Alerts This Week
Warning Icon 1 727
Alerts This Week
Warning Icon 1 727

Fedora 40: uv 2025-e923d51676 critical: rust dependency updates

fedora
Calendar Grey April 21, 2025
Dist Fedora Esm H88
Fedora 40 introduces a vital update for uv, tackling existing bugs while improving functionalities in Rust-centric package handling. Discover the details!
Update uv to 0.6.14, with various bugfixes and new features

Summary

An extremely fast Python package installer and resolver, written in Rust.

Designed as a drop-in replacement for common pip and pip-tools workflows.

Highlights:

• ⚖️ Drop-in replacement for common pip, pip-tools, and virtualenv commands.

• ⚡️ 10-100x faster than pip and pip-tools (pip-compile and pip-sync).

• 💾 Disk-space efficient, with a global cache for dependency deduplication.

• 🐍 Installable via curl, pip, pipx, etc. uv is a static binary that can be

installed without Rust or Python.

• 🧪 Tested at-scale against the top 10,000 PyPI packages.

• 🖥️ Support for macOS, Linux, and Windows.

• 🧰 Advanced features such as dependency version overrides and alternative

resolution strategies.

• ⁉️ Best-in-class error messages with a conflict-tracking resolver.

• 🤝 Support for a wide range of advanced pip features, including editable

installs, Git dependencies, direct URL dependencies, local dependencies,

constraints, source distributions, HTML and JSON indexes, and more.

Update Information:

Update uv to 0.6.14, with various bugfixes and new features. Update rust-idna to 1.0.3 (fixing RUSTSEC-2024-0421), rust-url to 2.5.4, rust- adblock to 0.9.6, and rust-cookie_store to 0.21.1; adjust some reverse dependencies of rust-idna. Initial packages for many dependencies. Update rust-ron to 0.9. Update rust-zip to 2.6.1, fixing GHSA-94vh-gphv-8pm8.

Change Log

* Fri Apr 11 2025 Benjamin A. Beasley - 0.6.14-3 - Patch bundled pubgrub/version-ranges fork for ron 0.9.0 final * Fri Apr 11 2025 Benjamin A. Beasley - 0.6.14-2 - Rebuilt with rust-idna 1.x * Thu Apr 10 2025 Benjamin A. Beasley - 0.6.14-1 - Update to 0.6.14 (close RHBZ#2358763) * Tue Apr 8 2025 Benjamin A. Beasley - 0.6.13-1 - Update to 0.6.13 (close RHBZ#2358064) * Fri Apr 4 2025 Benjamin A. Beasley - 0.6.12-2 - Update License expression * Fri Apr 4 2025 Benjamin A. Beasley - 0.6.12-1 - Update to 0.6.12 (close RHBZ#2354987) * Fri Apr 4 2025 Benjamin A. Beasley - 0.6.11-1 - Update to 0.6.11 * Thu Apr 3 2025 Benjamin A. Beasley - 0.6.10-1 - Update to 0.6.10 * Sat Mar 22 2025 Benjamin A. Beasley - 0.6.9-2 - Stop patching the forked async-zip for zip 0.6; use zip 2 * Fri Mar 21 2025 Benjamin A. Beasley - 0.6.9-1 - Update to 0.6.9 (close RHBZ#2353965) * Wed Mar 19 2025 Benjamin A. Beasley - 0.6.8-1 - Update to 0.6.8 (close RHBZ#2353281) * Tue Mar 18 2025 Benjamin A. Beasley - 0.6.7-1 - Update to 0.6.7 (close RHBZ#2353121) * Wed Mar 12 2025 Benjamin A. Beasley - 0.6.6-1 - Update to 0.6.6 (close RHBZ#2351456)

References


[ 1 ] Bug #2277901 - rust-adblock-0.9.6 is available https://bugzilla.redhat.com/show_bug.cgi?id=2277901 [ 2 ] Bug #2291175 - rust-idna-1.0.3 is available https://bugzilla.redhat.com/show_bug.cgi?id=2291175 [ 3 ] Bug #2323618 - rust-url-2.5.4 is available https://bugzilla.redhat.com/show_bug.cgi?id=2323618 [ 4 ] Bug #2324926 - rust-cookie_store-0.21.1 is available https://bugzilla.redhat.com/show_bug.cgi?id=2324926 [ 5 ] Bug #2352783 - rust-zip-2.6.1 is available https://bugzilla.redhat.com/show_bug.cgi?id=2352783 [ 6 ] Bug #2358015 - Review Request: rust-write16 - UTF-16 analog of the Write trait https://bugzilla.redhat.com/show_bug.cgi?id=2358015 [ 7 ] Bug #2358018 - Review Request: rust-utf16_iter - Iterator by char over potentially-invalid UTF-16 in &[u16] https://bugzilla.redhat.com/show_bug.cgi?id=2358018 [ 8 ] Bug #2358020 - Review Request: rust-icu_locid - API for managing Unicode Language and Locale Ide...

Read the Full Advisory

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-e923d51676' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

Severity
critical
Lowest
Low
Medium
High
Critical

Name: uv
Product: Fedora 40
Version: 0.6.14
Release: 3.fc40
Summary: An extremely fast Python package installer and resolver, written in Rust

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here