialProvider * CVE-2026-76044: Race condition in USB * CVE-2026-76039: Incorrect reference resolution in Core * CVE-2026-76040: Use after free in Browser * CVE-2026-76035: Inappropriate implementation in Media * CVE-2026-76042: Use of uninitialized resource in GPU * CVE-2026-76046: Buffer overflow in ANGLE * CVE-2026-76043: Incorrect calculation in V8 * CVE-2026-76041: Information leak in Skia * CVE-2026-76047: Type confusion in V8 * CVE-2026-76038: Type confusion in V8 * CVE-2026-76045: Use after free in WebGLchromium security release 151.0.7922.169
* CVE-2026-76034: Buffer overflow in WebGL * CVE-2026-76036: Buffer overflow in Dawn * CVE-2026-76033: Inappropriate implementation in CORS * CVE-2026-76037: Link following in CredentialProvider * CVE-2026-76044: Race condition in USB * CVE-2026-76039: Incorrect reference resolution in Core * CVE-2026-76040: Use after free in Browser * CVE-2026-76035: Inappropriate implementation in Media * CVE-2026-76042: Use of uninitialized resource in GPU * CVE-2026-76046: Buffer overflow in ANGLE * CVE-2026-76043: Incorrect calculation in V8 * CVE-2026-76041: Information leak in Skia * CVE-2026-76047: Type confusion in V8 * CVE-2026-76038: Type confusion in V8 * CVE-2026-76045: Use after free in WebGLchromium security release 151.0.7922.169
* CVE-2026-76034: Buffer overflow in WebGL * CVE-2026-76036: Buffer overflow in Dawn * CVE-2026-76033: Inappropriate implementation in CORS * CVE-2026-76037: Link following in CredentialProvider * CVE-2026-76044: Race condition in USB * CVE-2026-76039: Incorrect reference resolution in Core * CVE-2026-76040: Use after free in Browser * CVE-2026-76035: Inappropriate implementation in Media * CVE-2026-76042: Use of uninitialized resource in GPU * CVE-2026-76046: Buffer overflow in ANGLE * CVE-2026-76043: Incorrect calculation in V8 * CVE-2026-76041: Information leak in Skia * CVE-2026-76047: Type confusion in V8 * CVE-2026-76038: Type confusion in V8 * CVE-2026-76045: Use after free in WebGLUpdate to v1.5.4 a2313a3 Security Raises the gitpython floor from >=3.1.44 to >=3.1.59.
Earlier dependabot bumps only touched this repo's uv.lock, which pins the CI environment and nothing else. Downstream users installing from PyPI resolved against pyproject.toml, so they could still land on a GitPython carrying the 2026 option-injection advisories — GHSA-wvpp-8hx9-p66j and GHSA-jm78-9fvv-mhgr among them, all patched by 3.1.58, with further option hardening in 3.1.59.
This plugin never passes user input as git options, so it was not exploitable through those. The floor bump forces the upgrade in environments that already hold an older GitPython, and clears the warnings downstream scanners report.
Thanks to @nucleus-ffm for reporting it in #222.
Maintenance Harden test git repos against flaky "Error building trees" failures by @timvink in #212 ci: update GitHub Actions to Node 24 compatible versions by @timvink in #213 deps: bump idna and pymdown-extensions to patch security alerts by @timvink in #214 Bump gitpython from 3.1.50 to 3.1.58 in #217, #219, #220 Bump pymdown-extensions from 10.21.3 to 11.0.1 in #218, #221
Update to v1.5.4 a2313a3 Security Raises the gitpython floor from >=3.1.44 to >=3.1.59.
Earlier dependabot bumps only touched this repo's uv.lock, which pins the CI environment and nothing else. Downstream users installing from PyPI resolved against pyproject.toml, so they could still land on a GitPython carrying the 2026 option-injection advisories — GHSA-wvpp-8hx9-p66j and GHSA-jm78-9fvv-mhgr among them, all patched by 3.1.58, with further option hardening in 3.1.59.
This plugin never passes user input as git options, so it was not exploitable through those. The floor bump forces the upgrade in environments that already hold an older GitPython, and clears the warnings downstream scanners report.
Thanks to @nucleus-ffm for reporting it in #222.
Maintenance Harden test git repos against flaky "Error building trees" failures by @timvink in #212 ci: update GitHub Actions to Node 24 compatible versions by @timvink in #213 deps: bump idna and pymdown-extensions to patch security alerts by @timvink in #214 Bump gitpython from 3.1.50 to 3.1.58 in #217, #219, #220 Bump pymdown-extensions from 10.21.3 to 11.0.1 in #218, #221
Upstream security release FreeIPA 4.13.3
Release notes: https://www.freeipa.org/release-notes/4-13-3.html
5.36 - Apply Unicode NFC normalization in URI::_idna nameprep so IDNA host encoding matches other clients instead of emitting a non-standard, non-round-tripping A-label [CVE-2026-19953]
5.36 - Apply Unicode NFC normalization in URI::_idna nameprep so IDNA host encoding matches other clients instead of emitting a non-standard, non-round-tripping A-label [CVE-2026-19953]
Automatic update for yt-dlp-2026.08.19-1.fc45.
Changelog * Thu Aug 20 2026 Mikel Olasagasti Uranga <mikel@olasagasti.info> - 2026.08.19-1 - Update to 2026.08.19 - Closes rhbz#2497100 rhbz#2505367 rhbz#2491888 rhbz#2491889 rhbz#2491890 rhbz#2499189 * Fri Jul 17 2026 Fedora Release Engineering <releng@fedoraproject.org> - 2026.06.09-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_45_Mass_Rebuild