Aggregator
buildah-1.43.1-1.fc42 podman-5.8.2-1.fc42 skopeo-1.22.2-1.fc42
- buildah-1.43.1-1.fc42
- podman-5.8.2-1.fc42
- skopeo-1.22.2-1.fc42
Automatic update for buildah-1.43.1-1.fc42, skopeo-1.22.2-1.fc42, podman-5.8.2-1.fc42.
Changelog for buildah * Wed Apr 08 2026 Packit <hello@packit.dev> - 2:1.43.1-1 - Update to 1.43.1 upstream release Changelog for skopeo * Tue Apr 14 2026 Packit <hello@packit.dev> - 1:1.22.2-1 - Update to 1.22.2 upstream release * Fri Apr 10 2026 Lokesh Mandvekar <lsm5@redhat.com> - 1:1.22.1-2 - TMT: fix ref in plan * Thu Apr 09 2026 Packit <hello@packit.dev> - 1:1.22.1-1 - Update to 1.22.1 upstream release Changelog for podman * Tue Apr 14 2026 Packit <hello@packit.dev> - 5:5.8.2-1 - Update to 5.8.2 upstream releaseSecurity fix for CVE-2026-34986
buildah-1.43.1-1.fc43 podman-5.8.2-1.fc43 skopeo-1.22.2-1.fc43
- buildah-1.43.1-1.fc43
- podman-5.8.2-1.fc43
- skopeo-1.22.2-1.fc43
Automatic update for skopeo-1.22.2-1.fc43, podman-5.8.2-1.fc43, buildah-1.43.1-1.fc43.
Changelog for skopeo * Tue Apr 14 2026 Packit <hello@packit.dev> - 1:1.22.2-1 - Update to 1.22.2 upstream release * Fri Apr 10 2026 Lokesh Mandvekar <lsm5@redhat.com> - 1:1.22.1-2 - TMT: fix ref in plan * Thu Apr 09 2026 Packit <hello@packit.dev> - 1:1.22.1-1 - Update to 1.22.1 upstream release Changelog for podman * Tue Apr 14 2026 Packit <hello@packit.dev> - 5:5.8.2-1 - Update to 5.8.2 upstream release Changelog for buildah * Wed Apr 08 2026 Packit <hello@packit.dev> - 2:1.43.1-1 - Update to 1.43.1 upstream releaseSecurity fix for CVE-2026-34986
buildah-1.43.1-1.fc44 podman-5.8.2-1.fc44 skopeo-1.22.2-1.fc44
- buildah-1.43.1-1.fc44
- podman-5.8.2-1.fc44
- skopeo-1.22.2-1.fc44
Automatic update for buildah-1.43.1-1.fc44, podman-5.8.2-1.fc44, skopeo-1.22.2-1.fc44.
Changelog for buildah * Wed Apr 08 2026 Packit <hello@packit.dev> - 2:1.43.1-1 - Update to 1.43.1 upstream release Changelog for podman * Tue Apr 14 2026 Packit <hello@packit.dev> - 5:5.8.2-1 - Update to 5.8.2 upstream release Changelog for skopeo * Tue Apr 14 2026 Packit <hello@packit.dev> - 1:1.22.2-1 - Update to 1.22.2 upstream release * Fri Apr 10 2026 Lokesh Mandvekar <lsm5@redhat.com> - 1:1.22.1-2 - TMT: fix ref in plan * Thu Apr 09 2026 Packit <hello@packit.dev> - 1:1.22.1-1 - Update to 1.22.1 upstream releaseSecurity fix for CVE-2026-34986
USN-8168-2: Rust vulnerability
next-20260414: linux-next
pie-1.4.1-1.fc42
- pie-1.4.1-1.fc42
Version 1.4.1
- Update bundled Composer to 2.9.7
New features!
- Prompt to install missing system dependencies
- Prompt to install build toolchain
- Support pre-packaged-binary for download-url-method
- Support INSTALL_ROOT environment variable to override destination
For more information, see Upstream annoucenement
pie-1.4.1-1.el10_3
- pie-1.4.1-1.el10_3
Version 1.4.1
- Update bundled Composer to 2.9.7
New features!
- Prompt to install missing system dependencies
- Prompt to install build toolchain
- Support pre-packaged-binary for download-url-method
- Support INSTALL_ROOT environment variable to override destination
For more information, see Upstream annoucenement
pie-1.4.1-1.el10_1
- pie-1.4.1-1.el10_1
Version 1.4.1
- Update bundled Composer to 2.9.7
New features!
- Prompt to install missing system dependencies
- Prompt to install build toolchain
- Support pre-packaged-binary for download-url-method
- Support INSTALL_ROOT environment variable to override destination
For more information, see Upstream annoucenement
pie-1.4.1-1.el10_2
- pie-1.4.1-1.el10_2
Version 1.4.1
- Update bundled Composer to 2.9.7
New features!
- Prompt to install missing system dependencies
- Prompt to install build toolchain
- Support pre-packaged-binary for download-url-method
- Support INSTALL_ROOT environment variable to override destination
For more information, see Upstream annoucenement
pie-1.4.1-1.fc44
- pie-1.4.1-1.fc44
Version 1.4.1
- Update bundled Composer to 2.9.7
New features!
- Prompt to install missing system dependencies
- Prompt to install build toolchain
- Support pre-packaged-binary for download-url-method
- Support INSTALL_ROOT environment variable to override destination
For more information, see Upstream annoucenement
pie-1.4.1-1.fc43
- pie-1.4.1-1.fc43
Version 1.4.1
- Update bundled Composer to 2.9.7
New features!
- Prompt to install missing system dependencies
- Prompt to install build toolchain
- Support pre-packaged-binary for download-url-method
- Support INSTALL_ROOT environment variable to override destination
For more information, see Upstream annoucenement
curl-8.11.1-8.fc42
- curl-8.11.1-8.fc42
- fix bad reuse of HTTP Negotiate connection (CVE-2026-1965)
- fix token leak with redirect and netrc (CVE-2026-3783)
- fix wrong proxy connection reuse with credentials (CVE-2026-3784)
- fix use after free in SMB connection reuse (CVE-2026-3805)
composer-2.9.7-1.el10_3
- composer-2.9.7-1.el10_3
- Fixes regression calling custom script command aliases that are called a substring of a composer command (#12802)
- Security: Fixed command injection via malicious Perforce reference (GHSA-gqw4-4w2p-838q / CVE-2026-40261)
- Security: Fixed command injection via malicious Perforce repository definition (GHSA-wg36-wvj6-r67p / CVE-2026-40176)
- Security: Fixed git credentials remaining in git mirror .git/config after clone or update failed (2bcbfc3d)
- Security: Fixed usage of insecure 3DES ciphers when ext-curl is missing (5e71d77e)
- Security: Fixed Perforce unescaped user input in queryP4User shell command (ef3fc088)
- Security: Hardened git/hg/perforce/fossil identifier validation to ensure branch names starting with - do not cause issues (6621d45, d836b90, 5e08c764)
- Fixed inconsistent treatment of SingleCommandApplication script commands wrt autoloading (#12758)
- Fixed GitHub API authentication errors not being visible to the user (#12737)
- Fixed some platform package parsing failing when Composer runs in web SAPIs (#12735)
- Fixed error reporting for clarity when a constraint cannot be parsed (#12743)
composer-2.9.7-1.el9
- composer-2.9.7-1.el9
- Fixes regression calling custom script command aliases that are called a substring of a composer command (#12802)
- Security: Fixed command injection via malicious Perforce reference (GHSA-gqw4-4w2p-838q / CVE-2026-40261)
- Security: Fixed command injection via malicious Perforce repository definition (GHSA-wg36-wvj6-r67p / CVE-2026-40176)
- Security: Fixed git credentials remaining in git mirror .git/config after clone or update failed (2bcbfc3d)
- Security: Fixed usage of insecure 3DES ciphers when ext-curl is missing (5e71d77e)
- Security: Fixed Perforce unescaped user input in queryP4User shell command (ef3fc088)
- Security: Hardened git/hg/perforce/fossil identifier validation to ensure branch names starting with - do not cause issues (6621d45, d836b90, 5e08c764)
- Fixed inconsistent treatment of SingleCommandApplication script commands wrt autoloading (#12758)
- Fixed GitHub API authentication errors not being visible to the user (#12737)
- Fixed some platform package parsing failing when Composer runs in web SAPIs (#12735)
- Fixed error reporting for clarity when a constraint cannot be parsed (#12743)
composer-2.9.7-1.fc44
- composer-2.9.7-1.fc44
- Fixes regression calling custom script command aliases that are called a substring of a composer command (#12802)
- Security: Fixed command injection via malicious Perforce reference (GHSA-gqw4-4w2p-838q / CVE-2026-40261)
- Security: Fixed command injection via malicious Perforce repository definition (GHSA-wg36-wvj6-r67p / CVE-2026-40176)
- Security: Fixed git credentials remaining in git mirror .git/config after clone or update failed (2bcbfc3d)
- Security: Fixed usage of insecure 3DES ciphers when ext-curl is missing (5e71d77e)
- Security: Fixed Perforce unescaped user input in queryP4User shell command (ef3fc088)
- Security: Hardened git/hg/perforce/fossil identifier validation to ensure branch names starting with - do not cause issues (6621d45, d836b90, 5e08c764)
- Fixed inconsistent treatment of SingleCommandApplication script commands wrt autoloading (#12758)
- Fixed GitHub API authentication errors not being visible to the user (#12737)
- Fixed some platform package parsing failing when Composer runs in web SAPIs (#12735)
- Fixed error reporting for clarity when a constraint cannot be parsed (#12743)
composer-2.9.7-1.el10_2
- composer-2.9.7-1.el10_2
- Fixes regression calling custom script command aliases that are called a substring of a composer command (#12802)
- Security: Fixed command injection via malicious Perforce reference (GHSA-gqw4-4w2p-838q / CVE-2026-40261)
- Security: Fixed command injection via malicious Perforce repository definition (GHSA-wg36-wvj6-r67p / CVE-2026-40176)
- Security: Fixed git credentials remaining in git mirror .git/config after clone or update failed (2bcbfc3d)
- Security: Fixed usage of insecure 3DES ciphers when ext-curl is missing (5e71d77e)
- Security: Fixed Perforce unescaped user input in queryP4User shell command (ef3fc088)
- Security: Hardened git/hg/perforce/fossil identifier validation to ensure branch names starting with - do not cause issues (6621d45, d836b90, 5e08c764)
- Fixed inconsistent treatment of SingleCommandApplication script commands wrt autoloading (#12758)
- Fixed GitHub API authentication errors not being visible to the user (#12737)
- Fixed some platform package parsing failing when Composer runs in web SAPIs (#12735)
- Fixed error reporting for clarity when a constraint cannot be parsed (#12743)
composer-2.9.7-1.fc42
- composer-2.9.7-1.fc42
- Fixes regression calling custom script command aliases that are called a substring of a composer command (#12802)
- Security: Fixed command injection via malicious Perforce reference (GHSA-gqw4-4w2p-838q / CVE-2026-40261)
- Security: Fixed command injection via malicious Perforce repository definition (GHSA-wg36-wvj6-r67p / CVE-2026-40176)
- Security: Fixed git credentials remaining in git mirror .git/config after clone or update failed (2bcbfc3d)
- Security: Fixed usage of insecure 3DES ciphers when ext-curl is missing (5e71d77e)
- Security: Fixed Perforce unescaped user input in queryP4User shell command (ef3fc088)
- Security: Hardened git/hg/perforce/fossil identifier validation to ensure branch names starting with - do not cause issues (6621d45, d836b90, 5e08c764)
- Fixed inconsistent treatment of SingleCommandApplication script commands wrt autoloading (#12758)
- Fixed GitHub API authentication errors not being visible to the user (#12737)
- Fixed some platform package parsing failing when Composer runs in web SAPIs (#12735)
- Fixed error reporting for clarity when a constraint cannot be parsed (#12743)
composer-2.9.7-1.fc43
- composer-2.9.7-1.fc43
- Fixes regression calling custom script command aliases that are called a substring of a composer command (#12802)
- Security: Fixed command injection via malicious Perforce reference (GHSA-gqw4-4w2p-838q / CVE-2026-40261)
- Security: Fixed command injection via malicious Perforce repository definition (GHSA-wg36-wvj6-r67p / CVE-2026-40176)
- Security: Fixed git credentials remaining in git mirror .git/config after clone or update failed (2bcbfc3d)
- Security: Fixed usage of insecure 3DES ciphers when ext-curl is missing (5e71d77e)
- Security: Fixed Perforce unescaped user input in queryP4User shell command (ef3fc088)
- Security: Hardened git/hg/perforce/fossil identifier validation to ensure branch names starting with - do not cause issues (6621d45, d836b90, 5e08c764)
- Fixed inconsistent treatment of SingleCommandApplication script commands wrt autoloading (#12758)
- Fixed GitHub API authentication errors not being visible to the user (#12737)
- Fixed some platform package parsing failing when Composer runs in web SAPIs (#12735)
- Fixed error reporting for clarity when a constraint cannot be parsed (#12743)
composer-2.9.7-1.el10_1
- composer-2.9.7-1.el10_1
- Fixes regression calling custom script command aliases that are called a substring of a composer command (#12802)
- Security: Fixed command injection via malicious Perforce reference (GHSA-gqw4-4w2p-838q / CVE-2026-40261)
- Security: Fixed command injection via malicious Perforce repository definition (GHSA-wg36-wvj6-r67p / CVE-2026-40176)
- Security: Fixed git credentials remaining in git mirror .git/config after clone or update failed (2bcbfc3d)
- Security: Fixed usage of insecure 3DES ciphers when ext-curl is missing (5e71d77e)
- Security: Fixed Perforce unescaped user input in queryP4User shell command (ef3fc088)
- Security: Hardened git/hg/perforce/fossil identifier validation to ensure branch names starting with - do not cause issues (6621d45, d836b90, 5e08c764)
- Fixed inconsistent treatment of SingleCommandApplication script commands wrt autoloading (#12758)
- Fixed GitHub API authentication errors not being visible to the user (#12737)
- Fixed some platform package parsing failing when Composer runs in web SAPIs (#12735)
- Fixed error reporting for clarity when a constraint cannot be parsed (#12743)