The following Fedora EPEL 10.2 Security updates need testing:
 Age  URL
   6  https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2026-d03f559c4f   
coturn-4.7.0-4.el10_2
   4  https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2026-bc7502f16e   
composer-2.9.3-1.el10_2
   3  https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2026-c60f76437d   
libsodium-1.0.21-2.el10_2
   3  https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2026-b90feb26b8   
foomuuri-0.31-1.el10_2
   2  https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2026-50fab59f98   
helm-4.0.4-1.el10_2 helm3-3.19.3-1.el10_2


The following builds have been pushed to Fedora EPEL 10.2 updates-testing

    prosody-13.0.3-1.el10_2
    psfex-3.24.1-1.el10_2
    radicale-3.6.0-1.el10_2
    ruby-build-20260110-1.el10_2
    rust-b3sum-1.8.3-1.el10_2
    rust-blake3-1.8.3-1.el10_2
    rust-constant_time_eq-0.4.2-1.el10_2
    rust-gix-archive-0.24.0-2.el10_2
    rust-python-pkginfo-0.6.6-3.el10_2
    rust-zip-7.0.0-2.el10_2
    rust-zip0.6-0.6.6-5.el10_2
    rust-zip2-2.4.2-4.el10_2
    suricata-8.0.2-1.el10_2

Details about builds:


================================================================================
 prosody-13.0.3-1.el10_2 (FEDORA-EPEL-2026-d53a881031)
 Flexible communications server for Jabber/XMPP
--------------------------------------------------------------------------------
Update Information:

Prosody 13.0.3
Happy new year! Upstream's first release of 2026 is a minor release for their
stable branch, with a range of tweaks, bug fixes and minor improvements for you.
Fixes and improvements
mod_storage_sql: Set configurable wait time for locked SQLite3 database
net.server_event: Port TLS 1.3 channel binding method to libevent backend
mod_roster: Add command for cleaning out invalid contact JIDs
migrator: Allow migrating between different configs of the same driver
mod_admin_shell: Allow pinging any JID with xmpp:ping()
mod_invites: Accept –admin flag as shortcut for –role prosody:admin
mod_mam: Add send_legacy_offline_messages_to_mam_clients config option
mod_limits: Allow configuration of general s2s limit, and have s2sout inherit
from s2sin
mod_storage_internal: Return item-not-found for unknown before/after ids
MUC: Fixes for room avatar caching
Minor changes
core.configmanager: Fix referencing previous config options
MUC: Ensure allow MUC PM setting has valid value (fixes: PM does not work on new
MUCs)
mod_storage_sql: Assert that serialization of archive:set() payload succeeds
mod_smacks: Remove extra optional from sm element
mod_s2s_auth_dane_in: Fix caching SHA2-512 hash
MUC: Fix muc_room_default_presence_broadcast option not working
util.sslconfig: Fix error when applying ssl={[port]=…}
net.server_epoll: Restore idle checks after pause (e.g. rate limits)
util.jid: Validate domainparts using IDNA or as IP literals (fixes: Invalid JID
in Roster)
util.datamanager: Fix detection of index files created on different
architectures
util.startup: Inform process manager about failure to reload config
mod_muc: Revert commit f4e16e6265e6 and invalidate avatar cache only on vcard
change
mod_http_file_share: Improve debug logging around unexpected file sizes
mod_admin_shell: Ensure JIDs are normalized in xmpp:ping()
mod_invites: Return error when generating password reset for non-existent
account
util.uuid: Update UUIDv7 to match RFC 9562
--------------------------------------------------------------------------------
ChangeLog:

* Sat Jan 10 2026 Robert Scheck <[email protected]> 13.0.3-1
- Upgrade to 13.0.3 (#2427189)
* Sun Aug 10 2025 Robert Scheck <[email protected]> 13.0.2-4
- Use 'systemctl try-reload-or-restart' in logrotate postrotate
  script (#2371331, thanks to Marcos Mello)
- Do not use removed /etc/pki/tls/certs/ca-bundle.crt bundle file
  for Fedora 42 >= and RHEL >= 11
* Wed Aug  6 2025 FrantiÅ¡ek Zatloukal <[email protected]> - 13.0.2-3
- Rebuilt for icu 77.1
* Fri Jul 25 2025 Fedora Release Engineering <[email protected]> - 
13.0.2-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #2371331 - Simplify logrotate postrotate script with `systemctl 
try-reload-or-restart`
        https://bugzilla.redhat.com/show_bug.cgi?id=2371331
  [ 2 ] Bug #2427189 - prosody-13.0.3 is available
        https://bugzilla.redhat.com/show_bug.cgi?id=2427189
--------------------------------------------------------------------------------


================================================================================
 psfex-3.24.1-1.el10_2 (FEDORA-EPEL-2026-9400407da4)
 Model the Point Spread Function from FITS images
--------------------------------------------------------------------------------
Update Information:

PSFEx extracts models of the Point Spread Function (PSF) from FITS images
processed with SExtractor and measures the quality of images. The generated PSF
models can be used for model-fitting photometry or morphological analyses.
--------------------------------------------------------------------------------
ChangeLog:

* Sun Nov  9 2025 Sergio Pascual <[email protected]> - 3.24.1-1
- Initial import
--------------------------------------------------------------------------------


================================================================================
 radicale-3.6.0-1.el10_2 (FEDORA-EPEL-2026-924deac98c)
 A simple CalDAV (calendar) and CardDAV (contact) server
--------------------------------------------------------------------------------
Update Information:

Update to 3.6.0
--------------------------------------------------------------------------------
ChangeLog:

* Sat Jan 10 2026 Peter Bieringer <[email protected]>  - 3.6.0-1
- Update to 3.6.0
- add BuildRequires: python3-packaging
- force to use "passlib" instead of "libpass"
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #2428449 - radicale-3.6.0 is available
        https://bugzilla.redhat.com/show_bug.cgi?id=2428449
--------------------------------------------------------------------------------


================================================================================
 ruby-build-20260110-1.el10_2 (FEDORA-EPEL-2026-3776656994)
 Compile and install Ruby
--------------------------------------------------------------------------------
Update Information:

Update to 20260110
--------------------------------------------------------------------------------
ChangeLog:

* Sat Jan 10 2026 Packit <[email protected]> - 20260110-1
- Update to 20260110 upstream release
- Resolves: rhbz#2428461
--------------------------------------------------------------------------------


================================================================================
 rust-b3sum-1.8.3-1.el10_2 (FEDORA-EPEL-2026-cc20a69bc9)
 Command line implementation of the BLAKE3 hash function
--------------------------------------------------------------------------------
Update Information:

Update rust-zip to 7.0.0, rust-blake3 / rust-b3sum to 1.8.3 and rust-
constant_time_eq to 0.4.2, patching reverse dependencies of rust-zip and rust-
constant_time_eq to avoid introducing compat packages.
--------------------------------------------------------------------------------
ChangeLog:

* Fri Jan  9 2026 Benjamin A. Beasley <[email protected]> - 1.8.3-1
- Update to version 1.8.3; Fixes RHBZ#2428096
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #2347117 - rust-constant_time_eq-0.4.2 is available
        https://bugzilla.redhat.com/show_bug.cgi?id=2347117
  [ 2 ] Bug #2367905 - rust-zip-7.0.0 is available
        https://bugzilla.redhat.com/show_bug.cgi?id=2367905
  [ 3 ] Bug #2428096 - rust-b3sum-1.8.3 is available
        https://bugzilla.redhat.com/show_bug.cgi?id=2428096
  [ 4 ] Bug #2428121 - rust-blake3-1.8.3 is available
        https://bugzilla.redhat.com/show_bug.cgi?id=2428121
--------------------------------------------------------------------------------


================================================================================
 rust-blake3-1.8.3-1.el10_2 (FEDORA-EPEL-2026-cc20a69bc9)
 BLAKE3 hash function
--------------------------------------------------------------------------------
Update Information:

Update rust-zip to 7.0.0, rust-blake3 / rust-b3sum to 1.8.3 and rust-
constant_time_eq to 0.4.2, patching reverse dependencies of rust-zip and rust-
constant_time_eq to avoid introducing compat packages.
--------------------------------------------------------------------------------
ChangeLog:

* Thu Jan  8 2026 Benjamin A. Beasley <[email protected]> - 1.8.3-1
- Update to version 1.8.3; Fixes RHBZ#2428121
* Fri Jul 25 2025 Fedora Release Engineering <[email protected]> - 
1.8.2-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #2347117 - rust-constant_time_eq-0.4.2 is available
        https://bugzilla.redhat.com/show_bug.cgi?id=2347117
  [ 2 ] Bug #2367905 - rust-zip-7.0.0 is available
        https://bugzilla.redhat.com/show_bug.cgi?id=2367905
  [ 3 ] Bug #2428096 - rust-b3sum-1.8.3 is available
        https://bugzilla.redhat.com/show_bug.cgi?id=2428096
  [ 4 ] Bug #2428121 - rust-blake3-1.8.3 is available
        https://bugzilla.redhat.com/show_bug.cgi?id=2428121
--------------------------------------------------------------------------------


================================================================================
 rust-constant_time_eq-0.4.2-1.el10_2 (FEDORA-EPEL-2026-cc20a69bc9)
 Compares two equal-sized byte strings in constant time
--------------------------------------------------------------------------------
Update Information:

Update rust-zip to 7.0.0, rust-blake3 / rust-b3sum to 1.8.3 and rust-
constant_time_eq to 0.4.2, patching reverse dependencies of rust-zip and rust-
constant_time_eq to avoid introducing compat packages.
--------------------------------------------------------------------------------
ChangeLog:

* Fri Jan  9 2026 Benjamin A. Beasley <[email protected]> - 0.4.2-1
- Update to version 0.4.2; Fixes RHBZ#2347117
* Fri Jul 25 2025 Fedora Release Engineering <[email protected]> - 
0.3.1-3
- Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild
* Sun Jan 19 2025 Fedora Release Engineering <[email protected]> - 
0.3.1-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_42_Mass_Rebuild
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #2347117 - rust-constant_time_eq-0.4.2 is available
        https://bugzilla.redhat.com/show_bug.cgi?id=2347117
  [ 2 ] Bug #2367905 - rust-zip-7.0.0 is available
        https://bugzilla.redhat.com/show_bug.cgi?id=2367905
  [ 3 ] Bug #2428096 - rust-b3sum-1.8.3 is available
        https://bugzilla.redhat.com/show_bug.cgi?id=2428096
  [ 4 ] Bug #2428121 - rust-blake3-1.8.3 is available
        https://bugzilla.redhat.com/show_bug.cgi?id=2428121
--------------------------------------------------------------------------------


================================================================================
 rust-gix-archive-0.24.0-2.el10_2 (FEDORA-EPEL-2026-cc20a69bc9)
 Archive generation from of a worktree stream
--------------------------------------------------------------------------------
Update Information:

Update rust-zip to 7.0.0, rust-blake3 / rust-b3sum to 1.8.3 and rust-
constant_time_eq to 0.4.2, patching reverse dependencies of rust-zip and rust-
constant_time_eq to avoid introducing compat packages.
--------------------------------------------------------------------------------
ChangeLog:

* Thu Jan  8 2026 Benjamin A. Beasley <[email protected]> - 0.24.0-2
- Allow zip 7
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #2347117 - rust-constant_time_eq-0.4.2 is available
        https://bugzilla.redhat.com/show_bug.cgi?id=2347117
  [ 2 ] Bug #2367905 - rust-zip-7.0.0 is available
        https://bugzilla.redhat.com/show_bug.cgi?id=2367905
  [ 3 ] Bug #2428096 - rust-b3sum-1.8.3 is available
        https://bugzilla.redhat.com/show_bug.cgi?id=2428096
  [ 4 ] Bug #2428121 - rust-blake3-1.8.3 is available
        https://bugzilla.redhat.com/show_bug.cgi?id=2428121
--------------------------------------------------------------------------------


================================================================================
 rust-python-pkginfo-0.6.6-3.el10_2 (FEDORA-EPEL-2026-cc20a69bc9)
 Parse Python package metadata from sdist and bdists and etc
--------------------------------------------------------------------------------
Update Information:

Update rust-zip to 7.0.0, rust-blake3 / rust-b3sum to 1.8.3 and rust-
constant_time_eq to 0.4.2, patching reverse dependencies of rust-zip and rust-
constant_time_eq to avoid introducing compat packages.
--------------------------------------------------------------------------------
ChangeLog:

* Thu Jan  8 2026 Benjamin A. Beasley <[email protected]> - 0.6.6-3
- Allow zip 7
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #2347117 - rust-constant_time_eq-0.4.2 is available
        https://bugzilla.redhat.com/show_bug.cgi?id=2347117
  [ 2 ] Bug #2367905 - rust-zip-7.0.0 is available
        https://bugzilla.redhat.com/show_bug.cgi?id=2367905
  [ 3 ] Bug #2428096 - rust-b3sum-1.8.3 is available
        https://bugzilla.redhat.com/show_bug.cgi?id=2428096
  [ 4 ] Bug #2428121 - rust-blake3-1.8.3 is available
        https://bugzilla.redhat.com/show_bug.cgi?id=2428121
--------------------------------------------------------------------------------


================================================================================
 rust-zip-7.0.0-2.el10_2 (FEDORA-EPEL-2026-cc20a69bc9)
 Library to support the reading and writing of zip files
--------------------------------------------------------------------------------
Update Information:

Update rust-zip to 7.0.0, rust-blake3 / rust-b3sum to 1.8.3 and rust-
constant_time_eq to 0.4.2, patching reverse dependencies of rust-zip and rust-
constant_time_eq to avoid introducing compat packages.
--------------------------------------------------------------------------------
ChangeLog:

* Fri Jan  9 2026 Benjamin A. Beasley <[email protected]> - 7.0.0-2
- Update constant_time_eq from 0.3.1 to 0.4.2
* Thu Jan  8 2026 Benjamin A. Beasley <[email protected]> - 7.0.0-1
- Update to version 7.0.0; Fixes RHBZ#2367905
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #2347117 - rust-constant_time_eq-0.4.2 is available
        https://bugzilla.redhat.com/show_bug.cgi?id=2347117
  [ 2 ] Bug #2367905 - rust-zip-7.0.0 is available
        https://bugzilla.redhat.com/show_bug.cgi?id=2367905
  [ 3 ] Bug #2428096 - rust-b3sum-1.8.3 is available
        https://bugzilla.redhat.com/show_bug.cgi?id=2428096
  [ 4 ] Bug #2428121 - rust-blake3-1.8.3 is available
        https://bugzilla.redhat.com/show_bug.cgi?id=2428121
--------------------------------------------------------------------------------


================================================================================
 rust-zip0.6-0.6.6-5.el10_2 (FEDORA-EPEL-2026-cc20a69bc9)
 Library to support the reading and writing of zip files
--------------------------------------------------------------------------------
Update Information:

Update rust-zip to 7.0.0, rust-blake3 / rust-b3sum to 1.8.3 and rust-
constant_time_eq to 0.4.2, patching reverse dependencies of rust-zip and rust-
constant_time_eq to avoid introducing compat packages.
--------------------------------------------------------------------------------
ChangeLog:

* Fri Jan  9 2026 Benjamin A. Beasley <[email protected]> - 0.6.6-5
- Update constant_time_eq from 0.3 to 0.4
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #2347117 - rust-constant_time_eq-0.4.2 is available
        https://bugzilla.redhat.com/show_bug.cgi?id=2347117
  [ 2 ] Bug #2367905 - rust-zip-7.0.0 is available
        https://bugzilla.redhat.com/show_bug.cgi?id=2367905
  [ 3 ] Bug #2428096 - rust-b3sum-1.8.3 is available
        https://bugzilla.redhat.com/show_bug.cgi?id=2428096
  [ 4 ] Bug #2428121 - rust-blake3-1.8.3 is available
        https://bugzilla.redhat.com/show_bug.cgi?id=2428121
--------------------------------------------------------------------------------


================================================================================
 rust-zip2-2.4.2-4.el10_2 (FEDORA-EPEL-2026-cc20a69bc9)
 Library to support the reading and writing of zip files
--------------------------------------------------------------------------------
Update Information:

Update rust-zip to 7.0.0, rust-blake3 / rust-b3sum to 1.8.3 and rust-
constant_time_eq to 0.4.2, patching reverse dependencies of rust-zip and rust-
constant_time_eq to avoid introducing compat packages.
--------------------------------------------------------------------------------
ChangeLog:

* Fri Jan  9 2026 Benjamin A. Beasley <[email protected]> - 2.4.2-4
- Update constant_time_eq from 0.3 to 0.4
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #2347117 - rust-constant_time_eq-0.4.2 is available
        https://bugzilla.redhat.com/show_bug.cgi?id=2347117
  [ 2 ] Bug #2367905 - rust-zip-7.0.0 is available
        https://bugzilla.redhat.com/show_bug.cgi?id=2367905
  [ 3 ] Bug #2428096 - rust-b3sum-1.8.3 is available
        https://bugzilla.redhat.com/show_bug.cgi?id=2428096
  [ 4 ] Bug #2428121 - rust-blake3-1.8.3 is available
        https://bugzilla.redhat.com/show_bug.cgi?id=2428121
--------------------------------------------------------------------------------


================================================================================
 suricata-8.0.2-1.el10_2 (FEDORA-EPEL-2026-40f6435389)
 Intrusion Detection System
--------------------------------------------------------------------------------
Update Information:

Initial epel 10 release
--------------------------------------------------------------------------------
ChangeLog:

* Sat Nov  8 2025 Jason Taylor <[email protected]> 8.0.2-1
- Upstream security/bugfix release
* Thu Oct  9 2025 Jason Taylor <[email protected]> 8.0.1-1
- Migrate to 8.0.x release
- Addresses CVE-2025-59147, CVE-2025-59148
- Addresses CVE-2025-59149, CVE-2025-59150
- removed libprelude references as it is orphaned
- removed suricatasc python patch, suricatasc has been migrated to rust
- removed references to legacy C based libhtp, libhtp has been migrated to rust
* Fri Aug  8 2025 Steve Grubb <[email protected]> 7.0.11-1
- New bugfix release
* Fri Jul 25 2025 Fedora Release Engineering <[email protected]> - 
7.0.10-3
- Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild
* Wed May 21 2025 Steve Grubb <[email protected]> 7.0.10-2
- Fix sysusers.d config to only be F42 and later
* Tue Mar 25 2025 Steve Grubb <[email protected]> 7.0.10-1
- New bugfix release
* Tue Mar 18 2025 Steve Grubb <[email protected]> 7.0.9-1
- New security and bugfix release
* Tue Feb 11 2025 Zbigniew Jędrzejewski-Szmek <[email protected]> - 7.0.8-3
- Add sysusers.d config file to allow rpm to create users/groups automatically
* Sun Jan 19 2025 Fedora Release Engineering <[email protected]> - 
7.0.8-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_42_Mass_Rebuild
* Fri Jan  3 2025 Steve Grubb <[email protected]> 7.0.8-1
- New security and bugfix release
* Tue Oct 22 2024 Richard W.M. Jones <[email protected]> - 7.0.7-2
- Rebuild for Jansson 2.14
  
(https://lists.fedoraproject.org/archives/list/[email protected]/thread/3PYINSQGKQ4BB25NQUI2A2UCGGLAG5ND/)
* Mon Oct 14 2024 Steve Grubb <[email protected]> 7.0.7-1
- New security and bugfix release
* Sat Jul 20 2024 Fedora Release Engineering <[email protected]> - 
7.0.6-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_41_Mass_Rebuild
* Thu Jun 27 2024 Steve Grubb <[email protected]> 7.0.6-1
- New security and bugfix release
* Fri Jun  7 2024 Steve Grubb <[email protected]> 7.0.5-3
- Don't fail install if log doesn't exist
* Sat May 11 2024 Kevin Fenzi <[email protected]> - 7.0.5-2
- rebuild for hiredis soname bump
* Tue May  7 2024 Steve Grubb <[email protected]> 7.0.5-1
- New security and bugfix release
* Wed Mar 20 2024 Steve Grubb <[email protected]> 7.0.4-1
- New security and bugfix release
* Mon Feb 26 2024 Steve Grubb <[email protected]> 7.0.3-1
- New security and bugfix release
* Wed Jan 31 2024 Steve Grubb <[email protected]> 7.0.2-1
- New major release
* Sat Jan 27 2024 Fedora Release Engineering <[email protected]> - 
6.0.15-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild
--------------------------------------------------------------------------------


-- 
_______________________________________________
epel-devel mailing list -- [email protected]
To unsubscribe send an email to [email protected]
Fedora Code of Conduct: 
https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedoraproject.org/archives/list/[email protected]
Do not reply to spam, report it: 
https://pagure.io/fedora-infrastructure/new_issue

Reply via email to