Aggregator

p11-kit-0.26.5-1.fc43

9 hours 10 minutes ago
FEDORA-2026-e281fdcb69 Packages in this update:
  • p11-kit-0.26.5-1.fc43
Update description:

rpc: guard against overflow when decoding nested attributes (CVE-2026-18938) Only affects 32 bit systems

p11-kit-0.26.5-1.fc44

9 hours 10 minutes ago
FEDORA-2026-110c1a7742 Packages in this update:
  • p11-kit-0.26.5-1.fc44
Update description:

rpc: guard against overflow when decoding nested attributes (CVE-2026-18938) Only affects 32 bit systems

php-pear-PHP-CodeSniffer-4.0.4-1.fc44

17 hours 11 minutes ago
FEDORA-2026-d536e7004b Packages in this update:
  • php-pear-PHP-CodeSniffer-4.0.4-1.fc44
Update description: Version 4.0.4 - 2026-08-06

This is a security release and all users are advised to update their install(s) as soon as possible. The security issue only affects users of the Gitblame, Hgblame or Svnblame report(s).

Added
  • Tokenizer support for the PHP 8.5 (void) cast. [#1325] The T_VOID_CAST token has been added to the Tokens::CAST_TOKENS array.
  • suggest section to the composer.json file to inform users about the recommended iconv and pcntl PHP extensions. [#1388]
    • Thanks to [Rodrigo Primo][@rodrigoprimo] for the patch.
Changed
  • Clarified that libxml is a required PHP extension. [#1409]
  • Squiz.Scope.StaticThisUsage: the sniff will now also search for the use of $this in static closures. [#1377]
  • The Generic.PHP.LowerCaseKeyword, Generic.WhiteSpace.LanguageConstructSpacing and Squiz.Functions.FunctionDeclarationArgumentSpacing sniffs no longer embed UTF-8 middot characters for spaces in error messages. [#1379], [#1389] Fixes [Squiz/#2652][sq-2652].
    • Thanks to [Rodrigo Primo][@rodrigoprimo] for the patches.
  • PSR2.ControlStructures.SwitchDeclaration: the error message for the use of colon + curly braces (WrongOpener*) has been made more informative. [#1358]. Fixes [#1322].
    • Thanks to [Sule-Balogun Olanrewaju][@bigdevlarry] for the patch.
  • The error messages for the following sniffs have been improved by exposing more data placeholders:
    • PEAR.Functions.FunctionDeclaration [#1445]
      • The CloseBracketLine error message now exposes 1 data value (previously 0).
      • The EmptyLine error message now exposes 1 data value (previously 0).
      • The Indent error message now exposes 3 data values (previously 2).
      • These changes also affect the same error codes for the PSR12.Classes.AnonClassDeclaration and Squiz.Functions.MultiLineFunctionDeclaration sniffs.
    • PSR2.Classes.ClassDeclaration [#1446]
      • The ExtendsLine and ImplementsLine error messages now expose 3 data values (previously 1).
      • The SpaceBeforeExtends and SpaceBeforeImplements error messages now expose 2 data values (previously 1).
      • These changes also affect the same error codes for the PSR12.Classes.AnonClassDeclaration and Squiz.Classes.ClassDeclaration sniffs.
    • PSR2.ControlStructures.SwitchDeclaration [#1447]
      • The defaultNotLower and caseNotLower error messages now expose 3 data values (previously 2).
      • The SpaceBeforeColonDEFAULT and SpaceBeforeColonCASE error messages now expose 1 data value (previously 0).
      • The BodyOnNextLineDEFAULT and BodyOnNextLineCASE error messages now expose 1 data value (previously 0).
      • The WrongOpenerdefault and WrongOpenercase error messages now expose 1 data value (previously 0).
    • Squiz.ControlStructures.SwitchDeclaration [#1449]
      • The CaseNotLower and DefaultNotLower error messages now expose 3 data values (previously 2).
      • The CaseIndent and DefaultIndent error messages now expose 2 data values (previously 0).
      • The SpaceBeforeColonCase and SpaceBeforeColonDefault error messages now expose 1 data value (previously 0).
      • The BreakIndent error message now exposes 1 data value (previously 0).
      • The SpacingAfterCase and SpacingAfterDefault error messages now expose 1 data value (previously 0).
    • Squiz.Functions.FunctionDeclarationArgumentSpacing [#1452]
      • The SpaceBeforeEquals error message now exposes 3 data values (previously 2).
      • The SpaceAfterEquals error message now exposes 3 data values (previously 2).
    • Squiz.Functions.MultiLineFunctionDeclaration [#1453]
      • The FirstParamSpacing and UseFirstParamSpacing error messages now expose 1 data value (previously 0).
      • The OneParamPerLine and UseOneParamPerLine error messages now expose 1 data value (previously 0).
      • These changes also affect the same error codes for the PSR12.Classes.AnonClassDeclaration sniff.
    • If you have customised the error messages of these sniffs, please review your ruleset after upgrading.
    • Thanks to [Zhang WenTao][@ntdiary] for these patches.
  • The following sniff(s) have received efficiency improvements:
    • PSR2.Classes.PropertyDeclaration
    • Thanks to [Jonathan Champ][@jrchamp] for the patch.
  • The test suite is now more contributor friendly for contributors on MacOS. [#1437]
    • Thanks to [Sergei Morozov][@morozov] for the patch.
  • Various housekeeping, including improvements to the tests and documentation.
    • Thanks to [Dan Wallis][@fredden], [Rodrigo Primo][@rodrigoprimo], [Sergei Morozov][@morozov] and [Juliette Reinders Folmer][@jrfnl] for their contributions.
Fixed
  • SECURITY FIX: Running PHP_CodeSniffer over untrusted files, for example, in a CI pipeline that scans pull requests, or on a developer machine reviewing third-party code, could result in attacker-controlled shell commands being executed when the Gitblame, Hgblame or Svnblame report(s) would process a file whose name contains shell metacharacters. [#1473]
    • Users using the default Full report, or any of the other non-*blame reports, are not affected.
    • For more details, see the [security advisory][sec-1].
    • Thanks go to [Faze-up][@Faze-up] and [Volker Dusch][@edorian] for responsibly disclosing the vulnerability.
    • Additionally, thanks go to [Volker Dusch][@edorian], [Rodrigo Primo][@rodrigoprimo], [Dan Wallis][@fredden] and [Juliette Reinders Folmer][@jrfnl] for creating and testing the fix.
  • Fixed bug [#1320]: Generic.Strings.UnnecessaryHeredoc: the fixer could incidentally change tab indentation to space indentation in select lines in the heredoc body.
  • Fixed bug [#1354]: PSR12.Functions.ReturnTypeDeclaration: prevent an "Undefined array key" warning if the code under scan contains a parse error.
    • Thanks to [Dan Wallis][@fredden] for the patch.
  • Fixed bug [#1357]: Squiz.Scope.StaticThisUsage: false positive for usage of $this in non-static closures nested in OO methods.
  • Fixed bug [#1368]: PEAR.Functions.FunctionDeclaration: the indentation for subsequent lines in multi-line block comments within a multi-line function signature, would be incorrectly determined, leading to false positives and resulting in a fixer conflict when running phpcbf.
    • This also fixes, by extension, the same issue in the Squiz.Functions.MultiLineFunctionDeclaration sniff.
  • Fixed bug [#1418]: Tokenizer/PHP: tokenization of an inline else colon after an inline comment could fail and/or throw a "Trying to access array offset on null" warning.
    • Thanks to [Lazizbek Ergashev][@lazerg] for the patch.
  • Fixed bug [#1435]: Generic.Formatting.MultipleStatementAlignment would get into a fixer conflict for multiple assignments within a single statement spanning multiple lines.
    • Same as when the statement would be single-line, alignment of subsequent assignment operators within the same multi-line statement will now be ignored.
    • Thanks to [Sergei Morozov][@morozov] for the patch.
  • Fixed bug [#1451]: Tokenizer/PHP: prevent an "Undefined array key" warning during live coding when a file ends on the name in a constant declaration.
    • Thanks to [Lazizbek Ergashev][@lazerg] and [Sai Asish Y][@SAY-5] for the patch.
  • Fixed bug [#1463]: Squiz.Functions.FunctionDuplicateArgument: prevent an "Undefined array key" PHP warning when the sniff encounters a function declaration without parentheses (parse error / live coding).
    • Thanks to [Rodrigo Primo][@rodrigoprimo] for the patch.

php-pear-PHP-CodeSniffer-4.0.4-1.fc43

17 hours 11 minutes ago
FEDORA-2026-fdc77dd5f5 Packages in this update:
  • php-pear-PHP-CodeSniffer-4.0.4-1.fc43
Update description: Version 4.0.4 - 2026-08-06

This is a security release and all users are advised to update their install(s) as soon as possible. The security issue only affects users of the Gitblame, Hgblame or Svnblame report(s).

Added
  • Tokenizer support for the PHP 8.5 (void) cast. [#1325] The T_VOID_CAST token has been added to the Tokens::CAST_TOKENS array.
  • suggest section to the composer.json file to inform users about the recommended iconv and pcntl PHP extensions. [#1388]
    • Thanks to [Rodrigo Primo][@rodrigoprimo] for the patch.
Changed
  • Clarified that libxml is a required PHP extension. [#1409]
  • Squiz.Scope.StaticThisUsage: the sniff will now also search for the use of $this in static closures. [#1377]
  • The Generic.PHP.LowerCaseKeyword, Generic.WhiteSpace.LanguageConstructSpacing and Squiz.Functions.FunctionDeclarationArgumentSpacing sniffs no longer embed UTF-8 middot characters for spaces in error messages. [#1379], [#1389] Fixes [Squiz/#2652][sq-2652].
    • Thanks to [Rodrigo Primo][@rodrigoprimo] for the patches.
  • PSR2.ControlStructures.SwitchDeclaration: the error message for the use of colon + curly braces (WrongOpener*) has been made more informative. [#1358]. Fixes [#1322].
    • Thanks to [Sule-Balogun Olanrewaju][@bigdevlarry] for the patch.
  • The error messages for the following sniffs have been improved by exposing more data placeholders:
    • PEAR.Functions.FunctionDeclaration [#1445]
      • The CloseBracketLine error message now exposes 1 data value (previously 0).
      • The EmptyLine error message now exposes 1 data value (previously 0).
      • The Indent error message now exposes 3 data values (previously 2).
      • These changes also affect the same error codes for the PSR12.Classes.AnonClassDeclaration and Squiz.Functions.MultiLineFunctionDeclaration sniffs.
    • PSR2.Classes.ClassDeclaration [#1446]
      • The ExtendsLine and ImplementsLine error messages now expose 3 data values (previously 1).
      • The SpaceBeforeExtends and SpaceBeforeImplements error messages now expose 2 data values (previously 1).
      • These changes also affect the same error codes for the PSR12.Classes.AnonClassDeclaration and Squiz.Classes.ClassDeclaration sniffs.
    • PSR2.ControlStructures.SwitchDeclaration [#1447]
      • The defaultNotLower and caseNotLower error messages now expose 3 data values (previously 2).
      • The SpaceBeforeColonDEFAULT and SpaceBeforeColonCASE error messages now expose 1 data value (previously 0).
      • The BodyOnNextLineDEFAULT and BodyOnNextLineCASE error messages now expose 1 data value (previously 0).
      • The WrongOpenerdefault and WrongOpenercase error messages now expose 1 data value (previously 0).
    • Squiz.ControlStructures.SwitchDeclaration [#1449]
      • The CaseNotLower and DefaultNotLower error messages now expose 3 data values (previously 2).
      • The CaseIndent and DefaultIndent error messages now expose 2 data values (previously 0).
      • The SpaceBeforeColonCase and SpaceBeforeColonDefault error messages now expose 1 data value (previously 0).
      • The BreakIndent error message now exposes 1 data value (previously 0).
      • The SpacingAfterCase and SpacingAfterDefault error messages now expose 1 data value (previously 0).
    • Squiz.Functions.FunctionDeclarationArgumentSpacing [#1452]
      • The SpaceBeforeEquals error message now exposes 3 data values (previously 2).
      • The SpaceAfterEquals error message now exposes 3 data values (previously 2).
    • Squiz.Functions.MultiLineFunctionDeclaration [#1453]
      • The FirstParamSpacing and UseFirstParamSpacing error messages now expose 1 data value (previously 0).
      • The OneParamPerLine and UseOneParamPerLine error messages now expose 1 data value (previously 0).
      • These changes also affect the same error codes for the PSR12.Classes.AnonClassDeclaration sniff.
    • If you have customised the error messages of these sniffs, please review your ruleset after upgrading.
    • Thanks to [Zhang WenTao][@ntdiary] for these patches.
  • The following sniff(s) have received efficiency improvements:
    • PSR2.Classes.PropertyDeclaration
    • Thanks to [Jonathan Champ][@jrchamp] for the patch.
  • The test suite is now more contributor friendly for contributors on MacOS. [#1437]
    • Thanks to [Sergei Morozov][@morozov] for the patch.
  • Various housekeeping, including improvements to the tests and documentation.
    • Thanks to [Dan Wallis][@fredden], [Rodrigo Primo][@rodrigoprimo], [Sergei Morozov][@morozov] and [Juliette Reinders Folmer][@jrfnl] for their contributions.
Fixed
  • SECURITY FIX: Running PHP_CodeSniffer over untrusted files, for example, in a CI pipeline that scans pull requests, or on a developer machine reviewing third-party code, could result in attacker-controlled shell commands being executed when the Gitblame, Hgblame or Svnblame report(s) would process a file whose name contains shell metacharacters. [#1473]
    • Users using the default Full report, or any of the other non-*blame reports, are not affected.
    • For more details, see the [security advisory][sec-1].
    • Thanks go to [Faze-up][@Faze-up] and [Volker Dusch][@edorian] for responsibly disclosing the vulnerability.
    • Additionally, thanks go to [Volker Dusch][@edorian], [Rodrigo Primo][@rodrigoprimo], [Dan Wallis][@fredden] and [Juliette Reinders Folmer][@jrfnl] for creating and testing the fix.
  • Fixed bug [#1320]: Generic.Strings.UnnecessaryHeredoc: the fixer could incidentally change tab indentation to space indentation in select lines in the heredoc body.
  • Fixed bug [#1354]: PSR12.Functions.ReturnTypeDeclaration: prevent an "Undefined array key" warning if the code under scan contains a parse error.
    • Thanks to [Dan Wallis][@fredden] for the patch.
  • Fixed bug [#1357]: Squiz.Scope.StaticThisUsage: false positive for usage of $this in non-static closures nested in OO methods.
  • Fixed bug [#1368]: PEAR.Functions.FunctionDeclaration: the indentation for subsequent lines in multi-line block comments within a multi-line function signature, would be incorrectly determined, leading to false positives and resulting in a fixer conflict when running phpcbf.
    • This also fixes, by extension, the same issue in the Squiz.Functions.MultiLineFunctionDeclaration sniff.
  • Fixed bug [#1418]: Tokenizer/PHP: tokenization of an inline else colon after an inline comment could fail and/or throw a "Trying to access array offset on null" warning.
    • Thanks to [Lazizbek Ergashev][@lazerg] for the patch.
  • Fixed bug [#1435]: Generic.Formatting.MultipleStatementAlignment would get into a fixer conflict for multiple assignments within a single statement spanning multiple lines.
    • Same as when the statement would be single-line, alignment of subsequent assignment operators within the same multi-line statement will now be ignored.
    • Thanks to [Sergei Morozov][@morozov] for the patch.
  • Fixed bug [#1451]: Tokenizer/PHP: prevent an "Undefined array key" warning during live coding when a file ends on the name in a constant declaration.
    • Thanks to [Lazizbek Ergashev][@lazerg] and [Sai Asish Y][@SAY-5] for the patch.
  • Fixed bug [#1463]: Squiz.Functions.FunctionDuplicateArgument: prevent an "Undefined array key" PHP warning when the sniff encounters a function declaration without parentheses (parse error / live coding).
    • Thanks to [Rodrigo Primo][@rodrigoprimo] for the patch.