The following Fedora EPEL 9 Security updates need testing: Age URL 4 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2025-1dbf6380d2 java-latest-openjdk-24.0.2.0.12-1.rolling.el9 3 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2025-11ee8c8dc3 chromium-138.0.7204.168-1.el9 0 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2025-ab0fae74f1 opentofu-1.10.3-1.el9 The following builds have been pushed to Fedora EPEL 9 updates-testing algol68g-3.6.0-1.el9 node-exporter-1.9.1-2.el9 xq-1.3.0-5.el9 Details about builds: ================================================================================ algol68g-3.6.0-1.el9 (FEDORA-EPEL-2025-81b8223a49) Algol 68 Genie compiler-interpreter -------------------------------------------------------------------------------- Update Information: Update to 3.6.0 -------------------------------------------------------------------------------- ChangeLog: * Sun Jul 27 2025 Oleg Girko <ol@xxxxxxxxxxxxx> - 3.6.0-1 - Update to 3.6.0 * Wed Jul 23 2025 Fedora Release Engineering <releng@xxxxxxxxxxxxxxxxx> - 3.5.15-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild -------------------------------------------------------------------------------- References: [ 1 ] Bug #2383754 - algol68g-3.6.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=2383754 -------------------------------------------------------------------------------- ================================================================================ node-exporter-1.9.1-2.el9 (FEDORA-EPEL-2025-72356603ed) Exporter for machine metrics -------------------------------------------------------------------------------- Update Information: Initial package of node-expoter for for EL9 using go-vendor-tools. This obsoletes golang-github-prometheus-node-exporter and updates to latest 1.9.1 version. -------------------------------------------------------------------------------- ChangeLog: * Thu Jul 24 2025 Fedora Release Engineering <releng@xxxxxxxxxxxxxxxxx> - 1.9.1-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild * Tue Jul 8 2025 Mikel Olasagasti Uranga <mikel@xxxxxxxxxxxxxxx> - 1.9.1-1 - Update to 1.9.1 - Closes rhbz#2346095 rhbz#2340935 rhbz#2352318 * Fri Jan 17 2025 Fedora Release Engineering <releng@xxxxxxxxxxxxxxxxx> - 1.8.2-3 - Rebuilt for https://fedoraproject.org/wiki/Fedora_42_Mass_Rebuild * Thu Jul 18 2024 Fedora Release Engineering <releng@xxxxxxxxxxxxxxxxx> - 1.8.2-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_41_Mass_Rebuild * Sun Jul 14 2024 Mikel Olasagasti Uranga <mikel@xxxxxxxxxxxxxxx> - 1.8.2-1 - Update to 1.8.2 - Closes rhbz#2297753 * Fri Jun 7 2024 Mikel Olasagasti Uranga <mikel@xxxxxxxxxxxxxxx> - 1.8.1-1 - Update to 1.8.1 - Closes rhbz#2282791 * Sun Feb 11 2024 Maxwell G <maxwell@xxxxxxx> - 1.7.0-4 - Rebuild for golang 1.22.0 * Thu Jan 25 2024 Fedora Release Engineering <releng@xxxxxxxxxxxxxxxxx> - 1.7.0-3 - Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild * Sun Jan 21 2024 Fedora Release Engineering <releng@xxxxxxxxxxxxxxxxx> - 1.7.0-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild * Sat Jan 13 2024 Mikel Olasagasti Uranga <mikel@xxxxxxxxxxxxxxx> - 1.7.0-1 - Update to 1.7.0 - Closes rhbz#2250145 rhbz#2258169 * Sat Jan 13 2024 Mikel Olasagasti Uranga <mikel@xxxxxxxxxxxxxxx> - 1.6.1-2 - Add tmpfiles definition - Closes rhbz#2258169 * Sat Jan 13 2024 Mikel Olasagasti Uranga <mikel@xxxxxxxxxxxxxxx> - 1.6.1-1 - Initial package, rename from golang-github-prometheus-node-exporter - Closes rhbz#2250145 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2067346 - CVE-2022-21698 golang-github-prometheus-node-exporter: prometheus/client_golang: Denial of service using InstrumentHandlerCounter [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2067346 [ 2 ] Bug #2149438 - CVE-2022-46146 golang-github-prometheus-node-exporter: exporter-toolkit: authentication bypass via cache poisoning [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2149438 [ 3 ] Bug #2163045 - CVE-2022-41717 golang-github-prometheus-node-exporter: golang: net/http: An attacker can cause excessive memory growth in a Go server accepting HTTP/2 requests [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2163045 [ 4 ] Bug #2178401 - CVE-2022-41723 golang-github-prometheus-node-exporter: golang.org/x/net/http2: avoid quadratic complexity in HPACK decoding [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2178401 [ 5 ] Bug #2190404 - Please update to latest version of node-exporter https://bugzilla.redhat.com/show_bug.cgi?id=2190404 [ 6 ] Bug #2208339 - please build golang-github-prometheus-node-exporter-1.5.0 for EPEL 9 https://bugzilla.redhat.com/show_bug.cgi?id=2208339 [ 7 ] Bug #2248223 - golang-github-prometheus-node-exporter: golang: net/http, x/net/http2: rapid stream resets can cause excessive work (CVE-2023-39325) [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2248223 [ 8 ] Bug #2272670 - Please branch and build node-exporter for EPEL 9 https://bugzilla.redhat.com/show_bug.cgi?id=2272670 [ 9 ] Bug #2307514 - nfsd metrics do not work on RHEL 9 https://bugzilla.redhat.com/show_bug.cgi?id=2307514 [ 10 ] Bug #2351892 - CVE-2025-22870 golang-github-prometheus-node-exporter: HTTP Proxy bypass using IPv6 Zone IDs in golang.org/x/net [epel-9] https://bugzilla.redhat.com/show_bug.cgi?id=2351892 -------------------------------------------------------------------------------- ================================================================================ xq-1.3.0-5.el9 (FEDORA-EPEL-2025-63283e1b18) Command-line XML and HTML beautifier and content extractor -------------------------------------------------------------------------------- Update Information: Initial package of xq for EPEL9 & EPEL10 -------------------------------------------------------------------------------- ChangeLog: * Fri Jul 25 2025 Fedora Release Engineering <releng@xxxxxxxxxxxxxxxxx> - 1.3.0-4 - Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild * Thu Jul 10 2025 Mikel Olasagasti Uranga <mikel@xxxxxxxxxxxxxxx> - 1.3.0-3 - Adopt Go Vendor Tools * Sun Jan 19 2025 Fedora Release Engineering <releng@xxxxxxxxxxxxxxxxx> - 1.3.0-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_42_Mass_Rebuild * Mon Dec 23 2024 Packit <hello@xxxxxxxxxx> - 1.3.0-1 - Update to 1.3.0 upstream release - Resolves: rhbz#2333882 * Tue Sep 3 2024 Mikel Olasagasti Uranga <mikel@xxxxxxxxxxxxxxx> - 1.2.5-1 - Update to 1.2.5 * Sat Jul 20 2024 Fedora Release Engineering <releng@xxxxxxxxxxxxxxxxx> - 1.2.4-3 - Rebuilt for https://fedoraproject.org/wiki/Fedora_41_Mass_Rebuild * Sun Feb 11 2024 Maxwell G <maxwell@xxxxxxx> - 1.2.4-2 - Rebuild for golang 1.22.0 * Sun Feb 11 2024 Mikel Olasagasti Uranga <mikel@xxxxxxxxxxxxxxx> - 1.2.4-1 - Update to 1.2.4 - Closes rhbz#2259069 rhbz#2248415 rhbz#2229608 * Sat Jan 27 2024 Fedora Release Engineering <releng@xxxxxxxxxxxxxxxxx> - 1.2.3-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild * Mon Nov 6 2023 Mikel Olasagasti Uranga <mikel@xxxxxxxxxxxxxxx> - 1.2.3-1 - Update to 1.2.3 - Closes rhbz#2248087 * Fri Oct 13 2023 Mikel Olasagasti Uranga <mikel@xxxxxxxxxxxxxxx> - 1.2.2-2 - Add ldflags and remove devel package * Mon Oct 9 2023 Mikel Olasagasti Uranga <mikel@xxxxxxxxxxxxxxx> - 1.2.2-1 - Update to 1.2.2 - Closes rhbz#2242951 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2360717 - Please branch and build xq in epel8 and epel9 https://bugzilla.redhat.com/show_bug.cgi?id=2360717 -------------------------------------------------------------------------------- -- _______________________________________________ epel-devel mailing list -- epel-devel@xxxxxxxxxxxxxxxxxxxxxxx To unsubscribe send an email to epel-devel-leave@xxxxxxxxxxxxxxxxxxxxxxx Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/epel-devel@xxxxxxxxxxxxxxxxxxxxxxx Do not reply to spam, report it: https://pagure.io/fedora-infrastructure/new_issue