Debian Package Tracker
Register | Log in
Subscribe

python-webob

Choose email to subscribe with

general
  • source: python-webob (main)
  • version: 1:1.8.9-1
  • maintainer: Debian Python Team (DMD)
  • uploaders: Thomas Goirand [DMD] – Soren Hansen [DMD]
  • arch: all
  • std-ver: 3.9.8
  • VCS: Git (Browse, QA)
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • o-o-stable: 1:1.8.5-1
  • oldstable: 1:1.8.6-1.1
  • stable: 1:1.8.6-3
  • testing: 1:1.8.9-1
  • unstable: 1:1.8.9-1
versioned links
  • 1:1.8.5-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1:1.8.6-1.1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1:1.8.6-3: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1:1.8.9-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • python-webob-doc
  • python3-webob
action needed
Standards version of the package is outdated. high
The package is severely out of date with respect to the Debian Policy. The package should be updated to follow the last version of Debian Policy (Standards-Version 4.7.2 instead of 3.9.8).
Created: 2018-04-16 Last update: 2025-02-27 13:25
1 new commit since last upload, is it time to release? normal
vcswatch reports that this package seems to have new commits in its VCS but has not yet updated debian/changelog. You should consider updating the Debian changelog and uploading this new version into the archive.

Here are the relevant commit logs:
commit 53c3e2a2bb3d5d746d06b8aa9d7afdc4b728052c
Author: Alexandre Detiste <alexandre.detiste@gmail.com>
Date:   Sun Jan 19 15:11:50 2025 +0100

    drop python3-simplejson dep from python-webob-doc
Created: 2025-01-19 Last update: 2025-05-13 16:04
1 low-priority security issue in bookworm low

There is 1 open security issue in bookworm.

1 issue left for the package maintainer to handle:
  • CVE-2024-42353: (needs triaging) WebOb provides objects for HTTP requests and responses. When WebOb normalizes the HTTP Location header to include the request hostname, it does so by parsing the URL that the user is to be redirected to with Python's urlparse, and joining it to the base URL. `urlparse` however treats a `//` at the start of a string as a URI without a scheme, and then treats the next part as the hostname. `urljoin` will then use that hostname from the second part as the hostname replacing the original one from the request. This vulnerability is patched in WebOb version 1.8.8.

You can find information about how to handle this issue in the security team's documentation.

Created: 2024-08-17 Last update: 2025-02-27 05:02
debian/patches: 1 patch to forward upstream low

Among the 1 debian patch available in version 1:1.8.9-1 of the package, we noticed the following issues:

  • 1 patch where the metadata indicates that the patch has not yet been forwarded upstream. You should either forward the patch upstream or update the metadata to document its real status.
Created: 2023-02-26 Last update: 2025-01-13 09:02
news
[rss feed]
  • [2025-01-21] python-webob 1:1.8.9-1 MIGRATED to testing (Debian testing watch)
  • [2025-01-12] Accepted python-webob 1:1.8.9-1 (source) into unstable (Colin Watson)
  • [2024-11-20] python-webob 1:1.8.7-3 MIGRATED to testing (Debian testing watch)
  • [2024-11-15] Accepted python-webob 1:1.8.7-3 (source) into unstable (Thomas Goirand)
  • [2024-11-15] Accepted python-webob 1:1.8.7-2 (source) into unstable (Thomas Goirand)
  • [2024-03-06] python-webob 1:1.8.7-1 MIGRATED to testing (Debian testing watch)
  • [2024-03-01] Accepted python-webob 1:1.8.7-1 (source) into unstable (Alexandre Detiste)
  • [2022-10-22] python-webob 1:1.8.6-3 MIGRATED to testing (Debian testing watch)
  • [2022-10-17] Accepted python-webob 1:1.8.6-3 (source) into unstable (Jelmer Vernooij) (signed by: Jelmer Vernooij)
  • [2022-06-15] python-webob 1:1.8.6-2 MIGRATED to testing (Debian testing watch)
  • [2022-06-10] Accepted python-webob 1:1.8.6-2 (source) into unstable (Sandro Tosi)
  • [2020-11-19] python-webob 1:1.8.6-1.1 MIGRATED to testing (Debian testing watch)
  • [2020-11-14] Accepted python-webob 1:1.8.6-1.1 (source) into unstable (Matthias Klose)
  • [2020-03-28] python-webob 1:1.8.6-1 MIGRATED to testing (Debian testing watch)
  • [2020-03-22] Accepted python-webob 1:1.8.6-1 (source) into unstable (Piotr Ożarowski)
  • [2020-01-25] python-webob 1:1.8.5-2 MIGRATED to testing (Debian testing watch)
  • [2020-01-19] Accepted python-webob 1:1.8.5-2 (source) into unstable (Sandro Tosi)
  • [2019-01-11] python-webob 1:1.8.5-1 MIGRATED to testing (Debian testing watch)
  • [2019-01-05] Accepted python-webob 1:1.8.5-1 (source all) into unstable (Piotr Ożarowski) (signed by: Piotr Ozarowski)
  • [2019-01-02] python-webob 1:1.8.4-1 MIGRATED to testing (Debian testing watch)
  • [2018-12-28] Accepted python-webob 1:1.8.4-1 (source all) into unstable (TANIGUCHI Takaki)
  • [2018-09-10] python-webob 1:1.8.2-2 MIGRATED to testing (Debian testing watch)
  • [2018-09-05] Accepted python-webob 1:1.8.2-2 (source all) into unstable (Thomas Goirand)
  • [2018-08-23] Accepted python-webob 1:1.8.2-1 (source all) into experimental (Thomas Goirand)
  • [2017-11-07] python-webob 1:1.7.3-2 MIGRATED to testing (Debian testing watch)
  • [2017-11-01] Accepted python-webob 1:1.7.3-2 (source all) into unstable (Thomas Goirand)
  • [2017-09-17] Accepted python-webob 1:1.7.3-1 (source all) into experimental (Thomas Goirand)
  • [2017-01-30] python-webob 1:1.6.2-2 MIGRATED to testing (Debian testing watch)
  • [2017-01-19] Accepted python-webob 1:1.6.2-2 (source) into unstable (Ondřej Nový)
  • [2016-12-27] Accepted python-webob 1.7.0-1 (source all) into unstable (Piotr Ożarowski) (signed by: Piotr Ozarowski)
  • 1
  • 2
bugs [bug history graph]
  • all: 0
links
  • homepage
  • lintian
  • buildd: logs, reproducibility
  • popcon
  • browse source code
  • edit tags
  • other distros
  • security tracker
  • screenshots
  • debian patches
  • debci
ubuntu Ubuntu logo [Information about Ubuntu for Debian Developers]
  • version: 1:1.8.9-1

Debian Package Tracker — Copyright 2013-2025 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing