Fedora Account System
Red Hat Associate
Red Hat Customer
Releases retrieved: 1.17.4 Upstream release that is considered latest: 1.17.4 Current version/release in rawhide: 1.17.3-2.fc45 URL: https://www.flatpak.org Please consult the package updates policy before you issue an update to a stable branch: https://docs.fedoraproject.org/en-US/fesco/Updates_Policy/ More information about the service that created this bug can be found at: https://docs.fedoraproject.org/en-US/package-maintainers/Upstream_Release_Monitoring Please keep in mind that with any upstream change, there may also be packaging changes that need to be made. Specifically, please remember that it is your responsibility to review the new version to ensure that the licensing is still correct and that no non-free or legally problematic items have been added upstream. Based on the information from Anitya: https://release-monitoring.org/project/6377/ To change the monitoring settings for the project, please visit: https://src.fedoraproject.org/rpms/flatpak
Created attachment 2136291 [details] Update to 1.17.4 (#2456353)
the-new-hotness/release-monitoring.org's scratch build of flatpak-1.17.4-1.fc43.src.rpm for rawhide failed http://koji.fedoraproject.org/koji/taskinfo?taskID=144176258
FEDORA-2026-17f6840cea (flatpak-1.17.4-1.fc44) has been submitted as an update to Fedora 44. https://bodhi.fedoraproject.org/updates/FEDORA-2026-17f6840cea
FEDORA-2026-17f6840cea has been pushed to the Fedora 44 testing repository. Soon you'll be able to install the update with the following command: `sudo dnf upgrade --enablerepo=updates-testing --refresh --advisory=FEDORA-2026-17f6840cea` You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2026-17f6840cea See also https://fedoraproject.org/wiki/QA:Updates_Testing for more information on how to test updates.
The 1.17.4 release brings very important CVE fixes. See: https://github.com/flatpak/flatpak/releases/tag/1.17.4 However, it also causes regressions for apps such as Steam or some web browsers. These regressions have been fixed in the subsequent 1.17.5 and 1.17.6 releases: https://github.com/flatpak/flatpak/releases/tag/1.17.5 https://github.com/flatpak/flatpak/releases/tag/1.17.6
Proposed as a Blocker and Freeze Exception for 44-final by Fedora user asciiwolf using the blocker tracking app because: The latest 1.17.6 Flatpak release brings important CVE fixes and other fixes.
+4 in https://pagure.io/fedora-qa/blocker-review/issue/2101 , marking accepted FE.
F44 build: https://bodhi.fedoraproject.org/updates/FEDORA-2026-24eedfaa6c Rawhide build: https://bodhi.fedoraproject.org/updates/FEDORA-2026-fcdc11c1a9
FEDORA-2026-24eedfaa6c (flatpak-1.17.6-1.fc44) has been submitted as an update to Fedora 44. https://bodhi.fedoraproject.org/updates/FEDORA-2026-24eedfaa6c
The F44 build still hasn't been unfreezed: https://bodhi.fedoraproject.org/updates/FEDORA-2026-24eedfaa6c Could someone please do it? Thanks!
AGREED RejectedFinalBlocker Discussed at the 2026-04-13 (blocker / freeze exception) review meeting: The CVE criterion says CVEs rated Important or above on RH's scale can be blockers, and the two cited here are both Moderate. Note this is already accepted FE and will be pushed stable soon anyhow. https://meetbot-raw.fedoraproject.org//blocker-review_matrix_fedoraproject-org/2026-04-13/f44-blocker-review.2026-04-13-16.00.log.txt
FEDORA-2026-24eedfaa6c (flatpak-1.17.6-1.fc44) has been pushed to the Fedora 44 stable repository. If problem still persists, please make note of it in this bug report.