Debian Package Tracker
Register | Log in
Subscribe

guava-libraries

Choose email to subscribe with

general
  • source: guava-libraries (main)
  • version: 32.0.1-1
  • maintainer: Debian Java Maintainers (archive) (DMD)
  • uploaders: James Page [DMD] – Emmanuel Bourg [DMD]
  • arch: all
  • std-ver: 4.6.2
  • VCS: Git (Browse, QA)
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • o-o-stable: 19.0-1
  • oldstable: 29.0-6
  • stable: 31.1-1
  • testing: 32.0.1-1
  • unstable: 32.0.1-1
versioned links
  • 19.0-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 29.0-6: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 31.1-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 32.0.1-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • libguava-java
  • libguava-testlib-java
action needed
A new upstream version is available: 33.4.8 high
A new upstream version 33.4.8 is available, you should consider packaging it.
Created: 2023-07-03 Last update: 2025-05-11 23:01
debian/patches: 1 patch to forward upstream low

Among the 17 debian patches available in version 32.0.1-1 of the package, we noticed the following issues:

  • 1 patch where the metadata indicates that the patch has not yet been forwarded upstream. You should either forward the patch upstream or update the metadata to document its real status.
Created: 2023-02-26 Last update: 2023-06-25 08:36
Standards version of the package is outdated. wishlist
The package should be updated to follow the last version of Debian Policy (Standards-Version 4.7.2 instead of 4.6.2).
Created: 2024-04-07 Last update: 2025-02-27 13:25
No known security issue in bookworm wishlist

There are 2 open security issues in bookworm.

2 ignored issues:
  • CVE-2020-8908: A temp directory creation vulnerability exists in all versions of Guava, allowing an attacker with access to the machine to potentially access data in a temporary directory created by the Guava API com.google.common.io.Files.createTempDir(). By default, on unix-like systems, the created directory is world-readable (readable by an attacker with access to the system). The method in question has been marked @Deprecated in versions 30.0 and later and should not be used. For Android developers, we recommend choosing a temporary directory API provided by Android, such as context.getCacheDir(). For other Java developers, we recommend migrating to the Java 7 API java.nio.file.Files.createTempDirectory() which explicitly configures permissions of 700, or configuring the Java runtime's java.io.tmpdir system property to point to a location whose permissions are appropriately configured.
  • CVE-2023-2976: Use of Java's default temporary directory for file creation in `FileBackedOutputStream` in Google Guava versions 1.0 to 31.1 on Unix systems and Android Ice Cream Sandwich allows other users and apps on the machine with access to the default Java temporary directory to be able to access the files created by the class. Even though the security vulnerability is fixed in version 32.0.0, we recommend using version 32.0.1 as version 32.0.0 breaks some functionality under Windows.
Created: 2023-06-22 Last update: 2025-02-27 05:02
news
[rss feed]
  • [2023-06-30] guava-libraries 32.0.1-1 MIGRATED to testing (Debian testing watch)
  • [2023-06-24] Accepted guava-libraries 32.0.1-1 (source) into unstable (tony mancill)
  • [2022-12-20] guava-libraries 31.1-1 MIGRATED to testing (Debian testing watch)
  • [2022-12-12] Accepted guava-libraries 31.1-1 (source) into unstable (Emmanuel Bourg)
  • [2021-02-22] Accepted guava-libraries 29.0-6~bpo10+1 (source all) into buster-backports, buster-backports (Debian FTP Masters) (signed by: Sudip Mukherjee)
  • [2020-10-03] guava-libraries 29.0-6 MIGRATED to testing (Debian testing watch)
  • [2020-09-27] Accepted guava-libraries 29.0-6 (source) into unstable (Sudip Mukherjee)
  • [2020-06-12] guava-libraries 29.0-5 MIGRATED to testing (Debian testing watch)
  • [2020-06-06] Accepted guava-libraries 29.0-5 (source) into unstable (Emmanuel Bourg)
  • [2020-05-28] guava-libraries 29.0-4 MIGRATED to testing (Debian testing watch)
  • [2020-05-20] Accepted guava-libraries 29.0-4 (source) into unstable (Emmanuel Bourg)
  • [2020-05-19] Accepted guava-libraries 29.0-3 (source) into unstable (Emmanuel Bourg)
  • [2020-05-11] Accepted guava-libraries 29.0-2 (source all) into unstable, unstable (Debian FTP Masters) (signed by: Emmanuel Bourg)
  • [2020-05-10] Accepted guava-libraries 29.0-1 (source) into unstable (Emmanuel Bourg)
  • [2020-05-06] Accepted guava-libraries 29.0-1~exp1 (source) into experimental (Emmanuel Bourg)
  • [2020-05-02] Accepted guava-libraries 23.6.1-1~exp1 (source) into experimental (Emmanuel Bourg)
  • [2016-10-12] Accepted guava-libraries 19.0-1~bpo8+1 (source all) into jessie-backports (Emmanuel Bourg)
  • [2015-12-23] guava-libraries 19.0-1 MIGRATED to testing (Debian testing watch)
  • [2015-12-18] Accepted guava-libraries 19.0-1 (source all) into unstable (Emmanuel Bourg)
  • [2015-07-30] guava-libraries 18.0-4 MIGRATED to testing (Britney)
  • [2015-07-24] Accepted guava-libraries 18.0-4 (source all) into unstable (Emmanuel Bourg)
  • [2015-07-09] guava-libraries 18.0-3 MIGRATED to testing (Britney)
  • [2015-07-03] Accepted guava-libraries 18.0-3 (source all) into unstable (Emmanuel Bourg)
  • [2015-06-10] guava-libraries 18.0-2 MIGRATED to testing (Britney)
  • [2015-05-28] guava-libraries 18.0-1 MIGRATED to testing (Britney)
  • [2015-05-22] Accepted guava-libraries 18.0-1 (source all) into unstable (Emmanuel Bourg)
  • [2014-07-08] guava-libraries 17.0-1 MIGRATED to testing (Britney)
  • [2014-07-02] Accepted guava-libraries 17.0-1 (source all) (Emmanuel Bourg)
  • [2013-10-27] guava-libraries 15.0-2 MIGRATED to testing (Debian testing watch)
  • [2013-10-16] Accepted guava-libraries 15.0-2 (source all) (Emmanuel Bourg)
  • 1
  • 2
bugs [bug history graph]
  • all: 1
  • RC: 0
  • I&N: 1
  • M&W: 0
  • F&P: 0
  • patch: 0
links
  • homepage
  • lintian
  • buildd: logs, reproducibility
  • popcon
  • browse source code
  • edit tags
  • other distros
  • security tracker
  • debian patches
ubuntu Ubuntu logo [Information about Ubuntu for Debian Developers]
  • version: 32.0.1-1

Debian Package Tracker — Copyright 2013-2025 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing