Debian Package Tracker
Register | Log in
Subscribe

r-cran-jsonlite

Robust, High Performance JSON Parser and Generator for R

Choose email to subscribe with

general
  • source: r-cran-jsonlite (main)
  • version: 2.0.0+dfsg-1
  • maintainer: Debian R Packages Maintainers (archive) (DMD) (LowNMU)
  • uploaders: Chris Lawrence [DMD]
  • arch: any
  • std-ver: 4.7.3
  • VCS: Git (Browse, QA)
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • o-o-stable: 1.7.2+dfsg-1
  • oldstable: 1.8.4+dfsg-1
  • stable: 1.9.1+dfsg-1
  • testing: 1.9.1+dfsg-1
  • unstable: 2.0.0+dfsg-1
versioned links
  • 1.7.2+dfsg-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1.8.4+dfsg-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1.9.1+dfsg-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 2.0.0+dfsg-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • r-cran-jsonlite
action needed
Marked for autoremoval on 21 March: #1127064 high
Version 1.9.1+dfsg-1 of r-cran-jsonlite is marked for autoremoval from testing on Sat 21 Mar 2026. It is affected by #1127064. The removal of r-cran-jsonlite will also cause the removal of (transitive) reverse dependencies: car, ea-utils, hmisc, jupyter-kernel-test, macaulay2-jupyter-kernel, metakernel, misc3d, octave-kernel, ompl, r-cran-adegenet, r-cran-adephylo, r-cran-aer, r-cran-afex, r-cran-airr, r-cran-argparse, r-cran-benchmarkme, r-cran-bookdown, r-cran-brms, r-cran-bslib, r-cran-cmdfun, r-cran-colourpicker, r-cran-covid19us, r-cran-covr, r-cran-credentials, r-cran-crosstalk, r-cran-crul, r-cran-dbitest, r-cran-devtools, r-cran-dharma, r-cran-diagrammer, r-cran-doby, r-cran-dt, r-cran-dygraphs, r-cran-dynlm, r-cran-emayili, r-cran-epir, r-cran-factoextra, r-cran-factominer, r-cran-fitbitscraper, r-cran-flextable, r-cran-forecast, r-cran-formattable, r-cran-gap, r-cran-gargle, r-cran-gdtools, r-cran-gert, r-cran-gfonts, r-cran-ggforce, r-cran-ggpubr, r-cran-ggraph, r-cran-ggrastr, r-cran-ggvis, r-cran-gh, r-cran-googledrive, r-cran-googlesheets4, r-cran-googlevis, r-cran-gprofiler2, r-cran-gridsvg, r-cran-haplo.stats, r-cran-heatmaply, r-cran-htmltable, r-cran-htmlwidgets, r-cran-httptest2, r-cran-httr, r-cran-irdisplay, r-cran-irkernel, r-cran-jinjar, r-cran-jrc, r-cran-jsonld, r-cran-kableextra, r-cran-kernelheaping, r-cran-latte, r-cran-leiden, r-cran-luminescence, r-cran-m2r, r-cran-manipulatewidgets, r-cran-maotai, r-cran-mclogit, r-cran-memisc, r-cran-mertools, r-cran-miniui, r-cran-mixtools, r-cran-mockery, r-cran-natserv, r-cran-officer, r-cran-pammtools, r-cran-patrick, r-cran-pbkrtest, r-cran-pec, r-cran-phylobase, r-cran-pkgdown, r-cran-plot3d, r-cran-plotly, r-cran-plumber, r-cran-profvis, r-cran-projpred, r-cran-prophet, r-cran-qgam, r-cran-qgraph, r-cran-quantmod, r-cran-ragg, r-cran-randomglm, r-cran-rcmdrmisc, r-cran-rdbnomics, r-cran-relsurv, r-cran-rentrez, r-cran-repr, r-cran-reprex, r-cran-reticulate, r-cran-rhandsontable, r-cran-rhub, r-cran-riskregression, r-cran-ritis, r-cran-rlist, r-cran-rlumshiny, r-cran-rmarkdown, r-cran-rms, r-cran-rnaturalearth, r-cran-rnexml, r-cran-rotl, r-cran-rredlist, r-cran-rsconnect, r-cran-rsdmx, r-cran-rstan, r-cran-rstanarm, r-cran-rstatix, r-cran-rtweet, r-cran-rvest, r-cran-scatterd3, r-cran-semplot, r-cran-seurat, r-cran-shapes, r-cran-shiny, r-cran-shinybs, r-cran-shinycssloaders, r-cran-shinydashboard, r-cran-shinyfiles, r-cran-shinyjs, r-cran-shinystan, r-cran-shinythemes, r-cran-skimr, r-cran-solrium, r-cran-sparr, r-cran-statcheck, r-cran-survminer, r-cran-svglite, r-cran-systemfit, r-cran-systemfonts, r-cran-taxize, r-cran-testthat, r-cran-textshaping, r-cran-threejs, r-cran-tidyverse, r-cran-treespace, r-cran-tufte, r-cran-usethis, r-cran-v8, r-cran-vcr, r-cran-vdiffr, r-cran-vim, r-cran-visnetwork, r-cran-wdi, r-cran-webgestaltr, r-cran-webmockr, r-cran-webshot, r-cran-webutils, r-cran-whoami, r-cran-wikidataqueryservicer, r-cran-wikidatar, r-cran-wikipedir, r-cran-wikitaxa, r-cran-worrms, r-other-curvefdp, rcmdr, rgl, tseries. You should try to prevent the removal by fixing these RC bugs.
Created: 2026-02-12 Last update: 2026-02-23 21:32
lintian reports 1 error high
Lintian reports 1 error about this package. You should make the package lintian clean getting rid of them.
Created: 2025-12-26 Last update: 2026-01-21 16:32
The package has not entered testing even though the delay is over normal
The package has not entered testing even though the 5-day delay is over. Check why.
Created: 2026-01-22 Last update: 2026-02-23 23:02
3 low-priority security issues in bookworm low

There are 3 open security issues in bookworm.

3 issues left for the package maintainer to handle:
  • CVE-2017-16516: (needs triaging) In the yajl-ruby gem 1.3.0 for Ruby, when a crafted JSON file is supplied to Yajl::Parser.new.parse, the whole ruby process crashes with a SIGABRT in the yajl_string_decode function in yajl_encode.c. This results in the whole ruby process terminating and potentially a denial of service.
  • CVE-2022-24795: (needs triaging) yajl-ruby is a C binding to the YAJL JSON parsing and generation library. The 1.x branch and the 2.x branch of `yajl` contain an integer overflow which leads to subsequent heap memory corruption when dealing with large (~2GB) inputs. The reallocation logic at `yajl_buf.c#L64` may result in the `need` 32bit integer wrapping to 0 when `need` approaches a value of 0x80000000 (i.e. ~2GB of data), which results in a reallocation of buf->alloc into a small heap chunk. These integers are declared as `size_t` in the 2.x branch of `yajl`, which practically prevents the issue from triggering on 64bit platforms, however this does not preclude this issue triggering on 32bit builds on which `size_t` is a 32bit integer. Subsequent population of this under-allocated heap chunk is based on the original buffer size, leading to heap memory corruption. This vulnerability mostly impacts process availability. Maintainers believe exploitation for arbitrary code execution is unlikely. A patch is available and anticipated to be part of yajl-ruby version 1.4.2. As a workaround, avoid passing large inputs to YAJL.
  • CVE-2023-33460: (needs triaging) There's a memory leak in yajl 2.1.0 with use of yajl_tree_parse function. which will cause out-of-memory in server and cause crash.

You can find information about how to handle these issues in the security team's documentation.

Created: 2023-07-22 Last update: 2025-12-26 10:31
testing migrations
  • excuses:
    • Migration status for r-cran-jsonlite (1.9.1+dfsg-1 to 2.0.0+dfsg-1): BLOCKED: Rejected/violates migration policy/introduces a regression
    • Issues preventing migration:
    • ∙ ∙ r-cran-jsonlite unsatisfiable Build-Depends(-Arch) on armhf: architecture-is-64-bit
    • ∙ ∙ r-cran-jsonlite unsatisfiable Build-Depends(-Arch) on i386: architecture-is-64-bit
    • ∙ ∙ r-cran-jsonlite unsatisfiable Build-Depends(-Arch) on s390x: architecture-is-little-endian
    • ∙ ∙ Missing build on armhf
    • ∙ ∙ Missing build on i386
    • ∙ ∙ Missing build on s390x
    • ∙ ∙ Autopkgtest deferred on i386: missing arch:i386 build
    • ∙ ∙ Autopkgtest deferred on s390x: missing arch:s390x build
    • ∙ ∙ Autopkgtest for r-cran-jsonlite/2.0.0+dfsg-1: amd64: Pass, arm64: Pass, ppc64el: Pass, riscv64: Pass
    • ∙ ∙ Lintian check waiting for test results on i386, s390x, armhf - info
    • ∙ ∙ Reproducibility check deferred on armhf: missing builds
    • ∙ ∙ Reproducibility check deferred on i386: missing builds
    • Additional info (not blocking):
    • ∙ ∙ Updating r-cran-jsonlite will fix bugs in testing: #1127064
    • ∙ ∙ Piuparts tested OK - https://piuparts.debian.org/sid/source/r/r-cran-jsonlite.html
    • ∙ ∙ Reproducible on amd64
    • ∙ ∙ Reproducible on arm64
    • ∙ ∙ Reproducible on ppc64el
    • ∙ ∙ 60 days old (needed 5 days)
    • Not considered
news
[rss feed]
  • [2025-12-26] Accepted r-cran-jsonlite 2.0.0+dfsg-1 (source) into unstable (Charles Plessy)
  • [2025-03-22] r-cran-jsonlite 1.9.1+dfsg-1 MIGRATED to testing (Debian testing watch)
  • [2025-03-07] Accepted r-cran-jsonlite 1.9.1+dfsg-1 (source) into unstable (Charles Plessy)
  • [2024-10-04] r-cran-jsonlite 1.8.9+dfsg-1 MIGRATED to testing (Debian testing watch)
  • [2024-10-02] Accepted r-cran-jsonlite 1.8.9+dfsg-1 (source) into unstable (Charles Plessy)
  • [2023-12-08] r-cran-jsonlite 1.8.8+dfsg-1 MIGRATED to testing (Debian testing watch)
  • [2023-12-05] Accepted r-cran-jsonlite 1.8.8+dfsg-1 (source) into unstable (Andreas Tille)
  • [2023-08-27] r-cran-jsonlite 1.8.7+dfsg-1 MIGRATED to testing (Debian testing watch)
  • [2023-08-25] Accepted r-cran-jsonlite 1.8.7+dfsg-1 (source) into unstable (Andreas Tille)
  • [2023-07-21] r-cran-jsonlite 1.8.5+dfsg-1 MIGRATED to testing (Debian testing watch)
  • [2023-06-23] Accepted r-cran-jsonlite 1.8.5+dfsg-1 (source) into unstable (Andreas Tille)
  • [2022-12-11] r-cran-jsonlite 1.8.4+dfsg-1 MIGRATED to testing (Debian testing watch)
  • [2022-12-09] Accepted r-cran-jsonlite 1.8.4+dfsg-1 (source) into unstable (Andreas Tille)
  • [2022-10-28] r-cran-jsonlite 1.8.3+dfsg-1 MIGRATED to testing (Debian testing watch)
  • [2022-10-28] r-cran-jsonlite 1.8.3+dfsg-1 MIGRATED to testing (Debian testing watch)
  • [2022-10-25] Accepted r-cran-jsonlite 1.8.3+dfsg-1 (source) into unstable (Andreas Tille)
  • [2022-10-11] r-cran-jsonlite 1.8.2+dfsg-1 MIGRATED to testing (Debian testing watch)
  • [2022-10-08] Accepted r-cran-jsonlite 1.8.2+dfsg-1 (source) into unstable (Andreas Tille)
  • [2022-03-12] r-cran-jsonlite 1.8.0+dfsg-1 MIGRATED to testing (Debian testing watch)
  • [2022-03-09] Accepted r-cran-jsonlite 1.8.0+dfsg-1 (source) into unstable (Andreas Tille)
  • [2022-01-25] r-cran-jsonlite 1.7.3+dfsg-1 MIGRATED to testing (Debian testing watch)
  • [2022-01-23] Accepted r-cran-jsonlite 1.7.3+dfsg-1 (source) into unstable (Nilesh Patra)
  • [2020-12-13] r-cran-jsonlite 1.7.2+dfsg-1 MIGRATED to testing (Debian testing watch)
  • [2020-12-10] Accepted r-cran-jsonlite 1.7.2+dfsg-1 (source) into unstable (Nilesh Patra)
  • [2020-09-23] r-cran-jsonlite 1.7.1+dfsg-1 MIGRATED to testing (Debian testing watch)
  • [2020-09-21] Accepted r-cran-jsonlite 1.7.1+dfsg-1 (source) into unstable (Andreas Tille)
  • [2020-07-03] r-cran-jsonlite 1.7.0+dfsg-1 MIGRATED to testing (Debian testing watch)
  • [2020-07-01] Accepted r-cran-jsonlite 1.7.0+dfsg-1 (source) into unstable (Dylan Aïssi)
  • [2020-02-13] r-cran-jsonlite 1.6.1+dfsg-1 MIGRATED to testing (Debian testing watch)
  • [2020-02-10] Accepted r-cran-jsonlite 1.6.1+dfsg-1 (source) into unstable (Dylan Aïssi)
  • 1
  • 2
bugs [bug history graph]
  • all: 1
  • RC: 0
  • I&N: 1
  • M&W: 0
  • F&P: 0
  • patch: 0
links
  • homepage
  • lintian (1, 0)
  • buildd: logs, reproducibility, cross
  • popcon
  • browse source code
  • edit tags
  • other distros
  • security tracker
  • screenshots
  • debci
ubuntu Ubuntu logo [Information about Ubuntu for Debian Developers]
  • version: 1.9.1+dfsg-1

Debian Package Tracker — Copyright 2013-2025 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing