stable

python-jupytext-1.19.1-4.fc43

FEDORA-2026-85b819b928 created by jjames 4 months ago for Fedora 43

This update contains upgrades to various npm packages used during the build to address CVEs, namely:

  • CVE-2025-69873 (ajv)
  • CVE-2026-0540 (DOMPurify)
  • CVE-2026-3449 (@tootallnate/once)
  • CVE-2026-4800 (lodash)
  • CVE-2026-6321 (fast-uri)
  • CVE-2026-41240 (DOMPurify)

This is probably unimportant since these packages are used at build-time only. They are not shipped with python3-jupytext and therefore do not affect runtime.

How to install

Updates may require up to 24 hours to propagate to mirrors. If the following command doesn't work, please retry later:

sudo dnf upgrade --refresh --advisory=FEDORA-2026-85b819b928

This update has been submitted for testing by jjames.

4 months ago

This update's test gating status has been changed to 'ignored'.

4 months ago

This update has been pushed to testing.

4 months ago

This update has been submitted for stable by bodhi.

4 months ago

This update has been pushed to stable.

4 months ago

Please log in to add feedback.

Metadata
Type
security
Severity
low
Karma
0
Signed
Content Type
RPM
Test Gating
Autopush Settings
Unstable by Karma
-3
Stable by Karma
3
Stable by Time
7 days
Dates
submitted
4 months ago
in testing
4 months ago
in stable
4 months ago
approved
4 months ago
BZ#2439408 CVE-2025-69873 python-jupytext: ReDoS via $data reference [fedora-43]
0
0
BZ#2444210 CVE-2026-3449 python-jupytext: @tootallnate/once: Denial of Service due to incorrect control flow scoping with AbortSignal [fedora-all]
0
0
BZ#2444288 CVE-2026-0540 python-jupytext: DOMPurify: Cross-site scripting vulnerability [fedora-all]
0
0
BZ#2454050 CVE-2026-4800 python-jupytext: lodash: Arbitrary code execution via untrusted input in template imports [fedora-all]
0
0
BZ#2463432 CVE-2026-41240 python-jupytext: DOMPurify: Cross-Site Scripting (XSS) via inconsistent tag sanitization [fedora-all]
0
0
BZ#2466943 CVE-2026-6321 python-jupytext: fast-uri: Path traversal vulnerability allows bypass of security policies [fedora-all]
0
0

Automated Test Results