|
|
Log in / Subscribe / Register

Fedora alert FEDORA-2026-d0535bed52 (apache-ivy)

From:  updates--- via package-announce <package-announce@lists.fedoraproject.org>
To:  package-announce@lists.fedoraproject.org
Subject:  [SECURITY] Fedora 43 Update: apache-ivy-2.6.0-2.fc43
Date:  Mon, 31 Aug 2026 17:04:45 +0000
Message-ID:  <20260831170445.61A4F187D2A1@bastion01.rdu3.fedoraproject.org>
Archive-link:  Article

-------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-d0535bed52 2026-08-31 16:58:22.985364+00:00 -------------------------------------------------------------------------------- Name : apache-ivy Product : Fedora 43 Version : 2.6.0 Release : 2.fc43 URL : https://ant.apache.org/ivy Summary : Java-based dependency manager Description : Apache Ivy is a tool for managing (recording, tracking, resolving and reporting) project dependencies. It is designed as process agnostic and is not tied to any methodology or structure. while available as a standalone tool, Apache Ivy works particularly well with Apache Ant providing a number of powerful Ant tasks ranging from dependency resolution to dependency reporting and publication. -------------------------------------------------------------------------------- Update Information: IMPROVEMENT: ivy:retrieve and the 'post resolve tasks' now support the override child element. (IVY-1664) IMPROVEMENT: ivy:makepom will now add override elements of the ivy.xml to the dependencyManagement section of the generated pom. (IVY-1663) (Thanks to Eric Milles) IMPROVEMENT: ivy:deliver and ivy:publish now writes inherited dependencies first to preserve resolve order (IVY-1656) (Thanks to Eric Milles) IMPROVEMENT: ModuleRevisionId.encodeToString now returns a deterministic string that doesn’t rely on a implmentation of HashMap (Thanks to Arnout Engelen) FIX: improved Maven dependencyManagement matching for dependencies with a non- default type or classifier (IVY-1654) (Thanks to Mark Kittisopikul) FIX: the ivy:retrieve task failed when the retrieve pattern contained some text in parentheses before the first token, for instance: /jobs/lib (JDK 17)/[artifact].[ext] (IVY-1660) FIX: when the ivy:deliver task is configured to replace dynamic revisions, it now replaces these revisions to the resolved revision before any conflict resolution was done, which was the original behavior before Ivy 2.3.0. This way, the delivered ivy.xml can be used to have reproducible dependency resolution, especially when multiple configurations are used. It also fixes issues where the dynamic revisions were replaced by versions from other configurations. (IVY-1485, IVY-1661) FIX: the ivy:deliver task didn’t replace dynamic revision from inherited dependencies. (IVY-1410) (Thanks to Eric Milles) FIX: the ivy:install task didn’t take the from resolver into account when resolving Maven parent modules or source/javadoc artifacts. (Thanks to Colin Chambers) FIX: the ivy:checkdepsupdate task could suggest a lesser version as update. (IVY-1665) (Thanks to Eric Milles) FIX: the ivy:makepom task no longer adds a dependency to the section. (IVY-1667) (Thanks to Eric Milles) FIX: the ivy:deliver task didn’t include XML namespaces from a parent ivy module when merging the descriptors. (IVY-1658) (Thanks to Eric Milles) FIX: the ivy:checkdepsupdate task no longer shows evicted versions. (IVY-1662) (Thanks to Eric Milles) -------------------------------------------------------------------------------- ChangeLog: * Thu Jul 23 2026 Filipe Rosset <rosset.filipe@gmail.com> - 2.6.0-2 - opt-in to packit for rawhide * Thu Jul 23 2026 Filipe Rosset <rosset.filipe@gmail.com> - 2.6.0-1 - update to apache-ivy-2.6.0 fixes rhbz#2500944 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2520139 - CVE-2026-26032 apache-ivy: Apache Ivy: File overwrite vulnerability via malicious module coordinates [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2520139 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-d0535bed52' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgr... All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys --------------------------------------------------------------------------------


Attachment: None (type=text/plain)

-- _______________________________________________ package-announce mailing list -- package-announce@lists.fedoraproject.org To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-cond... List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/package-ann... Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new


to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds