Bug 2366216 - DokuWiki 2025-05-14b "Librarian" is available
Summary: DokuWiki 2025-05-14b "Librarian" is available
Keywords:
Status: CLOSED ERRATA
Alias: None
Product: Fedora
Classification: Fedora
Component: dokuwiki
Version: rawhide
Hardware: Unspecified
OS: Unspecified
unspecified
unspecified
Target Milestone: ---
Assignee: Artur Frenszek-Iwicki
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard: AcceptedFreezeException
Depends On: 2366627
Blocks: F43FinalFreezeException
TreeView+ depends on / blocked
 
Reported: 2025-05-14 10:16 UTC by Artur Frenszek-Iwicki
Modified: 2025-10-23 23:53 UTC (History)
2 users (show)

Fixed In Version: dokuwiki-20250514b-1.fc43
Clone Of:
Environment:
Last Closed: 2025-10-23 23:53:44 UTC
Type: Bug
Embargoed:


Attachments (Terms of Use)

Description Artur Frenszek-Iwicki 2025-05-14 10:16:09 UTC
DokuWiki 2025-05-14 "Librarian" is now available.
https://github.com/dokuwiki/dokuwiki/releases/tag/release-2025-05-14

The version currently in Rawhide is DokuWiki 2024-02-06b "Kaos" (dokuwiki-20240206b-1.fc43).

Comment 1 Artur Frenszek-Iwicki 2025-05-26 14:10:59 UTC
DokuWiki 2025-05-14a "Librarian" is now available.
https://github.com/dokuwiki/dokuwiki/releases/tag/release-2025-05-14a

Comment 2 Artur Frenszek-Iwicki 2025-10-07 20:34:09 UTC
Dokuwiki 2025-05-14b "Librarian" has been released on 2025-09-09.
https://github.com/dokuwiki/dokuwiki/releases/tag/release-2025-05-14b

Comment 3 Fedora Update System 2025-10-14 17:19:12 UTC
FEDORA-2025-e6ce056923 (dokuwiki-20250514b-1.fc43 and php-php81_bc-strftime-0.7.6-1.fc43) has been submitted as an update to Fedora 43.
https://bodhi.fedoraproject.org/updates/FEDORA-2025-e6ce056923

Comment 4 Fedora Update System 2025-10-14 17:20:05 UTC
FEDORA-2025-5c621a5a8a (dokuwiki-20250514b-1.fc44 and php-php81_bc-strftime-0.7.6-1.fc44) has been submitted as an update to Fedora 44.
https://bodhi.fedoraproject.org/updates/FEDORA-2025-5c621a5a8a

Comment 5 Fedora Update System 2025-10-14 17:24:38 UTC
FEDORA-2025-5c621a5a8a (dokuwiki-20250514b-1.fc44 and php-php81_bc-strftime-0.7.6-1.fc44) has been pushed to the Fedora 44 stable repository.
If problem still persists, please make note of it in this bug report.

Comment 6 Fedora Update System 2025-10-15 01:17:39 UTC
FEDORA-2025-e6ce056923 has been pushed to the Fedora 43 testing repository.
Soon you'll be able to install the update with the following command:
`sudo dnf upgrade --enablerepo=updates-testing --refresh --advisory=FEDORA-2025-e6ce056923`
You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2025-e6ce056923

See also https://fedoraproject.org/wiki/QA:Updates_Testing for more information on how to test updates.

Comment 7 Fedora Blocker Bugs Application 2025-10-18 08:49:16 UTC
Proposed as a Freeze Exception for 43-final by Fedora user suve using the blocker tracking app because:

 DokuWiki has recently had an XSS (cross-site scripting) vulnerability found in it [0]. While the original vulnerability report mentions only version 2025-05-14a as affected [1], it's possible older versions are vulnerable, as well.

The version currently in Fedora 43 stable is Dokuwiki 2024-02-06b. Keeping this version and providing 2025-05-14b as a zero-day update has two downsides:
1. Shipping a known potentially-vulnerable package
2. Violating the "avoid major version upgrades" point of the Updates Policy

[0] https://github.com/advisories/GHSA-pp4p-g4w7-gvp7
[1] https://github.com/MarioTesoro/vulnerability-research/tree/main/CVE-2025-61224

Comment 8 Lukas Ruzicka 2025-10-20 19:02:39 UTC
Discussed at the blocker review meeting on 20th Oct. 2025

AGREED AcceptedFinalFreezeException

This is accepted based on the justification in the bug, to get the vulnerability addressed ASAP and avoid a post-release version bump.

https://meetbot.fedoraproject.org/blocker-review_matrix_fedoraproject-org/2025-10-20/f43-blocker-review.2025-10-20-16.02.html

Comment 9 Fedora Update System 2025-10-23 23:53:44 UTC
FEDORA-2025-e6ce056923 (dokuwiki-20250514b-1.fc43 and php-php81_bc-strftime-0.7.6-1.fc43) has been pushed to the Fedora 43 stable repository.
If problem still persists, please make note of it in this bug report.


Note You need to log in before you can comment on or make changes to this bug.