Locked testing stable

complyctl-1.0.0-1.fc44

FEDORA-2026-f33ade2ba6 created by marcusburghardt 6 days ago for Fedora 44

This update aligns the package to the latest Upstream release, which is also the first stable version of complyctl.

It introduced the core redesign from OSCAL to Gemara. The project has gone through three pre-release milestones (alpha, beta, RC) with contributions from 11 people across 200+ commits. This release marks the point where the CLI surface, configuration format, provider gRPC API, and output formats are considered stable under semantic versioning. More information in https://github.com/complytime/complyctl/releases/tag/v1.0.0

The providers, formerly plugins, were also moved to their own repository and are no longer delivered in the same package of complyctl. A new package called complytime-providers is being introduced to Fedora repositories via https://bugzilla.redhat.com/show_bug.cgi?id=2526823

How to install

Updates may require up to 24 hours to propagate to mirrors. If the following command doesn't work, please retry later:

sudo dnf upgrade --enablerepo=updates-testing --refresh --advisory=FEDORA-2026-f33ade2ba6

This update has been submitted for testing by marcusburghardt.

6 days ago

This update's test gating status has been changed to 'waiting'.

6 days ago

This update's test gating status has been changed to 'passed'.

6 days ago

This update has been pushed to testing.

5 days ago
User Icon marcusburghardt commented & provided feedback a day ago

Necessary also for new complytime-providers package: https://src.fedoraproject.org/rpms/complytime-providers

BZ#2454536 Private bug
BZ#2454537 Private bug
BZ#2489911 CVE-2026-39828 complyctl: golang.org/x/crypto/ssh: Unauthorized command execution via discarded SSH permissions [fedora-all]
BZ#2490104 CVE-2026-39829 complyctl: golang.org/x/crypto/ssh: Denial of Service via crafted public key with excessive parameters [fedora-all]
BZ#2490476 CVE-2026-39830 complyctl: golang.org/x/crypto/ssh: Denial of Service via resource leak from unsolicited SSH responses [fedora-all]
BZ#2493068 CVE-2026-39832 complyctl: golang.org/x/crypto/ssh/agent: Security bypass due to improper handling of key restrictions [fedora-all]
BZ#2493497 CVE-2026-39835 complyctl: golang.org/x/crypto/ssh: Denial of Service via crafted SSH certificate [fedora-all]
BZ#2494298 CVE-2026-27145 complyctl: golang crypto/x509: Denial of Service via excessive processing of DNS SAN entries [fedora-all]
BZ#2494449 CVE-2026-39833 complyctl: golang.org/x/crypto/ssh/agent: Security bypass due to unenforced key confirmation [fedora-all]
BZ#2494622 CVE-2026-42506 complyctl: golang.org/x/net/html: Cross-Site Scripting (XSS) via arbitrary HTML parsing [fedora-all]
BZ#2494912 CVE-2026-25680 complyctl: golang.org/x/net/html: Denial of Service due to excessive HTML parsing [fedora-all]
BZ#2495262 CVE-2026-25681 complyctl: golang.org/x/net/html: Arbitrary code execution via Cross-Site Scripting [fedora-all]
BZ#2496488 CVE-2026-44740 complyctl: Billy: Denial of Service via crafted input due to insufficient validation [fedora-all]
BZ#2503279 CVE-2025-47914 complyctl: SSH Agent servers: Denial of Service due to malformed messages [fedora-43]
BZ#2509299 CVE-2026-46597 complyctl: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
BZ#2509470 CVE-2026-39831 complyctl: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
User Icon hbraswel commented & provided feedback 9 hours ago
karma

Validated installation within a Podman Fedora 44 container. Works as expected.

Output:

# Checking for proper installation
[root@ca298878bf39 /]# rpm -q complyctl
complyctl-1.0.0-1.fc44.aarch64

The complyctl init command works as expected and creates the .complytime/complytime.yaml workspace configuration.

This update has been submitted for stable by marcusburghardt.

9 hours ago

Please log in to add feedback.

Metadata
Type
security
Severity
medium
Karma
1
Signed
Content Type
RPM
Test Gating
Autopush Settings
Unstable by Karma
-3
Stable by Karma
3
Stable by Time
7 days
Thresholds
Minimum Karma
+1
Minimum Testing
7 days
Dates
submitted
6 days ago
in testing
5 days ago
BZ#2454536 Private bug
0
1
BZ#2454537 Private bug
0
1
BZ#2489911 CVE-2026-39828 complyctl: golang.org/x/crypto/ssh: Unauthorized command execution via discarded SSH permissions [fedora-all]
0
1
BZ#2490104 CVE-2026-39829 complyctl: golang.org/x/crypto/ssh: Denial of Service via crafted public key with excessive parameters [fedora-all]
0
1
BZ#2490476 CVE-2026-39830 complyctl: golang.org/x/crypto/ssh: Denial of Service via resource leak from unsolicited SSH responses [fedora-all]
0
1
BZ#2493068 CVE-2026-39832 complyctl: golang.org/x/crypto/ssh/agent: Security bypass due to improper handling of key restrictions [fedora-all]
0
1
BZ#2493497 CVE-2026-39835 complyctl: golang.org/x/crypto/ssh: Denial of Service via crafted SSH certificate [fedora-all]
0
1
BZ#2494298 CVE-2026-27145 complyctl: golang crypto/x509: Denial of Service via excessive processing of DNS SAN entries [fedora-all]
0
1
BZ#2494449 CVE-2026-39833 complyctl: golang.org/x/crypto/ssh/agent: Security bypass due to unenforced key confirmation [fedora-all]
0
1
BZ#2494622 CVE-2026-42506 complyctl: golang.org/x/net/html: Cross-Site Scripting (XSS) via arbitrary HTML parsing [fedora-all]
0
1
BZ#2494912 CVE-2026-25680 complyctl: golang.org/x/net/html: Denial of Service due to excessive HTML parsing [fedora-all]
0
1
BZ#2495262 CVE-2026-25681 complyctl: golang.org/x/net/html: Arbitrary code execution via Cross-Site Scripting [fedora-all]
0
1
BZ#2496488 CVE-2026-44740 complyctl: Billy: Denial of Service via crafted input due to insufficient validation [fedora-all]
0
1
BZ#2503279 CVE-2025-47914 complyctl: SSH Agent servers: Denial of Service due to malformed messages [fedora-43]
0
1
BZ#2509299 CVE-2026-46597 complyctl: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
0
1
BZ#2509470 CVE-2026-39831 complyctl: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
0
1

Automated Test Results