uv / python-uv-build 0.9.5 https://github.com/astral-sh/uv/blob/0.9.5/CHANGELOG.md ruff 0.14.2 https://github.com/astral-sh/ruff/blob/0.14.2/CHANGELOG.md Pydantic 2.12.3. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-4154ea83d0 2025-11-05 02:09:57.817569+00:00 -------------------------------------------------------------------------------- Name : openapi-python-client Product : Fedora 43 Version : 0.26.2 Release : 4.fc43 URL : https://github.com/openapi-generators/openapi-python-client Summary : Generate modern Python clients from OpenAPI Description : The openapi-python-client is a powerful tool designed to generate modern Python clients from OpenAPI 3.0+ documents supporting both synchronous and asynchronous HTTP requests. It automates the creation of Python classes and methods that correspond to the endpoints and schema defined in your OpenAPI specification, making it easier to interact with your API in a type-safe manner. -------------------------------------------------------------------------------- Update Information: uv / python-uv-build 0.9.5 https://github.com/astral-sh/uv/blob/0.9.5/CHANGELOG.md ruff 0.14.2 https://github.com/astral-sh/ruff/blob/0.14.2/CHANGELOG.md Pydantic 2.12.3 Blog post maturin 1.9.6 https://github.com/PyO3/maturin/blob/v1.9.6/Changelog.md python-typing-inspection 0.4.2 (2025-10-01) Add typing_objects.is_noextraitems() python-jiter 0.11.0 https://github.com/pydantic/jiter/releases/tag/v0.11.0 python-pydantic-extra-types 2.10.6 https://github.com/pydantic/pydantic-extra-types/releases/tag/v2.10.6 Typer 0.20.0 Features \u2728 Enable command suggestions on typo by default. Upgrades \u2b06\ufe0f Add (official) support for Python 3.14. Internal Assorted small enhancements. FastAPI 0.120.1 Upgrades \u2b06\ufe0f Bump Starlette to
It was discovered that there was a potential SQL injection attack in python-pymysql, a MySQL client library for Python. This was exploitable when python-pymysql was used with untrusted JSON input as keys were not escaped by the escape_dict routine. . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-3822-1
In OWSLib, a Python client library for Open Geospatial web services, the XML parser did not disable entity resolution which could lead to arbitrary file reads from an attacker-controlled XML payload. . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-3470-1
Update to latest Synapse release which fixes CVE-2018-12291 (0.31.1) and a second security bug in 0.31.2: https://github.com/matrix-org/synapse/releases/tag/v0.31.2 This update includes a new package which is a dependency introduced by synapse-0.31. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2018-6e759af8fb 2018-06-23 20:45:47.528690 --------------------------------------------------------------------------------Name : python-prometheus_client Product : Fedora 28 Version : 0.2.0 Release : 1.fc28 URL : https://github.com/prometheus/client_python Summary : The Python client for Prometheus Description : The Python client for Prometheus. --------------------------------------------------------------------------------Update Information: Update to latest Synapse release which fixes CVE-2018-12291 (0.31.1) and a second security bug in 0.31.2: https://github.com/matrix-org/synapse/releases/tag/v0.31.2 This update includes a new package which is a dependency introduced by synapse-0.31 --------------------------------------------------------------------------------References: [ 1 ] Bug #1590102 - CVE-2018-12291 matrix-synapse: Missing event filtering in handlers/federation.py [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1590102 [ 2 ] Bug #1578181 - matrix-synapse-0.31.1 is available https://bugzilla.redhat.com/show_bug.cgi?id=1578181 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2018-6e759af8fb' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.