The following Fedora EPEL 9 Security updates need testing:
Age URL
69 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2025-9a55de96db
xpdf-4.06-1.el9
0 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2026-0e3aa1d4ee
rust-sequoia-keystore-server-0.2.0-5.el9 rust-sequoia-sq-1.3.1-9.el9
The following builds have been pushed to Fedora EPEL 9 updates-testing
distribution-gpg-keys-1.116-1.el9
java-latest-openjdk-26.0.0.0.32-0.0.1.ea.el9
mock-core-configs-43.5-1.el9
yarnpkg-1.22.22-16.el9
Details about builds:
================================================================================
distribution-gpg-keys-1.116-1.el9 (FEDORA-EPEL-2026-f67f19697c)
GPG keys of various Linux distributions
--------------------------------------------------------------------------------
Update Information:
https://rpm-software-management.github.io/mock/Release-Notes-Configs-43.5
--------------------------------------------------------------------------------
ChangeLog:
* Tue Jan 27 2026 Pavel Raiskup <[email protected]> 1.116-1
- Add CentOS PQC signing keys
- Add RHEL PQC signing keys
- suse: Update RPM-GPG-KEY-SuSE-SLE-12
- Refresh CentOS SIG Extras key
- Update CentOS SIG keys downlod script
- Add missing CentOS SIG keys
- Add new Slack key used by versions 4.47 and above
- Add openSUSE Leap SLE imports
- Add Slack key
--------------------------------------------------------------------------------
================================================================================
java-latest-openjdk-26.0.0.0.32-0.0.1.ea.el9 (FEDORA-EPEL-2026-a6d429d59c)
OpenJDK 26 Runtime Environment
--------------------------------------------------------------------------------
Update Information:
January 2026 annual updates
--------------------------------------------------------------------------------
ChangeLog:
* Tue Jan 27 2026 Jiri Vanek <[email protected]> - 1:26.0.0.0.32-2
- RPMAUTOSPEC: unresolvable merge
--------------------------------------------------------------------------------
================================================================================
mock-core-configs-43.5-1.el9 (FEDORA-EPEL-2026-f67f19697c)
Mock core config files basic chroots
--------------------------------------------------------------------------------
Update Information:
https://rpm-software-management.github.io/mock/Release-Notes-Configs-43.5
--------------------------------------------------------------------------------
ChangeLog:
* Tue Jan 27 2026 Pavel Raiskup <[email protected]> 43.5-1
- add PQ keys to rhel9 ([email protected])
- Switch Mageia 10+ and Cauldron to DNF5 ([email protected])
- EOL Fedora 41
--------------------------------------------------------------------------------
================================================================================
yarnpkg-1.22.22-16.el9 (FEDORA-EPEL-2026-f542ecf2f3)
Fast, reliable, and secure dependency management.
--------------------------------------------------------------------------------
Update Information:
Update vendor bundle, fixes CVE-2025-13465.
--------------------------------------------------------------------------------
ChangeLog:
* Tue Jan 27 2026 Sandro Mani <[email protected]> - 1.22.22-16
- Refresh bundle, fixes CVE-2025-13465
* Sat Jan 17 2026 Fedora Release Engineering <[email protected]> -
1.22.22-15
- Rebuilt for https://fedoraproject.org/wiki/Fedora_44_Mass_Rebuild
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #2432934 - CVE-2025-13465 yarnpkg: prototype pollution in _.unset
and _.omit functions [epel-10]
https://bugzilla.redhat.com/show_bug.cgi?id=2432934
[ 2 ] Bug #2432950 - CVE-2025-13465 yarnpkg: prototype pollution in _.unset
and _.omit functions [epel-9]
https://bugzilla.redhat.com/show_bug.cgi?id=2432950
--------------------------------------------------------------------------------
--
_______________________________________________
epel-devel mailing list -- [email protected]
To unsubscribe send an email to [email protected]
Fedora Code of Conduct:
https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives:
https://lists.fedoraproject.org/archives/list/[email protected]
Do not reply to spam, report it:
https://forge.fedoraproject.org/infra/tickets/issues/new