Bug 2339830 - clamav-1.5.2 is available
Summary: clamav-1.5.2 is available
Keywords:
Status: ASSIGNED
Alias: None
Product: Fedora
Classification: Fedora
Component: clamav
Version: rawhide
Hardware: Unspecified
OS: Unspecified
unspecified
unspecified
Target Milestone: ---
Assignee: Gwyn Ciesla
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard:
Depends On: 2434105 2434118 2434135 2336069
Blocks:
TreeView+ depends on / blocked
 
Reported: 2025-01-22 18:22 UTC by Upstream Release Monitoring
Modified: 2026-04-07 16:20 UTC (History)
15 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Type: ---
Embargoed:


Attachments (Terms of Use)
Update to 1.4.2 (#2339830) (1.03 KB, patch)
2025-01-22 18:22 UTC, Upstream Release Monitoring
no flags Details | Diff
Update to 1.5.0-beta (#2339830) (1.04 KB, patch)
2025-03-31 20:19 UTC, Upstream Release Monitoring
no flags Details | Diff

Description Upstream Release Monitoring 2025-01-22 18:22:18 UTC
Releases retrieved: 1.0.8, 1.4.2
Upstream release that is considered latest: 1.4.2
Current version/release in rawhide: 1.4.1-1.fc42
URL: https://www.clamav.net

Please consult the package updates policy before you issue an update to a stable branch: https://docs.fedoraproject.org/en-US/fesco/Updates_Policy/


More information about the service that created this bug can be found at: https://docs.fedoraproject.org/en-US/package-maintainers/Upstream_Release_Monitoring


Please keep in mind that with any upstream change, there may also be packaging changes that need to be made. Specifically, please remember that it is your responsibility to review the new version to ensure that the licensing is still correct and that no non-free or legally problematic items have been added upstream.


Based on the information from Anitya: https://release-monitoring.org/project/291/


To change the monitoring settings for the project, please visit:
https://src.fedoraproject.org/rpms/clamav

Comment 1 Upstream Release Monitoring 2025-01-22 18:22:26 UTC
Scratch build failed. Details below:

BuilderException: Build failed:
Command '['rpmbuild', '-D', '_sourcedir .', '-D', '_topdir .', '-bs', '/var/tmp/thn-z159q8zf/clamav.spec']' returned non-zero exit status 1.

StdOut:
setting SOURCE_DATE_EPOCH=1737504000
error: Bad file: ./clamav-1.4.2-norar.tar.xz: No such file or directory

RPM build errors:
    Bad file: ./clamav-1.4.2-norar.tar.xz: No such file or directory


Traceback:
  File "/usr/local/lib/python3.12/site-packages/hotness/use_cases/package_scratch_build_use_case.py", line 56, in build
    result = self.builder.build(request.package, request.opts)
             ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
  File "/usr/local/lib/python3.12/site-packages/hotness/builders/koji.py", line 229, in build
    raise BuilderException(

If you think this issue is caused by some bug in the-new-hotness, please report it on the-new-hotness issue tracker: https://github.com/fedora-infra/the-new-hotness/issues

Comment 2 Upstream Release Monitoring 2025-01-22 18:22:28 UTC
Created attachment 2068086 [details]
Update to 1.4.2 (#2339830)

Comment 3 Upstream Release Monitoring 2025-03-31 20:19:02 UTC
Releases retrieved: 1.5.0-beta
Upstream release that is considered latest: 1.5.0-beta
Current version/release in rawhide: 1.4.2-2.fc43
URL: https://www.clamav.net

Please consult the package updates policy before you issue an update to a stable branch: https://docs.fedoraproject.org/en-US/fesco/Updates_Policy/


More information about the service that created this bug can be found at: https://docs.fedoraproject.org/en-US/package-maintainers/Upstream_Release_Monitoring


Please keep in mind that with any upstream change, there may also be packaging changes that need to be made. Specifically, please remember that it is your responsibility to review the new version to ensure that the licensing is still correct and that no non-free or legally problematic items have been added upstream.


Based on the information from Anitya: https://release-monitoring.org/project/291/


To change the monitoring settings for the project, please visit:
https://src.fedoraproject.org/rpms/clamav

Comment 4 Upstream Release Monitoring 2025-03-31 20:19:09 UTC
Scratch build failed. Details below:

BuilderException: Build failed:
Command '['rpmbuild', '-D', '_sourcedir .', '-D', '_topdir .', '-bs', '/var/tmp/thn-ak_318l1/clamav.spec']' returned non-zero exit status 1.

StdOut:
setting SOURCE_DATE_EPOCH=1743379200
error: Bad file: ./clamav-1.5.0-norar.tar.xz: No such file or directory

RPM build errors:
    Bad file: ./clamav-1.5.0-norar.tar.xz: No such file or directory


Traceback:
  File "/usr/local/lib/python3.12/site-packages/hotness/use_cases/package_scratch_build_use_case.py", line 56, in build
    result = self.builder.build(request.package, request.opts)
             ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
  File "/usr/local/lib/python3.12/site-packages/hotness/builders/koji.py", line 229, in build
    raise BuilderException(

If you think this issue is caused by some bug in the-new-hotness, please report it on the-new-hotness issue tracker: https://github.com/fedora-infra/the-new-hotness/issues

Comment 5 Upstream Release Monitoring 2025-03-31 20:19:11 UTC
Created attachment 2082853 [details]
Update to 1.5.0-beta (#2339830)

Comment 6 Orion Poplawski 2025-04-01 03:39:38 UTC
I've started poking at this and have some initial work here: https://src.fedoraproject.org/fork/orion/rpms/clamav/tree/1.5

TODO:
* Figure out how to deal with the clam-sigutil / clamav-signature-util library.  Posted a question to clamav-devel about it - https://lists.clamav.net/pipermail/clamav-devel/2025-April/000790.html 
* Make sure that the default_confs patch has been updated properly

Comment 7 Fedora Admin user for bugzilla script actions 2025-05-10 02:37:17 UTC
This package has changed maintainer in Fedora. Reassigning to the new maintainer of this component.

Comment 8 Fedora Admin user for bugzilla script actions 2025-05-24 02:28:11 UTC
This package has changed maintainer in Fedora. Reassigning to the new maintainer of this component.

Comment 9 Upstream Release Monitoring 2025-10-07 14:17:58 UTC
Releases retrieved: 1.5.0
Upstream release that is considered latest: 1.5.0
Current version/release in rawhide: 1.4.3-2.fc43
URL: https://www.clamav.net

Please consult the package updates policy before you issue an update to a stable branch: https://docs.fedoraproject.org/en-US/fesco/Updates_Policy/


More information about the service that created this bug can be found at: https://docs.fedoraproject.org/en-US/package-maintainers/Upstream_Release_Monitoring


Please keep in mind that with any upstream change, there may also be packaging changes that need to be made. Specifically, please remember that it is your responsibility to review the new version to ensure that the licensing is still correct and that no non-free or legally problematic items have been added upstream.


Based on the information from Anitya: https://release-monitoring.org/project/291/


To change the monitoring settings for the project, please visit:
https://src.fedoraproject.org/rpms/clamav

Comment 10 Upstream Release Monitoring 2025-10-07 14:18:03 UTC
Scratch build failed. Details below:

FileNotFoundError: [Errno 2] No such file or directory: '/var/tmp/thn-130b3vil/https://src.fedoraproject.org/repo/pkgs'
Traceback:
  File "/usr/local/lib/python3.12/site-packages/hotness/use_cases/package_scratch_build_use_case.py", line 56, in build
    result = self.builder.build(request.package, request.opts)
             ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
  File "/usr/local/lib/python3.12/site-packages/hotness/builders/koji.py", line 206, in build
    output["message"] = self._compare_sources(old_sources, new_sources)
                        ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
  File "/usr/local/lib/python3.12/site-packages/hotness/builders/koji.py", line 373, in _compare_sources
    with open(file_path, "rb") as fd:
         ^^^^^^^^^^^^^^^^^^^^^

If you think this issue is caused by some bug in the-new-hotness, please report it on the-new-hotness issue tracker: https://github.com/fedora-infra/the-new-hotness/issues

Comment 11 Upstream Release Monitoring 2025-10-16 17:05:13 UTC
Releases retrieved: 1.5.1
Upstream release that is considered latest: 1.5.1
Current version/release in rawhide: 1.4.3-2.fc43
URL: https://www.clamav.net

Please consult the package updates policy before you issue an update to a stable branch: https://docs.fedoraproject.org/en-US/fesco/Updates_Policy/


More information about the service that created this bug can be found at: https://docs.fedoraproject.org/en-US/package-maintainers/Upstream_Release_Monitoring


Please keep in mind that with any upstream change, there may also be packaging changes that need to be made. Specifically, please remember that it is your responsibility to review the new version to ensure that the licensing is still correct and that no non-free or legally problematic items have been added upstream.


Based on the information from Anitya: https://release-monitoring.org/project/291/


To change the monitoring settings for the project, please visit:
https://src.fedoraproject.org/rpms/clamav

Comment 12 Upstream Release Monitoring 2025-10-16 17:05:19 UTC
Scratch build failed. Details below:

FileNotFoundError: [Errno 2] No such file or directory: '/var/tmp/thn-5tm_tpev/https://src.fedoraproject.org/repo/pkgs'
Traceback:
  File "/usr/local/lib/python3.12/site-packages/hotness/use_cases/package_scratch_build_use_case.py", line 56, in build
    result = self.builder.build(request.package, request.opts)
             ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
  File "/usr/local/lib/python3.12/site-packages/hotness/builders/koji.py", line 206, in build
    output["message"] = self._compare_sources(old_sources, new_sources)
                        ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
  File "/usr/local/lib/python3.12/site-packages/hotness/builders/koji.py", line 373, in _compare_sources
    with open(file_path, "rb") as fd:
         ^^^^^^^^^^^^^^^^^^^^^

If you think this issue is caused by some bug in the-new-hotness, please report it on the-new-hotness issue tracker: https://github.com/fedora-infra/the-new-hotness/issues

Comment 13 Drew Freiberger 2026-01-09 20:56:47 UTC
I would greatly appreciate a review of this clamav 1.5.z release for adoption in Fedora, and consideration in EPEL for RHEL9 and RHEL10.

My team uses clamav in a high compliance environment requiring FIPS compliant code.  When clamd v1.4.3 runs on a FIPS-or-die RHEL9 host, it crashes due to calls to md5sum libraries.  The clamav 1.5 release is now FIPS compatible and should be adopted into Fedora and EPEL for the export-sensitive userbase.

Comment 14 Gwyn Ciesla 2026-01-14 21:18:16 UTC
@(In reply to Orion Poplawski from comment #6)
> I've started poking at this and have some initial work here:
> https://src.fedoraproject.org/fork/orion/rpms/clamav/tree/1.5
> 
> TODO:
> * Figure out how to deal with the clam-sigutil / clamav-signature-util
> library.  Posted a question to clamav-devel about it -
> https://lists.clamav.net/pipermail/clamav-devel/2025-April/000790.html 
> * Make sure that the default_confs patch has been updated properly

Orion, have you made any progress here? If not, do you think I should loop in the rust SIG?

Comment 15 Gwyn Ciesla 2026-01-28 18:50:34 UTC
Filed all necessary bugs and dependencies for this update.

Comment 16 Upstream Release Monitoring 2026-03-04 20:47:33 UTC
Releases retrieved: 1.4.4, 1.5.2
Upstream release that is considered latest: 1.5.2
Current version/release in rawhide: 1.4.3-6.fc44
URL: https://www.clamav.net

Please consult the package updates policy before you issue an update to a stable branch: https://docs.fedoraproject.org/en-US/fesco/Updates_Policy/


More information about the service that created this bug can be found at: https://docs.fedoraproject.org/en-US/package-maintainers/Upstream_Release_Monitoring


Please keep in mind that with any upstream change, there may also be packaging changes that need to be made. Specifically, please remember that it is your responsibility to review the new version to ensure that the licensing is still correct and that no non-free or legally problematic items have been added upstream.


Based on the information from Anitya: https://release-monitoring.org/project/291/


To change the monitoring settings for the project, please visit:
https://src.fedoraproject.org/rpms/clamav

Comment 17 Upstream Release Monitoring 2026-03-04 20:47:38 UTC
Scratch build failed. Details below:

FileNotFoundError: [Errno 2] No such file or directory: '/var/tmp/thn-ebew5tyc/https://src.fedoraproject.org/repo/pkgs'
Traceback:
  File "/usr/local/lib/python3.12/site-packages/hotness/use_cases/package_scratch_build_use_case.py", line 56, in build
    result = self.builder.build(request.package, request.opts)
             ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
  File "/usr/local/lib/python3.12/site-packages/hotness/builders/koji.py", line 206, in build
    output["message"] = self._compare_sources(old_sources, new_sources)
                        ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
  File "/usr/local/lib/python3.12/site-packages/hotness/builders/koji.py", line 373, in _compare_sources
    with open(file_path, "rb") as fd:
         ^^^^^^^^^^^^^^^^^^^^^

If you think this issue is caused by some bug in the-new-hotness, please report it on the-new-hotness issue tracker: https://github.com/fedora-infra/the-new-hotness/issues

Comment 18 Audrey Yeena Toskin 2026-04-07 03:12:29 UTC
Any progress on this? Clam 1.5.x fixing compatibility with FIPS mode would unfortunately be helpful for me at work...

Comment 19 Gwyn Ciesla 2026-04-07 16:20:55 UTC
We're working on it. The bugs that this bug depends on represent new Rust packages that need to be reviewed and built before we can update to 1.5.x.


Note You need to log in before you can comment on or make changes to this bug.