https://github.com/astral-sh/uv/blob/0.9.5/CHANGELOG.md
Since uv was built with astral-tokio-tar 0.5.6, this is a security fix for CVE-2025-62518.
https://github.com/astral-sh/ruff/blob/0.14.2/CHANGELOG.md
Fixed a parser desynchronization vulnerability when reading tar archives that contain mismatched size information in PAX/ustar headers.
This vulnerability is being tracked as GHSA-j5gw-2vrg-8fgx and CVE-2025-62518.
python-uv-build in Fedora 42ruff and uvrust-tikv-jemallocator and rust-tikv-jemalloc-sys to 0.6.1openapi-python-client to 0.26.2 and patch it to allow ruff 0.14Updates may require up to 24 hours to propagate to mirrors. If the following command doesn't work, please retry later:
sudo dnf upgrade --refresh --advisory=FEDORA-2025-a77c1f005b
Please log in to add feedback.
This update's test gating status has been changed to 'waiting'.
This update's test gating status has been changed to 'ignored'.
This update has been submitted for testing by bodhi.
This update has been pushed to testing.
music edited this update.
New build(s):
Karma has been reset.
This update has been submitted for testing by music.
This update has been pushed to testing.
music edited this update.
New build(s):
Karma has been reset.
This update has been submitted for testing by music.
This update has been pushed to testing.
music edited this update.
music edited this update.
music edited this update.
New build(s):
Karma has been reset.
This update has been submitted for testing by music.
This update has obsoleted openapi-python-client-0.26.2-2.fc42, and has inherited its bugs and notes.
music edited this update.
This update has been pushed to testing.
music edited this update.
New build(s):
Karma has been reset.
This update has been submitted for testing by music.
music edited this update.
music edited this update.
New build(s):
Karma has been reset.
music edited this update.
New build(s):
Karma has been reset.
This update has been pushed to testing.
music edited this update.
New build(s):
Removed build(s):
Karma has been reset.
This update has been submitted for testing by music.
music edited this update.
music edited this update.
This update has been pushed to testing.
music edited this update.
music edited this update.
music edited this update.
New build(s):
Removed build(s):
Karma has been reset.
This update has been submitted for testing by music.
This update has been pushed to testing.
music edited this update.
New build(s):
Removed build(s):
Karma has been reset.
This update has been submitted for testing by music.
With ruff and uv now both fully up to date, I’m going to try to stop editing this so that it can go stable.
music edited this update.
This update has been pushed to testing.
This update has been submitted for stable by bodhi.
This update has been pushed to stable.