Debian Package Tracker
Register | Log in
Subscribe

pdm

next generation Python package management tool

Choose email to subscribe with

general
  • source: pdm (main)
  • version: 2.20.1+ds1-2
  • maintainer: Debian Python Team (DMD)
  • uploaders: Boyuan Yang [DMD]
  • arch: all
  • std-ver: 4.7.0
  • VCS: Git (Browse, QA)
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • stable: 2.2.1+ds1-1
  • testing: 2.20.1+ds1-2
  • unstable: 2.20.1+ds1-2
versioned links
  • 2.2.1+ds1-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 2.20.1+ds1-2: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • python3-pdm
action needed
A new upstream version is available: 2.24.1 high
A new upstream version 2.24.1 is available, you should consider packaging it.
Created: 2024-11-27 Last update: 2025-05-19 19:31
lintian reports 2 warnings high
Lintian reports 2 warnings about this package. You should make the package lintian clean getting rid of them.
Created: 2022-09-23 Last update: 2024-11-09 08:31
Depends on packages which need a new maintainer normal
The packages that pdm depends on which need a new maintainer are:
  • python-first (#928536)
    • Build-Depends: python3-first
Created: 2022-07-10 Last update: 2025-05-20 00:30
version in VCS is newer than in repository, is it time to upload? normal
vcswatch reports that this package seems to have a new changelog entry (version 2.23.1-1, distribution UNRELEASED) and new commits in its VCS. You should consider whether it's time to make an upload.

Here are the relevant commit messages:
commit 0991462e1bdc4ded603da4e983701a04c9bd2ba7
Author: Alexandre Detiste <tchet@debian.org>
Date:   Sat May 17 16:56:52 2025 +0200

    drop build-dep on python3-tomli

commit cce40e66773d8d7c745fc1a487b67106ebc8273d
Author: eevelweezel <eevel.weezel@gmail.com>
Date:   Wed Apr 9 22:14:45 2025 -0500

    be more specific

commit 5723700fff48b3d065dba852a66689efa6a30ede
Author: eevelweezel <eevel.weezel@gmail.com>
Date:   Wed Apr 9 20:47:24 2025 -0500

    skip one more

commit a180e74f6a40fdb55180eca0f493993f5c37f41a
Author: eevelweezel <eevel.weezel@gmail.com>
Date:   Wed Apr 9 20:38:20 2025 -0500

    skip other tests requiring internet

commit 6c33ac80df7e4406b22e0302cbb2a0062781343a
Author: eevelweezel <eevel.weezel@gmail.com>
Date:   Wed Apr 9 20:24:07 2025 -0500

    skip failing tests

commit edf0b0da15818c125bdd8af1cad83832799f7745
Author: eevelweezel <eevel.weezel@gmail.com>
Date:   Wed Apr 9 20:01:51 2025 -0500

    put dotenv back

commit 1beda7ae468b0e7b062710d32897397631bf5a3d
Author: eevelweezel <eevel.weezel@gmail.com>
Date:   Wed Apr 9 19:49:56 2025 -0500

    put mock back

commit 73687a81986df3a6ec00ef5831474ce9a8245463
Author: eevelweezel <eevel.weezel@gmail.com>
Date:   Wed Apr 9 19:41:53 2025 -0500

    fix deps again

commit c5521200d8e9869962382ea300a7f9780b124e56
Author: eevelweezel <eevel.weezel@gmail.com>
Date:   Wed Apr 9 19:13:59 2025 -0500

    update changelog

commit aeb4ea60cfc66268708ee89b146d513bcb210fc9
Merge: 6e2aa22 8293f05
Author: eevelweezel <eevel.weezel@gmail.com>
Date:   Wed Apr 9 19:11:45 2025 -0500

    Update upstream source from tag 'upstream/2.23.1'
    
    Update to upstream version '2.23.1'
    with Debian dir c19c76a0bfcbff063fa72b6e931d9a38ee40cb47

commit 8293f059f6bccef2d7eedea8dfa25a645651ef78
Author: eevelweezel <eevel.weezel@gmail.com>
Date:   Wed Apr 9 19:11:41 2025 -0500

    New upstream version 2.23.1

commit 6e2aa22b43d8e0f35085b5d266a42307d8753cab
Author: eevelweezel <eevel.weezel@gmail.com>
Date:   Wed Apr 9 19:02:04 2025 -0500

    fix deps

commit 7d4a41259073a3c5ca401bf78d10df64e2225ac3
Author: eevelweezel <eevel.weezel@gmail.com>
Date:   Wed Jan 8 18:57:03 2025 -0600

    fix certifi version

commit 1a6d1dfb6ee3bc17a22b73988552d2e39179ffec
Author: eevelweezel <eevel.weezel@gmail.com>
Date:   Wed Jan 8 18:40:03 2025 -0600

    pull in 2.22.1

commit 6e6a960b8ab05b6426f974fbc929e2f07265230d
Merge: 2a832fd 2572400
Author: eevelweezel <eevel.weezel@gmail.com>
Date:   Wed Jan 8 18:34:22 2025 -0600

    Update upstream source from tag 'upstream/2.22.1'
    
    Update to upstream version '2.22.1'
    with Debian dir 37599808bc53eace8fe8ee0ae2bad89e40566f1e

commit 2572400ede8c763d3ece32de3d076cc49e7e3d93
Author: eevelweezel <eevel.weezel@gmail.com>
Date:   Wed Jan 8 18:34:15 2025 -0600

    New upstream version 2.22.1

commit 2a832fd94352b35c8ea877d139d76bda299f5825
Author: eevelweezel <eevel.weezel@gmail.com>
Date:   Mon Sep 2 22:07:12 2024 -0500

    update deps
    
    Signed-off-by: eevelweezel <eevel.weezel@gmail.com>

commit bfcab296e67354ee8eb24bd2ac66bf2cddce8e0f
Author: eevelweezel <eevel.weezel@gmail.com>
Date:   Wed Aug 7 20:53:01 2024 -0500

    update changelog

commit 0560ad6f10bc44d8000f0553bdfb5d1b67bc0e4b
Author: eevelweezel <eevel.weezel@gmail.com>
Date:   Wed Aug 7 20:38:49 2024 -0500

    New upstream version 2.17.3

commit 67210fd15f8b50e08fa2b346967f78280433f155
Merge: 8d00664 0560ad6
Author: eevelweezel <eevel.weezel@gmail.com>
Date:   Wed Aug 7 20:38:49 2024 -0500

    Update upstream source from tag 'upstream/2.17.3'
    
    Update to upstream version '2.17.3'
    with Debian dir 87fa41187d120e6615815f40327d8f6a2457b1fc

commit 8d00664406db684d6b36d6644e52e35e8bfcbeb4
Author: eevelweezel <eevel.weezel@gmail.com>
Date:   Wed Aug 7 20:17:46 2024 -0500

    add dep-logic

commit 01b7975d26a82185da7af6f30f60258959aeb1e3
Author: eevelweezel <eevel.weezel@gmail.com>
Date:   Mon Jul 29 04:11:37 2024 -0500

    fix changelog

commit 66eca2884e08f72e12b2c8f91f6c9251cfdda3c2
Author: eevelweezel <eevel.weezel@gmail.com>
Date:   Mon Jul 29 04:01:20 2024 -0500

    update standards

commit a29ea8c8d21b813eb85235def41def05633ff8a7
Merge: 54b58fa 7fc1985
Author: eevelweezel <eevel.weezel@gmail.com>
Date:   Sat Jul 13 19:51:31 2024 -0500

    Update upstream source from tag 'upstream/2.16.1'
    
    Update to upstream version '2.16.1'
    with Debian dir a245f2f60c63dafccfb61d5bd42be96af0c0d73d

commit 54b58fa1545a14a165af23f440f56465128a01da
Merge: 9bbb1bc e0ef73d
Author: eevelweezel <eevel.weezel@gmail.com>
Date:   Sat Jul 13 19:49:33 2024 -0500

    Update upstream source from tag 'upstream/2.16.1'
    
    Update to upstream version '2.16.1'
    with Debian dir a245f2f60c63dafccfb61d5bd42be96af0c0d73d

commit 9bbb1bc7d5bc44c567845874bb303f5ed3cd8041
Author: Stefano Rivera <stefanor@debian.org>
Date:   Sat Jun 29 19:00:31 2024 -0700

    fixup! Drop 0001-Disable-dynamic-version.patch, no longer needed.

commit 77c145517fd82349b8f4abfcde654090c26ff561
Author: Stefano Rivera <stefanor@debian.org>
Date:   Sat Jun 29 18:56:37 2024 -0700

    Remove missing-sources, no longer needed.

commit d280e4d8e6bea5133868f6be72d443d84f324b80
Author: Stefano Rivera <stefanor@debian.org>
Date:   Sat Jun 29 18:52:22 2024 -0700

    Drop 0001-Disable-dynamic-version.patch, no longer needed.

commit 83830a91caef5cf2a1fb0953dfe1b3922964c957
Author: Stefano Rivera <stefanor@debian.org>
Date:   Sat Jun 29 18:51:57 2024 -0700

    Refresh patches.

commit dddddca1a380a742f39f4acc3405f661349d604d
Author: eevelweezel <eevel.weezel@gmail.com>
Date:   Sat Jun 29 18:48:01 2024 -0700

    New upstream version.

commit 8367a1d24af90644dafc9e2de39d8d296a91cc7a
Merge: 70817b0 e4eff3c
Author: eevelweezel <eevel.weezel@gmail.com>
Date:   Wed Apr 17 20:47:24 2024 -0500

    Update upstream source from tag 'upstream/2.14.0'
    
    Update to upstream version '2.14.0'
    with Debian dir 0abc969b4210108263645e92abcacb4d9e3eab4e
Created: 2023-08-17 Last update: 2025-05-17 17:58
1 low-priority security issue in bookworm low

There is 1 open security issue in bookworm.

1 issue left for the package maintainer to handle:
  • CVE-2023-45805: (needs triaging) pdm is a Python package and dependency manager supporting the latest PEP standards. It's possible to craft a malicious `pdm.lock` file that could allow e.g. an insider or a malicious open source project to appear to depend on a trusted PyPI project, but actually install another project. A project `foo` can be targeted by creating the project `foo-2` and uploading the file `foo-2-2.tar.gz` to pypi.org. PyPI will see this as project `foo-2` version `2`, while PDM will see this as project `foo` version `2-2`. The version must only be `parseable as a version` and the filename must be a prefix of the project name, but it's not verified to match the version being installed. Version `2-2` is also not a valid normalized version per PEP 440. Matching the project name exactly (not just prefix) would fix the issue. When installing dependencies with PDM, what's actually installed could differ from what's listed in `pyproject.toml` (including arbitrary code execution on install). It could also be used for downgrade attacks by only changing the version. This issue has been addressed in commit `6853e2642df` which is included in release version `2.9.4`. Users are advised to upgrade. There are no known workarounds for this vulnerability.

You can find information about how to handle this issue in the security team's documentation.

Created: 2023-10-21 Last update: 2025-03-07 06:31
debian/patches: 1 patch to forward upstream low

Among the 1 debian patch available in version 2.20.1+ds1-2 of the package, we noticed the following issues:

  • 1 patch where the metadata indicates that the patch has not yet been forwarded upstream. You should either forward the patch upstream or update the metadata to document its real status.
Created: 2023-02-26 Last update: 2025-03-02 07:30
Standards version of the package is outdated. wishlist
The package should be updated to follow the last version of Debian Policy (Standards-Version 4.7.2 instead of 4.7.0).
Created: 2025-02-21 Last update: 2025-03-02 04:24
news
[rss feed]
  • [2025-03-07] pdm 2.20.1+ds1-2 MIGRATED to testing (Debian testing watch)
  • [2025-03-02] Accepted pdm 2.20.1+ds1-2 (source) into unstable (Boyuan Yang)
  • [2024-11-29] pdm 2.20.1+ds1-1 MIGRATED to testing (Debian testing watch)
  • [2024-11-23] Accepted pdm 2.20.1+ds1-1 (source) into unstable (Boyuan Yang)
  • [2024-11-14] pdm 2.20.0.post1+ds1-2 MIGRATED to testing (Debian testing watch)
  • [2024-11-08] Accepted pdm 2.20.0.post1+ds1-2 (source) into unstable (Boyuan Yang)
  • [2024-11-08] Accepted pdm 2.20.0.post1+ds1-1 (source) into unstable (Boyuan Yang)
  • [2024-05-05] pdm 2.2.1+ds1-2 MIGRATED to testing (Debian testing watch)
  • [2024-03-17] Accepted pdm 2.2.1+ds1-2 (source) into unstable (Pierre-Elliott Bécue)
  • [2023-09-19] pdm REMOVED from testing (Debian testing watch)
  • [2022-12-02] pdm 2.2.1+ds1-1 MIGRATED to testing (Debian testing watch)
  • [2022-11-26] Accepted pdm 2.2.1+ds1-1 (source) into unstable (Boyuan Yang)
  • [2022-09-27] pdm 2.1.4+ds1-1 MIGRATED to testing (Debian testing watch)
  • [2022-09-21] Accepted pdm 2.1.4+ds1-1 (source) into unstable (Boyuan Yang)
  • [2022-07-30] pdm 2.0.3+ds1-1 MIGRATED to testing (Debian testing watch)
  • [2022-07-23] Accepted pdm 2.0.3+ds1-1 (source) into unstable (Boyuan Yang)
  • [2022-07-23] pdm 2.0.1+ds1-1 MIGRATED to testing (Debian testing watch)
  • [2022-07-23] pdm 2.0.1+ds1-1 MIGRATED to testing (Debian testing watch)
  • [2022-07-17] Accepted pdm 2.0.1+ds1-1 (source) into unstable (Boyuan Yang)
  • [2022-07-15] pdm 2.0.0b2+ds1-1 MIGRATED to testing (Debian testing watch)
  • [2022-07-15] pdm 2.0.0b2+ds1-1 MIGRATED to testing (Debian testing watch)
  • [2022-07-09] Accepted pdm 2.0.0b2+ds1-1 (source) into unstable (Boyuan Yang)
  • [2022-07-09] Accepted pdm 2.0.0b1+ds1-1 (source all) into unstable, unstable (Debian FTP Masters) (signed by: Boyuan Yang)
  • [2001-12-19] Installed pdm 0.1 (arm source) (Philip Blundell)
bugs [bug history graph]
  • all: 2
  • RC: 0
  • I&N: 1
  • M&W: 0
  • F&P: 1
  • patch: 0
links
  • homepage
  • lintian (0, 2)
  • buildd: logs, reproducibility
  • popcon
  • browse source code
  • edit tags
  • other distros
  • security tracker
  • debian patches
ubuntu Ubuntu logo [Information about Ubuntu for Debian Developers]
  • version: 2.20.1+ds1-2

Debian Package Tracker — Copyright 2013-2025 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing