Debian Package Tracker
Register | Log in
Subscribe

php8.2

server-side, HTML-embedded scripting language (metapackage)

Choose email to subscribe with

general
  • source: php8.2 (main)
  • version: 8.2.10-2
  • maintainer: Debian PHP Maintainers (DMD)
  • uploaders: Ondřej Surý [DMD] – Lior Kaplan [DMD]
  • arch: all any
  • std-ver: 4.5.0.0
  • VCS: Git (Browse, QA)
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • stable: 8.2.7-1~deb12u1
  • stable-sec: 8.2.7-1~deb12u1
  • testing: 8.2.10-2
  • unstable: 8.2.10-2
versioned links
  • 8.2.7-1~deb12u1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 8.2.10-2: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • libapache2-mod-php8.2
  • libphp8.2-embed (1 bugs: 1, 0, 0, 0)
  • php8.2
  • php8.2-bcmath
  • php8.2-bz2
  • php8.2-cgi
  • php8.2-cli
  • php8.2-common
  • php8.2-curl
  • php8.2-dba
  • php8.2-dev
  • php8.2-enchant
  • php8.2-fpm (1 bugs: 0, 0, 1, 0)
  • php8.2-gd
  • php8.2-gmp
  • php8.2-imap
  • php8.2-interbase
  • php8.2-intl
  • php8.2-ldap
  • php8.2-mbstring
  • php8.2-mysql
  • php8.2-odbc
  • php8.2-opcache
  • php8.2-pgsql
  • php8.2-phpdbg
  • php8.2-pspell
  • php8.2-readline
  • php8.2-snmp
  • php8.2-soap
  • php8.2-sqlite3
  • php8.2-sybase
  • php8.2-tidy
  • php8.2-xml
  • php8.2-xsl
  • php8.2-zip
action needed
lintian reports 8 errors and 64 warnings high
Lintian reports 8 errors and 64 warnings about this package. You should make the package lintian clean getting rid of them.
Created: 2023-02-10 Last update: 2023-09-05 21:05
Depends on packages which need a new maintainer normal
The packages that php8.2 depends on which need a new maintainer are:
  • qdbm (#890504)
    • Depends: libqdbm14
    • Build-Depends: libqdbm-dev
  • argon2 (#1032462)
    • Depends: libargon2-1 libargon2-1 libargon2-1 libargon2-1 libargon2-1 libargon2-1
    • Build-Depends: libargon2-dev
Created: 2023-01-06 Last update: 2023-09-21 23:27
Does not build reproducibly during testing normal
A package building reproducibly enables third parties to verify that the source matches the distributed binaries. It has been identified that this source package produced different results, failed to build or had other issues in a test environment. Please read about how to improve the situation!
Created: 2023-01-15 Last update: 2023-09-21 16:37
1 new commit since last upload, is it time to release? normal
vcswatch reports that this package seems to have new commits in its VCS but has not yet updated debian/changelog. You should consider updating the Debian changelog and uploading this new version into the archive.

Here are the relevant commit logs:
commit b71f1dcfa31db9d05eb1bd0b37d837a3855266e8
Author: Ondřej Surý <ondrej@sury.org>
Date:   Tue Sep 5 07:49:06 2023 +0200

    Update changelog for 8.2.10-2 release
Created: 2023-07-09 Last update: 2023-09-17 20:34
2 low-priority security issues in bookworm low

There are 2 open security issues in bookworm.

2 issues left for the package maintainer to handle:
  • CVE-2023-3823: (postponed; to be fixed through a stable update) In PHP versions 8.0.* before 8.0.30, 8.1.* before 8.1.22, and 8.2.* before 8.2.8 various XML functions rely on libxml global state to track configuration variables, like whether external entities are loaded. This state is assumed to be unchanged unless the user explicitly changes it by calling appropriate function. However, since the state is process-global, other modules - such as ImageMagick - may also use this library within the same process, and change that global state for their internal purposes, and leave it in a state where external entities loading is enabled. This can lead to the situation where external XML is parsed with external entities loaded, which can lead to disclosure of any local files accessible to PHP. This vulnerable state may persist in the same process across many requests, until the process is shut down. 
  • CVE-2023-3824: (postponed; to be fixed through a stable update) In PHP version 8.0.* before 8.0.30,  8.1.* before 8.1.22, and 8.2.* before 8.2.8, when loading phar file, while reading PHAR directory entries, insufficient length checking may lead to a stack buffer overflow, leading potentially to memory corruption or RCE. 

You can find information about how to handle these issues in the security team's documentation.

Created: 2023-08-17 Last update: 2023-09-07 04:30
debian/patches: 45 patches to forward upstream low

Among the 46 debian patches available in version 8.2.10-2 of the package, we noticed the following issues:

  • 45 patches where the metadata indicates that the patch has not yet been forwarded upstream. You should either forward the patch upstream or update the metadata to document its real status.
Created: 2023-02-26 Last update: 2023-09-05 18:25
Build log checks report 2 warnings low
Build log checks report 2 warnings
Created: 2023-02-08 Last update: 2023-09-05 18:12
Standards version of the package is outdated. wishlist
The package should be updated to follow the last version of Debian Policy (Standards-Version 4.6.2 instead of 4.5.0.0).
Created: 2023-01-06 Last update: 2023-09-05 11:51
testing migrations
  • This package will soon be part of the auto-openldap transition. You might want to ensure that your package is ready for it. You can probably find supplementary information in the debian-release archives or in the corresponding release.debian.org bug.
  • This package will soon be part of the auto-tidy-html5 transition. You might want to ensure that your package is ready for it. You can probably find supplementary information in the debian-release archives or in the corresponding release.debian.org bug.
  • This package will soon be part of the auto-libsodium transition. You might want to ensure that your package is ready for it. You can probably find supplementary information in the debian-release archives or in the corresponding release.debian.org bug.
  • This package will soon be part of the auto-icu transition. You might want to ensure that your package is ready for it. You can probably find supplementary information in the debian-release archives or in the corresponding release.debian.org bug.
news
[rss feed]
  • [2023-09-07] php8.2 8.2.10-2 MIGRATED to testing (Debian testing watch)
  • [2023-09-05] Accepted php8.2 8.2.10-2 (source) into unstable (Ondřej Surý)
  • [2023-09-02] Accepted php8.2 8.2.10-1 (source) into unstable (Ondřej Surý)
  • [2023-06-18] php8.2 8.2.7-1 MIGRATED to testing (Debian testing watch)
  • [2023-06-16] Accepted php8.2 8.2.7-1~deb12u1 (source) into proposed-updates (Debian FTP Masters) (signed by: Ondřej Surý)
  • [2023-06-13] Accepted php8.2 8.2.7-1~deb12u1 (source) into stable-security (Debian FTP Masters) (signed by: Ondřej Surý)
  • [2023-06-09] Accepted php8.2 8.2.7-1 (source) into unstable (Ondřej Surý)
  • [2023-05-04] php8.2 8.2.5-2 MIGRATED to testing (Debian testing watch)
  • [2023-04-27] Accepted php8.2 8.2.5-2 (source) into unstable (Ondřej Surý)
  • [2023-04-27] Accepted php8.2 8.2.5-1 (source) into unstable (Ondřej Surý)
  • [2023-04-06] php8.2 8.2.4-1 MIGRATED to testing (Debian testing watch)
  • [2023-03-16] Accepted php8.2 8.2.4-1 (source) into unstable (Ondřej Surý)
  • [2023-02-14] php8.2 8.2.2-3 MIGRATED to testing (Debian testing watch)
  • [2023-02-07] Accepted php8.2 8.2.2-3 (source) into unstable (Ondřej Surý)
  • [2023-02-06] php8.2 8.2.2-1 MIGRATED to testing (Debian testing watch)
  • [2023-02-03] Accepted php8.2 8.2.2-1 (source) into unstable (Ondřej Surý)
  • [2023-01-13] php8.2 8.2.1-1 MIGRATED to testing (Debian testing watch)
  • [2023-01-06] Accepted php8.2 8.2.1-1 (source) into unstable (Ondřej Surý)
  • [2023-01-05] Accepted php8.2 8.2.0-4 (source) into unstable (Ondřej Surý)
  • [2022-12-10] Accepted php8.2 8.2.0-1 (source) into experimental (Ondřej Surý)
  • [2022-10-28] Accepted php8.2 8.2.0~rc5-1 (source) into experimental (Ondřej Surý)
  • [2022-07-08] Accepted php8.2 8.2.0~alpha3-1 (source amd64 all) into experimental, experimental (Debian FTP Masters) (signed by: Ondřej Surý)
  • [2022-07-08] Accepted php8.2 8.2.0~alpha2-1 (source amd64 all) into experimental, experimental (Debian FTP Masters) (signed by: Ondřej Surý)
bugs [bug history graph]
  • all: 7
  • RC: 1
  • I&N: 3
  • M&W: 3
  • F&P: 0
  • patch: 0
links
  • homepage
  • lintian (8, 64)
  • buildd: logs, checks, reproducibility, cross
  • popcon
  • browse source code
  • edit tags
  • other distros
  • security tracker
  • screenshots
  • debian patches
  • debci
ubuntu Ubuntu logo [Information about Ubuntu for Debian Developers]
  • version: 8.2.10-2ubuntu1
  • 1 bug
  • patches for 8.2.10-2ubuntu1

Debian Package Tracker — Copyright 2013-2018 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing