Debian Package Tracker
Register | Log in
Subscribe

varnish

state of the art, high-performance web accelerator

Choose email to subscribe with

general
  • source: varnish (main)
  • version: 6.6.1-1
  • maintainer: Varnish Package Maintainers (DMD)
  • uploaders: Emanuele Rocca [DMD] – Tollef Fog Heen [DMD] – Jan Wagner [DMD] – Lars Bahner [DMD] – Stig Sandbeck Mathisen [DMD]
  • arch: all any
  • std-ver: 4.5.1
  • VCS: Git (Browse, QA)
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • o-o-stable: 5.0.0-7+deb9u2
  • o-o-sec: 5.0.0-7+deb9u3
  • oldstable: 6.1.1-1+deb10u1
  • old-sec: 6.1.1-1+deb10u3
  • stable: 6.5.1-1
  • stable-sec: 6.5.1-1+deb11u2
  • unstable: 6.6.1-1
versioned links
  • 5.0.0-7+deb9u2: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 5.0.0-7+deb9u3: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 6.1.1-1+deb10u1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 6.1.1-1+deb10u3: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 6.5.1-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 6.5.1-1+deb11u2: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 6.6.1-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • libvarnishapi-dev
  • libvarnishapi2
  • varnish (17 bugs: 1, 11, 5, 0)
  • varnish-doc
action needed
Problems while searching for a new upstream version high
uscan had problems while searching for a new upstream version:
In debian/watch no matching files for watch line
  https://varnish-cache.org/releases/ \.\./_downloads/varnish-(?:[-_]?(\d[\-+\.:\~\da-zA-Z]*)).tgz
Created: 2022-01-28 Last update: 2022-05-20 19:39
1 security issue in sid high

There is 1 open security issue in sid.

1 important issue:
  • CVE-2022-23959: In Varnish Cache before 6.6.2 and 7.x before 7.0.2, Varnish Cache 6.0 LTS before 6.0.10, and and Varnish Enterprise (Cache Plus) 4.1.x before 4.1.11r6 and 6.0.x before 6.0.9r4, request smuggling can occur for HTTP/1 connections.
Created: 2022-01-26 Last update: 2022-05-05 17:36
1 security issue in bookworm high

There is 1 open security issue in bookworm.

1 important issue:
  • CVE-2022-23959: In Varnish Cache before 6.6.2 and 7.x before 7.0.2, Varnish Cache 6.0 LTS before 6.0.10, and and Varnish Enterprise (Cache Plus) 4.1.x before 4.1.11r6 and 6.0.x before 6.0.9r4, request smuggling can occur for HTTP/1 connections.
Created: 2022-01-26 Last update: 2022-03-26 17:38
lintian reports 2 errors and 10 warnings high
Lintian reports 2 errors and 10 warnings about this package. You should make the package lintian clean getting rid of them.
Created: 2021-10-23 Last update: 2021-10-23 20:03
The package has not entered testing even though the delay is over normal
The package has not entered testing even though the 2-day delay is over. Check why.
Created: 2022-05-05 Last update: 2022-05-21 01:01
3 bugs tagged patch in the BTS normal
The BTS contains patches fixing 3 bugs, consider including or untagging them.
Created: 2021-08-14 Last update: 2022-05-21 00:33
3 new commits since last upload, is it time to release? normal
vcswatch reports that this package seems to have new commits in its VCS but has not yet updated debian/changelog. You should consider updating the Debian changelog and uploading this new version into the archive.

Here are the relevant commit logs:
commit 34c575f7faadb8a460f0b6f42dab9d39eb2b1eb0
Author: Stig Sandbeck Mathisen <ssm@debian.org>
Date:   Mon Jan 31 14:48:05 2022 +0100

    debian/watch: Update match for release tarballs

commit baac036033188053a1aeafc0bbd5c3b66a3625c0
Author: Stig Sandbeck Mathisen <ssm@debian.org>
Date:   Mon Oct 4 08:46:26 2021 +0200

    Update licenses for build-aux/*

commit f9b7f225f55d682ab5390fbe08bb9ecb5bdaf0ba
Author: Stig Sandbeck Mathisen <ssm@debian.org>
Date:   Mon Oct 4 08:36:57 2021 +0200

    Update standards version to 4.6.0, no changes needed.
    
    Changes-By: lintian-brush
    Fixes: lintian: out-of-date-standards-version
    See-also: https://lintian.debian.org/tags/out-of-date-standards-version.html
Created: 2021-10-04 Last update: 2022-05-19 04:35
2 low-priority security issues in buster low

There are 2 open security issues in buster.

2 issues left for the package maintainer to handle:
  • CVE-2019-20637: (needs triaging) An issue was discovered in Varnish Cache before 6.0.5 LTS, 6.1.x and 6.2.x before 6.2.2, and 6.3.x before 6.3.1. It does not clear a pointer between the handling of one client request and the next request within the same connection. This sometimes causes information to be disclosed from the connection workspace, such as data structures associated with previous requests within this connection or VCL-related temporary headers.
  • CVE-2020-11653: (postponed; to be fixed through a stable update) An issue was discovered in Varnish Cache before 6.0.6 LTS, 6.1.x and 6.2.x before 6.2.3, and 6.3.x before 6.3.2. It occurs when communication with a TLS termination proxy uses PROXY version 2. There can be an assertion failure and daemon restart, which causes a performance loss.

You can find information about how to handle these issues in the security team's documentation.

Created: 2021-02-19 Last update: 2022-05-05 17:36
Standards version of the package is outdated. wishlist
The package should be updated to follow the last version of Debian Policy (Standards-Version 4.6.1 instead of 4.5.1).
Created: 2018-12-23 Last update: 2022-05-11 23:25
testing migrations
  • excuses:
    • Migration status for varnish (- to 6.6.1-1): BLOCKED: Rejected/violates migration policy/introduces a regression
    • Issues preventing migration:
    • ∙ ∙ Updating varnish would introduce bugs in testing: #1004433, #1010582
    • Additional info:
    • ∙ ∙ Piuparts tested OK - https://piuparts.debian.org/sid/source/v/varnish.html
    • ∙ ∙ autopkgtest for varnish/6.6.1-1: amd64: Pass, arm64: Pass, armhf: Pass, i386: Pass, ppc64el: Pass, s390x: Pass
    • ∙ ∙ Required age reduced by 3 days because of autopkgtest
    • ∙ ∙ 244 days old (needed 2 days)
    • Not considered
news
[rss feed]
  • [2022-05-06] varnish REMOVED from testing (Debian testing watch)
  • [2022-03-05] Accepted varnish 6.1.1-1+deb10u3 (source) into oldstable-proposed-updates->oldstable-new, oldstable-proposed-updates (Debian FTP Masters) (signed by: Florian Weimer)
  • [2022-03-05] Accepted varnish 6.1.1-1+deb10u2 (source) into oldstable-proposed-updates->oldstable-new, oldstable-proposed-updates (Debian FTP Masters) (signed by: Florian Weimer)
  • [2022-03-05] Accepted varnish 6.5.1-1+deb11u2 (source) into proposed-updates->stable-new, proposed-updates (Debian FTP Masters) (signed by: Florian Weimer)
  • [2022-03-05] Accepted varnish 6.5.1-1+deb11u1 (source) into proposed-updates->stable-new, proposed-updates (Debian FTP Masters) (signed by: Florian Weimer)
  • [2022-03-03] Accepted varnish 6.1.1-1+deb10u2 (source) into oldstable->embargoed, oldstable (Debian FTP Masters) (signed by: Florian Weimer)
  • [2022-03-03] Accepted varnish 6.1.1-1+deb10u3 (source) into oldstable->embargoed, oldstable (Debian FTP Masters) (signed by: Florian Weimer)
  • [2022-03-03] Accepted varnish 6.5.1-1+deb11u2 (source) into stable-security->embargoed, stable-security (Debian FTP Masters) (signed by: Florian Weimer)
  • [2022-03-03] Accepted varnish 6.5.1-1+deb11u1 (source) into stable-security->embargoed, stable-security (Debian FTP Masters) (signed by: Florian Weimer)
  • [2022-02-13] Accepted varnish 5.0.0-7+deb9u3 (source) into oldoldstable (Markus Koschany)
  • [2021-10-04] varnish 6.6.1-1 MIGRATED to testing (Debian testing watch)
  • [2021-09-18] Accepted varnish 6.6.1-1 (source) into unstable (Stig Sandbeck Mathisen)
  • [2021-09-09] varnish 6.5.2-1 MIGRATED to testing (Debian testing watch)
  • [2021-07-20] Accepted varnish 6.5.2-1 (source) into unstable (Stig Sandbeck Mathisen)
  • [2020-11-19] varnish 6.5.1-1 MIGRATED to testing (Debian testing watch)
  • [2020-11-19] varnish 6.5.1-1 MIGRATED to testing (Debian testing watch)
  • [2020-09-29] Accepted varnish 6.5.1-1 (source) into unstable (Stig Sandbeck Mathisen)
  • [2020-09-17] Accepted varnish 6.5.0-1 (source) into unstable (Stig Sandbeck Mathisen)
  • [2020-05-27] varnish 6.4.0-3 MIGRATED to testing (Debian testing watch)
  • [2020-05-24] Accepted varnish 6.4.0-3 (source) into unstable (Stig Sandbeck Mathisen)
  • [2020-04-25] varnish 6.4.0-2 MIGRATED to testing (Debian testing watch)
  • [2020-04-23] Accepted varnish 6.4.0-2 (source) into unstable (Stig Sandbeck Mathisen)
  • [2020-04-18] Accepted varnish 6.4.0-1 (all amd64 source) into unstable (Stig Sandbeck Mathisen)
  • [2020-03-17] varnish 6.2.1-3 MIGRATED to testing (Debian testing watch)
  • [2020-03-15] Accepted varnish 6.2.1-3 (source) into unstable (Stig Sandbeck Mathisen)
  • [2019-10-19] varnish 6.2.1-2 MIGRATED to testing (Debian testing watch)
  • [2019-09-08] Accepted varnish 6.2.1-2 (source) into unstable (Stig Sandbeck Mathisen)
  • [2019-09-07] Accepted varnish 6.1.1-1+deb10u1 (source amd64 all) into proposed-updates->stable-new, proposed-updates (Moritz Mühlenhoff)
  • [2019-09-04] Accepted varnish 6.1.1-1+deb10u1 (source amd64 all) into stable->embargoed, stable (Moritz Mühlenhoff)
  • [2019-09-03] Accepted varnish 6.2.1-1 (source) into unstable (Stig Sandbeck Mathisen)
  • 1
  • 2
bugs [bug history graph]
  • all: 20 21
  • RC: 1
  • I&N: 12 13
  • M&W: 6
  • F&P: 1
  • patch: 3
links
  • homepage
  • lintian (2, 10)
  • buildd: logs, clang, cross
  • popcon
  • browse source code
  • edit tags
  • other distros
  • security tracker
  • screenshots
  • debci
ubuntu Ubuntu logo [Information about Ubuntu for Debian Developers]
  • version: 6.6.1-1
  • 14 bugs (1 patch)

Debian Package Tracker — Copyright 2013-2018 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing