This package is a slimmed down version of uv containing only the build
backend.
Update Information:
uv 0.9.5 https://github.com/astral-sh/uv/blob/0.9.5/CHANGELOG.md Since uv was built with astral-tokio-tar 0.5.6, this is a security fix for CVE-2025-62518. ruff 0.14.2 https://github.com/astral-sh/ruff/blob/0.14.2/CHANGELOG.md rust-astral-tokio-tar 0.5.6 Fixed a parser desynchronization vulnerability when reading tar archives that contain mismatched size information in PAX/ustar headers. This vulnerability is being tracked as GHSA-j5gw-2vrg-8fgx and CVE-2025-62518. Initial package for python-uv-build in Fedora 42 Initial packages for a number of new dependencies for ruff and uv Update rust-tikv-jemallocator and rust-tikv-jemalloc-sys to 0.6.1 Update openapi-python-client to 0.26.2 and patch it to allow ruff 0.14
* Fri Oct 24 2025 Benjamin A. Beasley - 0.9.5-1
- Update to 0.9.5 (close RHBZ#2402881)
* Fri Oct 24 2025 Benjamin A. Beasley - 0.9.4-1
- Update to 0.9.4
* Thu Oct 23 2025 Benjamin A. Beasley - 0.9.3-1
- Update to 0.9.3
* Thu Oct 23 2025 Benjamin A. Beasley - 0.9.2-1
- Update to 0.9.2
* Thu Oct 23 2025 Benjamin A. Beasley - 0.9.1-1
- Update to 0.9.1
* Thu Oct 23 2025 Benjamin A. Beasley - 0.9.0-1
- Update to 0.9.0
* Wed Oct 22 2025 Benjamin A. Beasley - 0.8.24-1
- Update to 0.8.24
* Wed Oct 22 2025 Benjamin A. Beasley - 0.8.23-1
- Update to 0.8.23
* Wed Oct 22 2025 Benjamin A. Beasley - 0.8.22-1
- Update to 0.8.22
* Wed Oct 22 2025 Benjamin A. Beasley - 0.8.21-1
- Update to 0.8.21
* Mon Sep 29 2025 Benjamin A. Beasley - 0.8.20-1
- Update to 0.8.20 (close RHBZ#2389312)
* Mon Sep 29 2025 Benjamin A. Beasley - 0.8.19-1
- Update to 0.8.19
* Mon Sep 29 2025 Benjamin A. Beasley - 0.8.18-1
- Update to 0.8.18
* Sun Sep 28 2025 Benjamin A. Beasley - 0.8.17-1
- Update to 0.8.17
* Sun Sep 28 2025 Benjamin A. Beasley - 0.8.16-1
- Update to 0.8.16
* Sun Sep 28 2025 Benjamin A. Beasley - 0.8.15-1
- Update to 0.8.15
* Sun Sep 28 2025 Benjamin A. Beasley - 0.8.14-1
- Update to 0.8.14
* Sun Sep 28 2025 Benjamin A. Beasley - 0.8.13-1
- Update to 0.8.13
* Sun Sep 28 2025 Benjamin A. Beasley - 0.8.12-1
- Update to 0.8.12
* Sun Sep 28 2025 Benjamin A. Beasley - 0.8.11-4
- Use the bundled reqwest-middleware, too
* Fri Sep 19 2025 Python Maint - 0.8.11-2
- Rebuilt with rust-tracing-subscriber-0.3.20
- Fixes CVE-2025-58160: fixes RHBZ#2392055, fixes RHBZ#2392012, fixes
RHBZ#2391975
* Sat Aug 16 2025 Benjamin A. Beasley - 0.8.11-1
- Update to 0.8.11 (close RHBZ#2388438)
* Sat Aug 16 2025 Benjamin A. Beasley - 0.8.10-1
- Update to 0.8.10
* Fri Aug 15 2025 Python Maint - 0.8.9-1
- Update to 0.8.9 (close RHBZ#2387765)
* Sat Aug 9 2025 Benjamin A. Beasley - 0.8.8-1
- Update to 0.8.8 (close RHBZ#2387092)
* Sat Aug 9 2025 Benjamin A. Beasley - 0.8.7-1
- Update to 0.8.7
* Sat Aug 9 2025 Benjamin A. Beasley - 0.8.6-1
- Update to 0.8.6
* Wed Aug 6 2025 Benjamin A. Beasley - 0.8.5-1
- Update to 0.8.5 (close RHBZ#2386645)
* Thu Jul 31 2025 Benjamin A. Beasley - 0.8.4-1
- Update to 0.8.4 (close RHBZ#2381737)
* Thu Jul 31 2025 Benjamin A. Beasley - 0.8.3-1
- Update to 0.8.3
* Tue Jul 29 2025 Benjamin A. Beasley - 0.8.2-1
- Update to 0.8.2
* Tue Jul 29 2025 Benjamin A. Beasley - 0.8.1-1
- Update to 0.8.1
* Tue Jul 29 2025 Benjamin A. Beasley - 0.8.0-1
- Update to 0.8.0
* Fri Jul 25 2025 Fedora Release Engineering - 0.7.22-1
- Update to 0.7.22
* Tue Jul 15 2025 Benjamin A. Beasley - 0.7.21-1
- Update to 0.7.21 (close RHBZ#2379123)
* Thu Jul 10 2025 Benjamin A. Beasley - 0.7.20-1
- Update to 0.7.20 (close RHBZ#2379145)
* Tue Jul 8 2025 Benjamin A. Beasley - 0.7.19-1
- Update to 0.7.19 (close RHBZ#2375432)
* Tue Jul 8 2025 Benjamin A. Beasley - 0.7.18-1
- Update to 0.7.18
* Tue Jul 8 2025 Benjamin A. Beasley - 0.7.17-1
- Update to 0.7.17
* Sat Jun 28 2025 Benjamin A. Beasley - 0.7.16-1
- Update to 0.7.16 (close RHBZ#2374368)
* Sat Jun 28 2025 Benjamin A. Beasley - 0.7.15-1
- Update to 0.7.15
* Thu Jun 26 2025 Benjamin A. Beasley - 0.7.14-1
- Update to 0.7.14
* Thu Jun 26 2025 Benjamin A. Beasley - 0.7.13-2
- Correctly patch out foreign deps. in bundled crates
* Fri Jun 13 2025 Benjamin A. Beasley - 0.7.13-1
- Update to 0.7.13 (close RHBZ#2372600)
* Mon Jun 9 2025 Benjamin A. Beasley - 0.7.12-1
- Update to 0.7.12 (close RHBZ#2370052)
* Mon Jun 9 2025 Benjamin A. Beasley - 0.7.11-1
- Update to 0.7.11
* Mon Jun 9 2025 Benjamin A. Beasley - 0.7.10-1
- Update to 0.7.10
* Tue Jun 3 2025 Python Maint - 0.7.9-1
- Update to 0.7.9 (close RHBZ#2369520)
* Sun May 25 2025 Benjamin A. Beasley - 0.7.8-1
- Update to 0.7.8 (close RHBZ#2368082)
* Tue May 20 2025 Benjamin A. Beasley - 0.7.6-1
- Update to 0.7.6 (close RHBZ#2367412)
* Sat May 17 2025 Benjamin A. Beasley - 0.7.5-1
- Update to 0.7.5 (close RHBZ#2362369)
* Sat May 17 2025 Benjamin A. Beasley - 0.7.4-1
- Update to 0.7.4
* Fri May 16 2025 Benjamin A. Beasley - 0.7.3-1
- Update to 0.7.3
* Fri May 9 2025 Benjamin A. Beasley - 0.7.2-1
- Update to 0.7.2
* Fri May 9 2025 Benjamin A. Beasley - 0.7.1-1
- Update to 0.7.1
* Fri May 9 2025 Benjamin A. Beasley - 0.7.0-1
- Update to 0.7.0
* Fri May 9 2025 Benjamin A. Beasley - 0.6.17-2
- F41+: Use the provisional pyproject declarative buildsystem
* Mon May 5 2025 Benjamin A. Beasley - 0.6.17-1
- Update to 0.6.17
* Fri Apr 25 2025 Benjamin A. Beasley - 0.6.16-3
- Fix a typo in the LICENSE expression (missing AND)
* Fri Apr 25 2025 Benjamin A. Beasley - 0.6.16-2
- Update ron to 0.10
* Tue Apr 22 2025 Benjamin A. Beasley - 0.6.16-1
- Update to 0.6.16 (close RHBZ#2361554)
- Update the License expression, primarily due to rust-idna 1.x
* Sat Apr 12 2025 Benjamin A. Beasley - 0.6.14-2
- Patch bundled pubgrub/version-ranges fork for ron 0.9.0 final
* Thu Apr 10 2025 Benjamin A. Beasley - 0.6.14-1
- Update to 0.6.14 (close RHBZ#2358749)
* Tue Apr 8 2025 Benjamin A. Beasley - 0.6.13-1
- Update to 0.6.13 (close RHBZ#2358054)
* Sat Apr 5 2025 Benjamin A. Beasley - 0.6.12-2
- Let LICENSE.dependencies be installed in the .dist-info
* Fri Apr 4 2025 Benjamin A. Beasley - 0.6.12-1
- Initial package (close RHBZ#2357473)
[ 1 ] Bug #2360699 - ruff-0.14.1 is available
https://bugzilla.redhat.com/show_bug.cgi?id=2360699
[ 2 ] Bug #2402441 - rust-reqsign-core-2.0.0 is available
https://bugzilla.redhat.com/show_bug.cgi?id=2402441
[ 3 ] Bug #2402442 - rust-reqsign-command-execute-tokio-2.0.0 is available
https://bugzilla.redhat.com/show_bug.cgi?id=2402442
[ 4 ] Bug #2402443 - rust-reqsign-http-send-reqwest-2.0.0 is available
https://bugzilla.redhat.com/show_bug.cgi?id=2402443
[ 5 ] Bug #2402881 - python-uv-build-0.9.5 is available
https://bugzilla.redhat.com/show_bug.cgi?id=2402881
[ 6 ] Bug #2402923 - uv-0.9.5 is available
https://bugzilla.redhat.com/show_bug.cgi?id=2402923
[ 7 ] Bug #2405474 - CVE-2025-62518 rust-astral-tokio-tar: astral-tokio-tar Vulnerable to PAX Header Desynchronization [fedora-42]
https://bugzilla.redhat.com/show_bug.cgi?id=2405474
[ 8 ] Bug #2405476 - CVE-2025-62518 uv: astral-tokio-tar Vulnerable...
This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-a77c1f005b' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label
Get the latest Linux and open source security news straight to your inbox.