-------------------------------------------------------------------------------- Fedora EPEL Update Notification FEDORA-EPEL-2025-d12b62c436 2025-11-03 00:51:33.254409+00:00 --------------------------------------------------------------------------------
Name : rust-dotenv Product : Fedora EPEL 10.2 Version : 0.15.0 Release : 16.el10_2 URL : https://crates.io/crates/dotenv Summary : Dotenv implementation for Rust Description : A `dotenv` implementation for Rust. -------------------------------------------------------------------------------- Update Information: uv 0.9.5 https://github.com/astral-sh/uv/blob/0.9.5/CHANGELOG.md Since uv was built with astral-tokio-tar 0.5.6, this is a security fix for CVE-2025-62518. ruff 0.14.2 https://github.com/astral-sh/ruff/blob/0.14.2/CHANGELOG.md rust-astral-tokio-tar 0.5.6 Fixed a parser desynchronization vulnerability when reading tar archives that contain mismatched size information in PAX/ustar headers. This vulnerability is being tracked as GHSA-j5gw-2vrg-8fgx and CVE-2025-62518. Initial packages for a number of new dependencies for ruff and uv, and initial EPEL10 packages for a few of their dependencies. Update rust-tikv-jemallocator and rust-tikv-jemalloc-sys to 0.6.1. -------------------------------------------------------------------------------- ChangeLog: * Fri Jul 25 2025 Fedora Release Engineering <[email protected]> - 0.15.0-16 - Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild * Sun Jan 19 2025 Fedora Release Engineering <[email protected]> - 0.15.0-15 - Rebuilt for https://fedoraproject.org/wiki/Fedora_42_Mass_Rebuild * Fri Sep 13 2024 Fabio Valentini <[email protected]> - 0.15.0-14 - Remove reference to readme file that is not included in published crates * Fri Jul 19 2024 Fedora Release Engineering <[email protected]> - 0.15.0-13 - Rebuilt for https://fedoraproject.org/wiki/Fedora_41_Mass_Rebuild * Fri Jan 26 2024 Fedora Release Engineering <[email protected]> - 0.15.0-12 - Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild -------------------------------------------------------------------------------- References: [ 1 ] Bug #2360699 - ruff-0.14.1 is available https://bugzilla.redhat.com/show_bug.cgi?id=2360699 [ 2 ] Bug #2402441 - rust-reqsign-core-2.0.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=2402441 [ 3 ] Bug #2402442 - rust-reqsign-command-execute-tokio-2.0.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=2402442 [ 4 ] Bug #2402443 - rust-reqsign-http-send-reqwest-2.0.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=2402443 [ 5 ] Bug #2402923 - uv-0.9.5 is available https://bugzilla.redhat.com/show_bug.cgi?id=2402923 [ 6 ] Bug #2405468 - CVE-2025-62518 rust-astral-tokio-tar: astral-tokio-tar Vulnerable to PAX Header Desynchronization [epel-10] https://bugzilla.redhat.com/show_bug.cgi?id=2405468 [ 7 ] Bug #2405469 - CVE-2025-62518 uv: astral-tokio-tar Vulnerable to PAX Header Desynchronization [epel-10] https://bugzilla.redhat.com/show_bug.cgi?id=2405469 [ 8 ] Bug #2406135 - ruff-0.14.2 is available https://bugzilla.redhat.com/show_bug.cgi?id=2406135 -------------------------------------------------------------------------------- This update can be installed with the "yum" update programs. Use su -c 'yum update rust-dotenv' at the command line. For more information, refer to "YUM", available at https://access.redhat.com/documentation/en-US/Red_Hat_Enterprise_Linux/7\ /html/System_Administrators_Guide/ch-yum.html All packages are signed with the Fedora EPEL GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ epel-package-announce mailing list -- [email protected] To unsubscribe send an email to [email protected] Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/[email protected] Do not reply to spam, report it: https://pagure.io/fedora-infrastructure/new_issue
