The following Fedora EPEL 10.2 Security updates need testing:
 Age  URL
   5  https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2025-633e14145a   
roundcubemail-1.6.12-1.el10_2
   3  https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2025-f671db26fe   
singularity-ce-4.3.6-1.el10_2
   2  https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2025-708d3dfaca   
gdu-5.32.0-1.el10_2
   1  https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2025-0abe7a3da8   
gobuster-3.8.2-1.el10_2


The following builds have been pushed to Fedora EPEL 10.2 updates-testing

    glycin-2.0.5-1.el10_2
    java-latest-openjdk-25.0.1.0.8-0.3.el10_2
    mkdocs-material-9.7.1-1.el10_2
    openvpn-2.7_rc4-1.el10_2
    perl-Finance-Quote-1.6800-1.el10_2
    pocketsphinx-5.0.4-1.el10_2
    podman-tui-1.10.0-1.el10_2
    python-astropy-iers-data-0.2025.12.22.0.40.30-1.el10_2
    rust-supports-hyperlinks-3.2.0-1.el10_2
    rust-tree-sitter-0.25.10-1.el10_2
    rust-tree-sitter-ada-0.1.0-1.el10_2
    rust-tree-sitter-cmake-0.7.1-1.el10_2
    rust-tree-sitter-racket-0.24.7-1.el10_2
    rust-tree-sitter0.24-0.24.7-2.el10_2
    tmt-1.64.0-2.el10_2
    xdg-terminal-exec-0.14.1-1.el10_2

Details about builds:


================================================================================
 glycin-2.0.5-1.el10_2 (FEDORA-EPEL-2025-9dc07cf791)
 Sandboxed image rendering
--------------------------------------------------------------------------------
Update Information:

Upstream update to 2.0.5
--------------------------------------------------------------------------------
ChangeLog:

* Mon Dec 22 2025 Ding-Yi Chen <[email protected]> - 2.0.5-1
- Upstream update to 2.0.5
* Mon Nov  3 2025 Fabio Valentini <[email protected]> - 2.0.4-1
- Update to version 2.0.4; Fixes RHBZ#2405336
* Fri Oct 10 2025 Fabio Valentini <[email protected]> - 2.0.3-1
- Update to version 2.0.3; Fixes RHBZ#2402967
* Mon Sep 29 2025 Fabio Valentini <[email protected]> - 2.0.2-1
- Update to version 2.0.2; Fixes RHBZ#2399870
* Mon Sep 15 2025 Fabio Valentini <[email protected]> - 2.0.0-1
- Update to version 2.0.0; Fixes RHBZ#2394711
* Fri Sep 12 2025 Fabio Valentini <[email protected]> - 2.0~rc-4
- Rebuild with updated seccomp filter list
* Fri Sep  5 2025 Michael Catanzaro <[email protected]> - 2.0~rc-3
- Add versioned Obsoletes to replace gdk-pixbuf-thumbnailer
* Wed Sep  3 2025 Fabio Valentini <[email protected]> - 2.0~rc-2
- Drop ExcludeArch for i686; needed for the gdk-pixbuf2 loader
* Tue Sep  2 2025 Fabio Valentini <[email protected]> - 2.0~rc-1
- Update to version 2.0.rc
* Mon Aug 25 2025 Fabio Valentini <[email protected]> - 2.0~beta.3-1
- Update to version 2.0.beta.3
* Fri Aug 22 2025 Fabio Valentini <[email protected]> - 2.0~beta.2-2
- Fix ELN build (vendored deps gone from upstream release tarball)
* Thu Aug 21 2025 Fabio Valentini <[email protected]> - 2.0~beta.2-1
- Update to version 2.0.beta.2
* Thu Aug  7 2025 Fabio Valentini <[email protected]> - 2.0~alpha.6-3
- Add missing hard dependency on bubblewrap; Fixes RHBZ#2387023
* Wed Jul 23 2025 Fedora Release Engineering <[email protected]> - 
2.0~alpha.6-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild
* Fri Jul  4 2025 Fabio Valentini <[email protected]> - 2.0~alpha.6-1
- Update to version 2.0.alpha.6
* Fri Jul  4 2025 Fabio Valentini <[email protected]> - 1.2.2-1
- Update to version 1.2.2; Fixes RHBZ#2375215
* Tue Apr 22 2025 Fabio Valentini <[email protected]> - 1.2.1-1
- Update to version 1.2.1; Fixes RHBZ#2359075
* Mon Mar 24 2025 Fabio Valentini <[email protected]> - 1.2.0-1
- Update to version 1.2.0; Fixes RHBZ#2352544
* Thu Feb 27 2025 Fabio Valentini <[email protected]> - 1.1.6-1
- Update to version 1.1.6; Fixes RHBZ#2347403
* Tue Feb 18 2025 Fabio Valentini <[email protected]> - 1.1.4-4
- Correctly apply patches depending on use of vendored sources
* Mon Feb  3 2025 Robert-André Mauchin <[email protected]> - 1.1.4-3
- Bump jpegxl-rs / jpegxl-sys dependencies from 0.10 to 0.11
* Thu Jan 16 2025 Fedora Release Engineering <[email protected]> - 
1.1.4-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_42_Mass_Rebuild
* Wed Jan 15 2025 Fabio Valentini <[email protected]> - 1.1.4-1
- Update to version 1.1.4; Fixes RHBZ#2335515
* Mon Dec  2 2024 Fabio Valentini <[email protected]> - 1.1.2-1
- Update to version 1.1.2; Fixes RHBZ#2328437
* Sun Dec  1 2024 Fabio Valentini <[email protected]> - 1.1.1-3
- Simplify macro usage for conditionally building with vendored deps
* Mon Sep 30 2024 Fabio Valentini <[email protected]> - 1.1.1-2
- Move libglycin-gtk4 into subpackages
* Mon Sep 30 2024 Fabio Valentini <[email protected]> - 1.1.1-1
- Initial import (#2315381)
--------------------------------------------------------------------------------


================================================================================
 java-latest-openjdk-25.0.1.0.8-0.3.el10_2 (FEDORA-EPEL-2025-68602a20f6)
 OpenJDK 25 Runtime Environment
--------------------------------------------------------------------------------
Update Information:

Enabled system crypto policy setup
--------------------------------------------------------------------------------
ChangeLog:

* Fri Dec 19 2025 Jiri Vanek <[email protected]> - 1:25.0.1.0.8-4
- Make different path for built libnssadapter.so on el x fedora
* Fri Dec 19 2025 Jiri Vanek <[email protected]> - 1:25.0.1.0.8-3
- Release bump
* Fri Dec 19 2025 Jiri Vanek <[email protected]> - 1:25.0.1.0.8-2
- Migrated to universal fipsver df044414ef4
--------------------------------------------------------------------------------


================================================================================
 mkdocs-material-9.7.1-1.el10_2 (FEDORA-EPEL-2025-4af8feaddb)
 Material design theme for MkDocs
--------------------------------------------------------------------------------
Update Information:

Fixed privacy plugin not picking up protocol-relative URLs
Fixed #8542: false positives and negatives captured in privacy plugin
--------------------------------------------------------------------------------
ChangeLog:

* Thu Dec 18 2025 Packit <[email protected]> - 9.7.1-1
- Update to 9.7.1 upstream release
- Resolves: rhbz#2423545
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #2423545 - mkdocs-material-9.7.1 is available
        https://bugzilla.redhat.com/show_bug.cgi?id=2423545
--------------------------------------------------------------------------------


================================================================================
 openvpn-2.7_rc4-1.el10_2 (FEDORA-EPEL-2025-bb0be74404)
 A full-featured TLS VPN solution
--------------------------------------------------------------------------------
Update Information:

Update to upstream 2.7_rc4 release
--------------------------------------------------------------------------------
ChangeLog:

* Mon Dec 22 2025 Frank Lichtenheld <[email protected]> - 2.7_rc4
- Update to upstream 2.7_rc4 release
--------------------------------------------------------------------------------


================================================================================
 perl-Finance-Quote-1.6800-1.el10_2 (FEDORA-EPEL-2025-8379b8b798)
 A Perl module that retrieves stock and mutual fund quotes
--------------------------------------------------------------------------------
Update Information:

Cumulative bug-fix update from upstream.
Defunct module CMBChina has been removed and new module USBonds has been added.
--------------------------------------------------------------------------------
ChangeLog:

* Mon Dec 22 2025 Paul Howarth <[email protected]> - 1.6800-1
- Update to 1.68
  - Changes to AlphaVantage.pm and CurrencyRates/AlphaVantage.pm to throttle
    queries (GH#546)
  - YahooJSON.pm: Add additional fields/labels (GH#544)
  - New module USBonds.pm
  - MarketWatch.pm: Added headers to fix 401 code (GH#542)
  - Modified AEX.pm to return no data available if currency indicator is '%'
    (bonds return percentage of par/facevalue) (GH#539)
  - Fixed YahooWeb.pm (GH#533, GH#538)
  - Removed CMBChina.pm - no longer working (GH#534)
  - Rewrote Union.pm for URL that returns JSON (GH#516)
  - Modified parsing in BVB.pm (GH#513)
--------------------------------------------------------------------------------


================================================================================
 pocketsphinx-5.0.4-1.el10_2 (FEDORA-EPEL-2025-8975268dc4)
 Real-time speech recognition
--------------------------------------------------------------------------------
Update Information:

Initial EPEL 10 package
--------------------------------------------------------------------------------
ChangeLog:

* Sun Dec 14 2025 W. Michael Petullo <[email protected]> - 2:5.0.4-1
- Initial EPEL 10 package
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #2354775 - Please branch and build pocketsphinx in epel8/9/10
        https://bugzilla.redhat.com/show_bug.cgi?id=2354775
--------------------------------------------------------------------------------


================================================================================
 podman-tui-1.10.0-1.el10_2 (FEDORA-EPEL-2025-39c166b09c)
 Podman Terminal User Interface
--------------------------------------------------------------------------------
Update Information:

release 1.10.0
--------------------------------------------------------------------------------
ChangeLog:

* Mon Dec 22 2025 Navid Yaghoobi <[email protected]> - 1.10.0-1
- Release 1.10.0
* Fri Oct 10 2025 Alejandro Sáez <[email protected]> - 1.9.0-2
- rebuild
* Sat Oct  4 2025 Navid Yaghoobi <[email protected]> - 1.9.0-1
- Release v1.9.0
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #2398307 - CVE-2025-47910 podman-tui: CrossOriginProtection bypass 
in net/http [epel-10]
        https://bugzilla.redhat.com/show_bug.cgi?id=2398307
  [ 2 ] Bug #2398943 - CVE-2025-47906 podman-tui: Unexpected paths returned 
from LookPath in os/exec [epel-10]
        https://bugzilla.redhat.com/show_bug.cgi?id=2398943
  [ 3 ] Bug #2407492 - CVE-2025-58189 podman-tui: go crypto/tls ALPN 
negotiation error contains attacker controlled information [epel-10]
        https://bugzilla.redhat.com/show_bug.cgi?id=2407492
  [ 4 ] Bug #2408532 - CVE-2025-61725 podman-tui: Excessive CPU consumption in 
ParseAddress in net/mail [epel-10]
        https://bugzilla.redhat.com/show_bug.cgi?id=2408532
  [ 5 ] Bug #2408944 - CVE-2025-61723 podman-tui: Quadratic complexity when 
parsing some invalid inputs in encoding/pem [epel-10]
        https://bugzilla.redhat.com/show_bug.cgi?id=2408944
  [ 6 ] Bug #2409886 - CVE-2025-58185 podman-tui: Parsing DER payload can cause 
memory exhaustion in encoding/asn1 [epel-10]
        https://bugzilla.redhat.com/show_bug.cgi?id=2409886
  [ 7 ] Bug #2410826 - CVE-2025-58188 podman-tui: Panic when validating 
certificates with DSA public keys in crypto/x509 [epel-10]
        https://bugzilla.redhat.com/show_bug.cgi?id=2410826
  [ 8 ] Bug #2412492 - CVE-2025-58183 podman-tui: Unbounded allocation when 
parsing GNU sparse map [epel-all]
        https://bugzilla.redhat.com/show_bug.cgi?id=2412492
  [ 9 ] Bug #2420558 - CVE-2025-47913 podman-tui: 
golang.org/x/crypto/ssh/agent: SSH client panic due to unexpected 
SSH_AGENT_SUCCESS [epel-10]
        https://bugzilla.redhat.com/show_bug.cgi?id=2420558
--------------------------------------------------------------------------------


================================================================================
 python-astropy-iers-data-0.2025.12.22.0.40.30-1.el10_2 
(FEDORA-EPEL-2025-0b581aa02e)
 IERS Earth Rotation and Leap Second tables for the astropy core package
--------------------------------------------------------------------------------
Update Information:

Automatic update for python-astropy-iers-data-0.2025.12.22.0.40.30-1.el10_2.
Changelog for python-astropy-iers-data
* Mon Dec 22 2025 Packit <[email protected]> - 0.2025.12.22.0.40.30-1
- Update to 0.2025.12.22.0.40.30 upstream release
- Resolves: rhbz#2422139
--------------------------------------------------------------------------------
ChangeLog:

* Mon Dec 22 2025 Packit <[email protected]> - 0.2025.12.22.0.40.30-1
- Update to 0.2025.12.22.0.40.30 upstream release
- Resolves: rhbz#2422139
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #2422139 - python-astropy-iers-data-0.2025.12.22.0.40.30 is 
available
        https://bugzilla.redhat.com/show_bug.cgi?id=2422139
--------------------------------------------------------------------------------


================================================================================
 rust-supports-hyperlinks-3.2.0-1.el10_2 (FEDORA-EPEL-2025-7017d95377)
 Detects whether a terminal supports rendering hyperlinks
--------------------------------------------------------------------------------
Update Information:

term: detect Zed's intergrated terminal (#8)
--------------------------------------------------------------------------------
ChangeLog:

* Mon Dec 22 2025 Michel Lind <[email protected]> - 3.2.0-1
- Update to version 3.2.0; Fixes RHBZ#2422974
* Fri Jul 25 2025 Fedora Release Engineering <[email protected]> - 
3.1.0-3
- Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild
* Sun Jan 19 2025 Fedora Release Engineering <[email protected]> - 
3.1.0-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_42_Mass_Rebuild
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #2422974 - rust-supports-hyperlinks-3.2.0 is available
        https://bugzilla.redhat.com/show_bug.cgi?id=2422974
--------------------------------------------------------------------------------


================================================================================
 rust-tree-sitter-0.25.10-1.el10_2 (FEDORA-EPEL-2025-a63307c379)
 Rust bindings to the Tree-sitter parsing library
--------------------------------------------------------------------------------
Update Information:

Initial EPEL 10 packages
--------------------------------------------------------------------------------
ChangeLog:

* Sun Sep 28 2025 Aleksei Bavshin <[email protected]> - 0.25.10-1
- Update to 0.25.10 (#2393686)
* Fri Jul 25 2025 Fedora Release Engineering <[email protected]> - 
0.25.8-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild
* Sat Jul 19 2025 Aleksei Bavshin <[email protected]> - 0.25.8-1
- Update to 0.25.8 (#2370284)
* Sun Jun  1 2025 Aleksei Bavshin <[email protected]> - 0.25.5-1
- Update to 0.25.5 (#2365531)
* Sat Apr 19 2025 Aleksei Bavshin <[email protected]> - 0.25.3-1
- Update to 0.25.3 (rhbz#2343309)
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #2421760 - Review Request: rust-tree-sitter-ada - Ada grammar for 
tree-sitter
        https://bugzilla.redhat.com/show_bug.cgi?id=2421760
  [ 2 ] Bug #2421763 - Review Request: rust-tree-sitter-cmake - CMake grammar 
for tree-sitter
        https://bugzilla.redhat.com/show_bug.cgi?id=2421763
--------------------------------------------------------------------------------


================================================================================
 rust-tree-sitter-ada-0.1.0-1.el10_2 (FEDORA-EPEL-2025-a63307c379)
 Ada grammar for tree-sitter
--------------------------------------------------------------------------------
Update Information:

Initial EPEL 10 packages
--------------------------------------------------------------------------------
ChangeLog:

* Mon Dec 22 2025 Michel Lind <[email protected]> - 0.1.0-1
- Initial package; Resolves: RHBZ#2421760
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #2421760 - Review Request: rust-tree-sitter-ada - Ada grammar for 
tree-sitter
        https://bugzilla.redhat.com/show_bug.cgi?id=2421760
  [ 2 ] Bug #2421763 - Review Request: rust-tree-sitter-cmake - CMake grammar 
for tree-sitter
        https://bugzilla.redhat.com/show_bug.cgi?id=2421763
--------------------------------------------------------------------------------


================================================================================
 rust-tree-sitter-cmake-0.7.1-1.el10_2 (FEDORA-EPEL-2025-a63307c379)
 CMake grammar for tree-sitter
--------------------------------------------------------------------------------
Update Information:

Initial EPEL 10 packages
--------------------------------------------------------------------------------
ChangeLog:

* Mon Dec 22 2025 Michel Lind <[email protected]> - 0.7.1-1
- Initial package; Resolves: RHBZ#2421763
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #2421760 - Review Request: rust-tree-sitter-ada - Ada grammar for 
tree-sitter
        https://bugzilla.redhat.com/show_bug.cgi?id=2421760
  [ 2 ] Bug #2421763 - Review Request: rust-tree-sitter-cmake - CMake grammar 
for tree-sitter
        https://bugzilla.redhat.com/show_bug.cgi?id=2421763
--------------------------------------------------------------------------------


================================================================================
 rust-tree-sitter-racket-0.24.7-1.el10_2 (FEDORA-EPEL-2025-1cd0b5745e)
 Racket parser for tree-sitter
--------------------------------------------------------------------------------
Update Information:

Initial release
--------------------------------------------------------------------------------
ChangeLog:

* Mon Dec 22 2025 Michel Lind <[email protected]> - 0.24.7-1
- Initial package; Resolves: RHBZ#2421759
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #2421759 - Review Request: rust-tree-sitter-racket - Racket parser 
for tree-sitter
        https://bugzilla.redhat.com/show_bug.cgi?id=2421759
--------------------------------------------------------------------------------


================================================================================
 rust-tree-sitter0.24-0.24.7-2.el10_2 (FEDORA-EPEL-2025-a63307c379)
 Rust bindings to the Tree-sitter parsing library
--------------------------------------------------------------------------------
Update Information:

Initial EPEL 10 packages
--------------------------------------------------------------------------------
ChangeLog:

* Fri Jul 25 2025 Fedora Release Engineering <[email protected]> - 
0.24.7-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild
* Wed Apr 23 2025 Aleksei Bavshin <[email protected]> - 0.24.7-1
- Initial import (rust-tree-sitter 0.24 compat package)
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #2421760 - Review Request: rust-tree-sitter-ada - Ada grammar for 
tree-sitter
        https://bugzilla.redhat.com/show_bug.cgi?id=2421760
  [ 2 ] Bug #2421763 - Review Request: rust-tree-sitter-cmake - CMake grammar 
for tree-sitter
        https://bugzilla.redhat.com/show_bug.cgi?id=2421763
--------------------------------------------------------------------------------


================================================================================
 tmt-1.64.0-2.el10_2 (FEDORA-EPEL-2025-35b77d8b61)
 Test Management Tool
--------------------------------------------------------------------------------
Update Information:

Update tmt to 1.64.0-2.fc42
Automatic update for tmt-1.64.0-1.el10_2.
--------------------------------------------------------------------------------
ChangeLog:

* Mon Dec 22 2025 Cristian Le <[email protected]> - 1.64.0-2
- Limit pomdan-machine dependency to available arches
* Thu Dec 18 2025 Packit <[email protected]> - 1.64.0-1
- Update to 1.64.0 upstream release
--------------------------------------------------------------------------------


================================================================================
 xdg-terminal-exec-0.14.1-1.el10_2 (FEDORA-EPEL-2025-05cc5903fa)
 Proposed XDG Default Terminal Execution Spec implementation
--------------------------------------------------------------------------------
Update Information:

v0.14.1
fix: add foot-server and footclient to fallback exclusions
v0.14.0
docs: meniton XTE_DEBUG var in manpage
--------------------------------------------------------------------------------
ChangeLog:

* Tue Dec 16 2025 Packit <[email protected]> - 0.14.1-1
- Update to 0.14.1 upstream release
- Resolves: rhbz#2415293
* Wed Sep 17 2025 Packit <[email protected]> - 0.13.3-1
- Update to 0.13.3 upstream release
- Resolves: rhbz#2396171
* Fri Jul 25 2025 Fedora Release Engineering <[email protected]> - 
0.13.2-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #2415293 - xdg-terminal-exec-0.14.1 is available
        https://bugzilla.redhat.com/show_bug.cgi?id=2415293
--------------------------------------------------------------------------------


-- 
_______________________________________________
epel-devel mailing list -- [email protected]
To unsubscribe send an email to [email protected]
Fedora Code of Conduct: 
https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedoraproject.org/archives/list/[email protected]
Do not reply to spam, report it: 
https://pagure.io/fedora-infrastructure/new_issue

Reply via email to