Debian Package Tracker
Register | Log in
Subscribe

docker-compose

Define and run multi-container applications with Docker (program)

Choose email to subscribe with

general
  • source: docker-compose (main)
  • version: 2.32.4-3
  • maintainer: Debian Go Packaging Team (DMD)
  • uploaders: Reinhard Tartler [DMD] – Nicolas Peugnet [DMD]
  • arch: any
  • std-ver: 4.7.2
  • VCS: Git (Browse, QA)
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • o-o-stable: 1.25.0-1
  • oldstable: 1.29.2-3
  • stable: 2.26.1-4
  • testing: 2.32.4-3
  • unstable: 2.32.4-3
versioned links
  • 1.25.0-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1.29.2-3: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 2.26.1-4: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 2.32.4-3: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • docker-compose (1 bugs: 0, 1, 0, 0)
action needed
A new upstream version is available: 2.40.3 high
A new upstream version 2.40.3 is available, you should consider packaging it.
Created: 2025-02-26 Last update: 2025-11-04 10:30
1 security issue in trixie high

There is 1 open security issue in trixie.

1 important issue:
  • CVE-2025-62725: Docker Compose trusts the path information embedded in remote OCI compose artifacts. When a layer includes the annotations com.docker.compose.extends or com.docker.compose.envfile, Compose joins the attacker‑supplied value from com.docker.compose.file/com.docker.compose.envfile with its local cache directory and writes the file there. This affects any platform or workflow that resolves remote OCI compose artifacts, Docker Desktop, standalone Compose binaries on Linux, CI/CD runners, cloud dev environments is affected. An attacker can escape the cache directory and overwrite arbitrary files on the machine running docker compose, even if the user only runs read‑only commands such as docker compose config or docker compose ps. This issue is fixed in v2.40.2.
Created: 2025-10-28 Last update: 2025-11-04 04:01
1 security issue in sid high

There is 1 open security issue in sid.

1 important issue:
  • CVE-2025-62725: Docker Compose trusts the path information embedded in remote OCI compose artifacts. When a layer includes the annotations com.docker.compose.extends or com.docker.compose.envfile, Compose joins the attacker‑supplied value from com.docker.compose.file/com.docker.compose.envfile with its local cache directory and writes the file there. This affects any platform or workflow that resolves remote OCI compose artifacts, Docker Desktop, standalone Compose binaries on Linux, CI/CD runners, cloud dev environments is affected. An attacker can escape the cache directory and overwrite arbitrary files on the machine running docker compose, even if the user only runs read‑only commands such as docker compose config or docker compose ps. This issue is fixed in v2.40.2.
Created: 2025-10-28 Last update: 2025-11-04 04:01
1 security issue in forky high

There is 1 open security issue in forky.

1 important issue:
  • CVE-2025-62725: Docker Compose trusts the path information embedded in remote OCI compose artifacts. When a layer includes the annotations com.docker.compose.extends or com.docker.compose.envfile, Compose joins the attacker‑supplied value from com.docker.compose.file/com.docker.compose.envfile with its local cache directory and writes the file there. This affects any platform or workflow that resolves remote OCI compose artifacts, Docker Desktop, standalone Compose binaries on Linux, CI/CD runners, cloud dev environments is affected. An attacker can escape the cache directory and overwrite arbitrary files on the machine running docker compose, even if the user only runs read‑only commands such as docker compose config or docker compose ps. This issue is fixed in v2.40.2.
Created: 2025-10-28 Last update: 2025-11-04 04:01
1 security issue in bookworm high

There is 1 open security issue in bookworm.

1 important issue:
  • CVE-2025-62725: Docker Compose trusts the path information embedded in remote OCI compose artifacts. When a layer includes the annotations com.docker.compose.extends or com.docker.compose.envfile, Compose joins the attacker‑supplied value from com.docker.compose.file/com.docker.compose.envfile with its local cache directory and writes the file there. This affects any platform or workflow that resolves remote OCI compose artifacts, Docker Desktop, standalone Compose binaries on Linux, CI/CD runners, cloud dev environments is affected. An attacker can escape the cache directory and overwrite arbitrary files on the machine running docker compose, even if the user only runs read‑only commands such as docker compose config or docker compose ps. This issue is fixed in v2.40.2.
Created: 2025-10-28 Last update: 2025-11-04 04:01
debian/patches: 2 patches to forward upstream low

Among the 4 debian patches available in version 2.32.4-3 of the package, we noticed the following issues:

  • 2 patches where the metadata indicates that the patch has not yet been forwarded upstream. You should either forward the patch upstream or update the metadata to document its real status.
Created: 2024-07-12 Last update: 2025-10-26 21:18
news
[rss feed]
  • [2025-11-04] docker-compose 2.32.4-3 MIGRATED to testing (Debian testing watch)
  • [2025-10-26] Accepted docker-compose 2.32.4-3 (source) into unstable (Reinhard Tartler)
  • [2025-10-22] Accepted docker-compose 2.32.4-2 (source) into experimental (Nicolas Peugnet)
  • [2025-10-19] Accepted docker-compose 2.32.4-1 (source) into experimental (Nicolas Peugnet) (signed by: Reinhard Tartler)
  • [2025-03-17] docker-compose 2.26.1-4 MIGRATED to testing (Debian testing watch)
  • [2025-03-14] Accepted docker-compose 2.26.1-4 (source) into unstable (Nicolas Peugnet) (signed by: Andrew Shadura)
  • [2025-03-08] docker-compose 2.26.1-3 MIGRATED to testing (Debian testing watch)
  • [2025-02-26] Accepted docker-compose 2.26.1-3 (source) into unstable (Reinhard Tartler)
  • [2025-02-24] Accepted docker-compose 2.26.1-2 (source) into experimental (Reinhard Tartler)
  • [2025-02-23] Accepted docker-compose 2.26.1-1 (source) into experimental (Reinhard Tartler)
  • [2025-02-19] Accepted docker-compose 1.29.2-8 (source) into experimental (Andrej Shadura) (signed by: Andrew Shadura)
  • [2025-02-19] Accepted docker-compose 1.29.2-7 (source) into experimental (Andrej Shadura) (signed by: Andrew Shadura)
  • [2025-01-19] Accepted docker-compose 1.29.2-6.4 (source) into unstable (Colin Watson)
  • [2024-12-07] docker-compose REMOVED from testing (Debian testing watch)
  • [2024-08-14] docker-compose 1.29.2-6.3 MIGRATED to testing (Debian testing watch)
  • [2024-08-09] Accepted docker-compose 1.29.2-6.3 (source) into unstable (Faidon Liambotis)
  • [2024-07-20] docker-compose REMOVED from testing (Debian testing watch)
  • [2024-07-20] docker-compose REMOVED from testing (Debian testing watch)
  • [2024-07-19] Accepted docker-compose 1.29.2-6.2 (source) into unstable (Emmanuel Arias)
  • [2024-07-11] Accepted docker-compose 1.29.2-6.1 (source) into unstable (Emmanuel Arias)
  • [2023-08-17] docker-compose 1.29.2-6 MIGRATED to testing (Debian testing watch)
  • [2023-08-11] Accepted docker-compose 1.29.2-6 (source) into unstable (Andrej Shadura) (signed by: Andrew Shadura)
  • [2023-08-10] Accepted docker-compose 1.29.2-5 (all source) into unstable (Debian FTP Masters) (signed by: Andrew Shadura)
  • [2023-02-27] docker-compose 1.29.2-3 MIGRATED to testing (Debian testing watch)
  • [2023-02-27] docker-compose 1.29.2-3 MIGRATED to testing (Debian testing watch)
  • [2023-02-16] Accepted docker-compose 1.29.2-3 (source) into unstable (Andrej Shadura) (signed by: Andrew Shadura)
  • [2022-08-27] docker-compose 1.29.2-2 MIGRATED to testing (Debian testing watch)
  • [2022-08-21] Accepted docker-compose 1.29.2-2 (source) into unstable (Andrej Shadura) (signed by: Andrew Shadura)
  • [2022-01-30] docker-compose 1.29.2-1 MIGRATED to testing (Debian testing watch)
  • [2022-01-25] Accepted docker-compose 1.29.2-1 (source) into unstable (Andrej Shadura) (signed by: Andrew Shadura)
  • 1
  • 2
bugs [bug history graph]
  • all: 2
  • RC: 0
  • I&N: 2
  • M&W: 0
  • F&P: 0
  • patch: 0
links
  • homepage
  • lintian
  • buildd: logs, reproducibility, cross
  • popcon
  • browse source code
  • edit tags
  • other distros
  • security tracker
  • screenshots
  • debian patches
  • debci

Debian Package Tracker — Copyright 2013-2025 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing