Debian Package Tracker
Register | Log in
Subscribe

golang-github-jackc-pgx

PostgreSQL driver and toolkit for Golang

Choose email to subscribe with

general
  • source: golang-github-jackc-pgx (main)
  • version: 4.18.1-2
  • maintainer: Debian Go Packaging Team (DMD)
  • uploaders: Dmitry Smirnov [DMD] – Pirate Praveen [DMD]
  • arch: all
  • std-ver: 4.6.0
  • VCS: Git (Browse, QA)
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • oldstable: 3.6.2-2
  • stable: 4.15.0-4
  • testing: 4.18.1-2
  • unstable: 4.18.1-2
versioned links
  • 3.6.2-2: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 4.15.0-4: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 4.18.1-2: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • golang-github-jackc-pgx-v4-dev
action needed
Debci reports failed tests high
  • unstable: fail (log)
    The tests ran in 0:00:57
    Last run: 2020-01-23T16:53:31.000Z
    Previous status: unknown

Created: 2020-04-20 Last update: 2025-05-20 09:33
A new upstream version is available: 5.7.4 high
A new upstream version 5.7.4 is available, you should consider packaging it.
Created: 2022-04-17 Last update: 2025-05-20 08:31
version in VCS is newer than in repository, is it time to upload? normal
vcswatch reports that this package seems to have a new changelog entry (version 5.7.1-1, distribution UNRELEASED) and new commits in its VCS. You should consider whether it's time to make an upload.

Here are the relevant commit messages:
commit a73355cdaa20fd63f9c25d52ee82dd24710936c0
Author: Dr. Tobias Quathamer <toddy@debian.org>
Date:   Wed Apr 23 11:29:14 2025 +0200

    Switch gbp debian branch back to debian/sid

commit a9ccdef358030259cd9aa238585efcea242da0d2
Author: Dr. Tobias Quathamer <toddy@debian.org>
Date:   Wed Apr 23 11:28:19 2025 +0200

    Remove patches, have been applied upstream

commit f101e42b74067425950a528ae0d314fd146366d9
Merge: 8ca5db1 d42bba3
Author: Dr. Tobias Quathamer <toddy@debian.org>
Date:   Wed Apr 23 11:23:45 2025 +0200

    Merge branch 'debian/sid-soft-freeze' into debian/sid

commit 8ca5db1c886027006ce22336f3f5544df979872b
Author: tous <touss@protonmail.com>
Date:   Fri Nov 1 11:31:56 2024 -0300

    Drop unnecessary /v4 suffix in XS-Go-Import-Path

commit 17b786ab1274b5a5fd3d3daf3d4ec2eddd84a887
Author: tous <touss@protonmail.com>
Date:   Fri Nov 1 11:30:22 2024 -0300

    Update debian/changelog

commit 26f74bd3c8a8a564a95e6eb9317dcd40c47f60c2
Merge: 44d79f1 a1e52c4
Author: tous <touss@protonmail.com>
Date:   Wed Oct 23 11:55:44 2024 -0300

    Update upstream source from tag 'upstream/5.7.1'
    
    Update to upstream version '5.7.1'
    with Debian dir c440bc1b285fdd730a4a60867860c65db350a935

commit a1e52c47f0988c277bf01a0b6884e87a98bde9eb
Author: tous <touss@protonmail.com>
Date:   Wed Oct 23 11:55:42 2024 -0300

    New upstream version 5.7.1
Created: 2024-11-01 Last update: 2025-05-18 08:34
2 low-priority security issues in bookworm low

There are 2 open security issues in bookworm.

2 issues left for the package maintainer to handle:
  • CVE-2024-27289: (needs triaging) pgx is a PostgreSQL driver and toolkit for Go. Prior to version 4.18.2, SQL injection can occur when all of the following conditions are met: the non-default simple protocol is used; a placeholder for a numeric value must be immediately preceded by a minus; there must be a second placeholder for a string value after the first placeholder; both must be on the same line; and both parameter values must be user-controlled. The problem is resolved in v4.18.2. As a workaround, do not use the simple protocol or do not place a minus directly before a placeholder.
  • CVE-2024-27304: (needs triaging) pgx is a PostgreSQL driver and toolkit for Go. SQL injection can occur if an attacker can cause a single query or bind message to exceed 4 GB in size. An integer overflow in the calculated message size can cause the one large message to be sent as multiple messages under the attacker's control. The problem is resolved in v4.18.2 and v5.5.4. As a workaround, reject user input large enough to cause a single query or bind message to exceed 4 GB in size.

You can find information about how to handle these issues in the security team's documentation.

Created: 2024-03-07 Last update: 2025-05-03 05:32
debian/patches: 2 patches to forward upstream low

Among the 2 debian patches available in version 4.18.1-2 of the package, we noticed the following issues:

  • 2 patches where the metadata indicates that the patch has not yet been forwarded upstream. You should either forward the patch upstream or update the metadata to document its real status.
Created: 2025-04-23 Last update: 2025-04-23 21:03
Standards version of the package is outdated. wishlist
The package should be updated to follow the last version of Debian Policy (Standards-Version 4.7.2 instead of 4.6.0).
Created: 2022-05-11 Last update: 2025-04-23 19:01
news
[rss feed]
  • [2025-05-03] golang-github-jackc-pgx 4.18.1-2 MIGRATED to testing (Debian testing watch)
  • [2025-04-23] Accepted golang-github-jackc-pgx 4.18.1-2 (source) into unstable (Dr. Tobias Quathamer)
  • [2024-03-03] golang-github-jackc-pgx 4.18.1-1 MIGRATED to testing (Debian testing watch)
  • [2024-02-27] Accepted golang-github-jackc-pgx 4.18.1-1 (source) into unstable (Anthony Fok)
  • [2022-11-26] golang-github-jackc-pgx 4.15.0-4 MIGRATED to testing (Debian testing watch)
  • [2022-09-28] golang-github-jackc-pgx REMOVED from testing (Debian testing watch)
  • [2022-04-23] golang-github-jackc-pgx 4.15.0-4 MIGRATED to testing (Debian testing watch)
  • [2022-04-18] Accepted golang-github-jackc-pgx 4.15.0-4 (source) into unstable (Pirate Praveen) (signed by: Praveen Arimbrathodiyil)
  • [2022-04-17] Accepted golang-github-jackc-pgx 4.15.0-3 (source all) into unstable (Pirate Praveen) (signed by: Praveen Arimbrathodiyil)
  • [2022-04-17] Accepted golang-github-jackc-pgx 4.15.0-2 (source) into unstable (Pirate Praveen) (signed by: Praveen Arimbrathodiyil)
  • [2022-03-28] Accepted golang-github-jackc-pgx 4.15.0-1 (source all) into experimental, experimental (Debian FTP Masters) (signed by: Praveen Arimbrathodiyil)
  • [2020-08-09] golang-github-jackc-pgx 3.6.2-2 MIGRATED to testing (Debian testing watch)
  • [2020-08-03] Accepted golang-github-jackc-pgx 3.6.2-2 (source) into unstable (Stephen Gelman)
  • [2020-02-09] golang-github-jackc-pgx 3.6.2-1 MIGRATED to testing (Debian testing watch)
  • [2020-02-04] Accepted golang-github-jackc-pgx 3.6.2-1 (source) into unstable (Dmitry Smirnov)
  • [2020-01-15] Accepted golang-github-jackc-pgx 3.6.1-1 (source) into unstable (Dmitry Smirnov)
  • [2020-01-13] Accepted golang-github-jackc-pgx 3.6.0-1 (source all) into unstable, unstable (Dmitry Smirnov)
bugs [bug history graph]
  • all: 0
links
  • homepage
  • lintian
  • buildd: logs, reproducibility
  • popcon
  • browse source code
  • edit tags
  • other distros
  • security tracker
  • debian patches
  • debci
ubuntu Ubuntu logo [Information about Ubuntu for Debian Developers]
  • version: 4.18.1-2

Debian Package Tracker — Copyright 2013-2025 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing