Debian Package Tracker
Register | Log in
Subscribe

symfony

Choose email to subscribe with

general
  • source: symfony (main)
  • version: 6.4.21+dfsg-2
  • maintainer: Debian PHP PEAR Maintainers (archive) (DMD)
  • uploaders: David Prévot [DMD] – Daniel Beyer [DMD]
  • arch: all
  • std-ver: 4.7.2
  • VCS: Git (Browse, QA)
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • o-o-stable: 3.4.22+dfsg-2+deb10u1
  • o-o-sec: 3.4.22+dfsg-2+deb10u3
  • oldstable: 4.4.19+dfsg-2+deb11u6
  • old-p-u: 4.4.19+dfsg-2+deb11u6
  • stable: 5.4.23+dfsg-1+deb12u4
  • stable-sec: 5.4.23+dfsg-1+deb12u4
  • testing: 6.4.20+dfsg-2
  • unstable: 6.4.21+dfsg-2
  • exp: 7.3.0~beta2+dfsg-1
versioned links
  • 3.4.22+dfsg-2+deb10u1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 3.4.22+dfsg-2+deb10u3: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 4.4.19+dfsg-2+deb11u6: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 5.4.23+dfsg-1+deb12u4: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 6.4.20+dfsg-2: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 6.4.21+dfsg-2: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 7.3.0~beta2+dfsg-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • php-symfony
  • php-symfony-all-my-sms-notifier
  • php-symfony-amazon-mailer
  • php-symfony-amazon-sns-notifier
  • php-symfony-amazon-sqs-messenger
  • php-symfony-amqp-messenger
  • php-symfony-asset
  • php-symfony-asset-mapper
  • php-symfony-bandwidth-notifier
  • php-symfony-beanstalkd-messenger
  • php-symfony-brevo-mailer
  • php-symfony-brevo-notifier
  • php-symfony-browser-kit
  • php-symfony-cache
  • php-symfony-chatwork-notifier
  • php-symfony-click-send-notifier
  • php-symfony-clickatell-notifier
  • php-symfony-clock
  • php-symfony-config
  • php-symfony-console
  • php-symfony-contact-everyone-notifier
  • php-symfony-crowdin-translation-provider
  • php-symfony-css-selector
  • php-symfony-debug-bundle
  • php-symfony-dependency-injection
  • php-symfony-discord-notifier
  • php-symfony-doctrine-bridge
  • php-symfony-doctrine-messenger
  • php-symfony-dom-crawler
  • php-symfony-dotenv
  • php-symfony-engagespot-notifier
  • php-symfony-error-handler
  • php-symfony-esendex-notifier
  • php-symfony-event-dispatcher
  • php-symfony-expo-notifier
  • php-symfony-expression-language
  • php-symfony-fake-chat-notifier
  • php-symfony-fake-sms-notifier
  • php-symfony-filesystem
  • php-symfony-finder
  • php-symfony-firebase-notifier
  • php-symfony-form
  • php-symfony-forty-six-elks-notifier
  • php-symfony-framework-bundle
  • php-symfony-free-mobile-notifier
  • php-symfony-gateway-api-notifier
  • php-symfony-gitter-notifier
  • php-symfony-go-ip-notifier
  • php-symfony-google-chat-notifier
  • php-symfony-google-mailer
  • php-symfony-html-sanitizer
  • php-symfony-http-client
  • php-symfony-http-foundation
  • php-symfony-http-kernel
  • php-symfony-infobip-mailer
  • php-symfony-infobip-notifier
  • php-symfony-intl
  • php-symfony-iqsms-notifier
  • php-symfony-isendpro-notifier
  • php-symfony-kaz-info-teh-notifier
  • php-symfony-ldap
  • php-symfony-light-sms-notifier
  • php-symfony-line-notify-notifier
  • php-symfony-linked-in-notifier
  • php-symfony-lock
  • php-symfony-loco-translation-provider
  • php-symfony-lokalise-translation-provider
  • php-symfony-mail-pace-mailer
  • php-symfony-mailchimp-mailer
  • php-symfony-mailer
  • php-symfony-mailer-send-mailer
  • php-symfony-mailgun-mailer
  • php-symfony-mailjet-mailer
  • php-symfony-mailjet-notifier
  • php-symfony-mastodon-notifier
  • php-symfony-mattermost-notifier
  • php-symfony-mercure-notifier
  • php-symfony-message-bird-notifier
  • php-symfony-message-media-notifier
  • php-symfony-messenger
  • php-symfony-microsoft-teams-notifier
  • php-symfony-mime
  • php-symfony-mobyt-notifier
  • php-symfony-monolog-bridge
  • php-symfony-notifier
  • php-symfony-novu-notifier
  • php-symfony-ntfy-notifier
  • php-symfony-octopush-notifier
  • php-symfony-oh-my-smtp-mailer
  • php-symfony-one-signal-notifier
  • php-symfony-options-resolver
  • php-symfony-orange-sms-notifier
  • php-symfony-ovh-cloud-notifier
  • php-symfony-pager-duty-notifier
  • php-symfony-password-hasher
  • php-symfony-phpunit-bridge
  • php-symfony-phrase-translation-provider
  • php-symfony-plivo-notifier
  • php-symfony-postmark-mailer
  • php-symfony-process
  • php-symfony-property-access
  • php-symfony-property-info
  • php-symfony-proxy-manager-bridge
  • php-symfony-psr-http-message-bridge
  • php-symfony-pushover-notifier
  • php-symfony-rate-limiter
  • php-symfony-redis-messenger
  • php-symfony-redlink-notifier
  • php-symfony-remote-event
  • php-symfony-ring-central-notifier
  • php-symfony-rocket-chat-notifier
  • php-symfony-routing
  • php-symfony-runtime
  • php-symfony-scaleway-mailer
  • php-symfony-scheduler
  • php-symfony-security-bundle
  • php-symfony-security-core
  • php-symfony-security-csrf
  • php-symfony-security-http
  • php-symfony-semaphore
  • php-symfony-sendberry-notifier
  • php-symfony-sendgrid-mailer
  • php-symfony-sendinblue-mailer
  • php-symfony-sendinblue-notifier
  • php-symfony-serializer
  • php-symfony-simple-textin-notifier
  • php-symfony-sinch-notifier
  • php-symfony-slack-notifier
  • php-symfony-sms-biuras-notifier
  • php-symfony-sms-factor-notifier
  • php-symfony-sms77-notifier
  • php-symfony-smsapi-notifier
  • php-symfony-smsc-notifier
  • php-symfony-smsmode-notifier
  • php-symfony-spot-hit-notifier
  • php-symfony-stopwatch
  • php-symfony-string
  • php-symfony-telegram-notifier
  • php-symfony-telnyx-notifier
  • php-symfony-templating
  • php-symfony-termii-notifier
  • php-symfony-translation
  • php-symfony-turbo-sms-notifier
  • php-symfony-twig-bridge
  • php-symfony-twig-bundle
  • php-symfony-twilio-notifier
  • php-symfony-twitter-notifier
  • php-symfony-uid
  • php-symfony-validator
  • php-symfony-var-dumper
  • php-symfony-var-exporter
  • php-symfony-vonage-notifier
  • php-symfony-web-link
  • php-symfony-web-profiler-bundle
  • php-symfony-webhook
  • php-symfony-workflow
  • php-symfony-yaml
  • php-symfony-yunpian-notifier
  • php-symfony-zendesk-notifier
  • php-symfony-zulip-notifier
action needed
5 security issues in bullseye high

There are 5 open security issues in bullseye.

5 important issues:
  • CVE-2024-50340: symfony/runtime is a module for the Symphony PHP framework which enables decoupling PHP applications from global state. When the `register_argv_argc` php directive is set to `on` , and users call any URL with a special crafted query string, they are able to change the environment or debug mode used by the kernel when handling the request. As of versions 5.4.46, 6.4.14, and 7.1.7 the `SymfonyRuntime` now ignores the `argv` values for non-SAPI PHP runtimes. All users are advised to upgrade. There are no known workarounds for this vulnerability.
  • CVE-2024-50342: symfony/http-client is a module for the Symphony PHP framework which provides powerful methods to fetch HTTP resources synchronously or asynchronously. When using the `NoPrivateNetworkHttpClient`, some internal information is still leaking during host resolution, which leads to possible IP/port enumeration. As of versions 5.4.46, 6.4.14, and 7.1.7 the `NoPrivateNetworkHttpClient` now filters blocked IPs earlier to prevent such leaks. All users are advised to upgrade. There are no known workarounds for this vulnerability.
  • CVE-2024-50343: symfony/validator is a module for the Symphony PHP framework which provides tools to validate values. It is possible to trick a `Validator` configured with a regular expression using the `$` metacharacters, with an input ending with `\n`. Symfony as of versions 5.4.43, 6.4.11, and 7.1.4 now uses the `D` regex modifier to match the entire input. Users are advised to upgrade. There are no known workarounds for this vulnerability.
  • CVE-2024-50345: symfony/http-foundation is a module for the Symphony PHP framework which defines an object-oriented layer for the HTTP specification. The `Request` class, does not parse URI with special characters the same way browsers do. As a result, an attacker can trick a validator relying on the `Request` class to redirect users to another domain. The `Request::create` methods now assert the URI does not contain invalid characters as defined by https://url.spec.whatwg.org/. This issue has been patched in versions 5.4.46, 6.4.14, and 7.1.7. Users are advised to upgrade. There are no known workarounds for this vulnerability.
  • CVE-2024-51996: Symphony process is a module for the Symphony PHP framework which executes commands in sub-processes. When consuming a persisted remember-me cookie, Symfony does not check if the username persisted in the database matches the username attached with the cookie, leading to authentication bypass. This vulnerability is fixed in 5.4.47, 6.4.15, and 7.1.8.
Created: 2024-11-07 Last update: 2025-05-05 09:30
Fails to build during reproducibility testing normal
A package building reproducibly enables third parties to verify that the source matches the distributed binaries. It has been identified that this source package produced different results, failed to build or had other issues in a test environment. Please read about how to improve the situation!
Created: 2024-09-29 Last update: 2025-05-15 04:05
1 new commit since last upload, is it time to release? normal
vcswatch reports that this package seems to have new commits in its VCS but has not yet updated debian/changelog. You should consider updating the Debian changelog and uploading this new version into the archive.

Here are the relevant commit logs:
commit 20e8cbc0f644b8d7a7df8fdde53e5ad344adc1e5
Author: David Prévot <david@tilapin.org>
Date:   Tue May 13 18:51:46 2025 +0200

    Use php-dba for debci
Created: 2025-05-13 Last update: 2025-05-13 22:03
lintian reports 5 warnings normal
Lintian reports 5 warnings about this package. You should make the package lintian clean getting rid of them.
Created: 2025-05-05 Last update: 2025-05-06 00:01
debian/patches: 36 patches to forward upstream low

Among the 41 debian patches available in version 6.4.21+dfsg-2 of the package, we noticed the following issues:

  • 36 patches where the metadata indicates that the patch has not yet been forwarded upstream. You should either forward the patch upstream or update the metadata to document its real status.
Created: 2023-02-26 Last update: 2025-05-05 14:33
Issues found with some translations low

Automatic checks made by the Debian l10n team found some issues with the translations contained in this package. You should check the l10n status report for more information.

Issues can be things such as missing translations, problematic translated strings, outdated PO files, unknown languages, etc.

Created: 2020-02-26 Last update: 2020-02-26 10:49
news
[rss feed]
  • [2025-05-15] symfony 6.4.21+dfsg-2 MIGRATED to testing (Debian testing watch)
  • [2025-05-12] Accepted symfony 7.3.0~beta2+dfsg-1 (source) into experimental (David Prévot)
  • [2025-05-05] Accepted symfony 7.3.0~beta1+dfsg-1 (source all) into experimental (Debian FTP Masters) (signed by: David Prévot)
  • [2025-05-05] Accepted symfony 6.4.21+dfsg-2 (source) into unstable (David Prévot)
  • [2025-05-02] Accepted symfony 7.2.6-1 (source) into experimental (David Prévot)
  • [2025-05-02] Accepted symfony 6.4.21+dfsg-1 (source) into unstable (David Prévot)
  • [2025-04-25] symfony 6.4.20+dfsg-2 MIGRATED to testing (Debian testing watch)
  • [2025-04-15] Accepted symfony 6.4.20+dfsg-2 (source) into unstable (David Prévot)
  • [2025-04-04] symfony 6.4.20+dfsg-1 MIGRATED to testing (Debian testing watch)
  • [2025-03-29] Accepted symfony 7.2.5+dfsg-1 (source all) into experimental (David Prévot)
  • [2025-03-29] Accepted symfony 6.4.20+dfsg-1 (source) into unstable (David Prévot)
  • [2025-03-27] symfony 6.4.19+dfsg-2 MIGRATED to testing (Debian testing watch)
  • [2025-03-24] Accepted symfony 6.4.19+dfsg-2 (source) into unstable (David Prévot)
  • [2025-03-03] symfony 6.4.19+dfsg-1 MIGRATED to testing (Debian testing watch)
  • [2025-02-28] Accepted symfony 6.4.19+dfsg-1 (source) into unstable (David Prévot)
  • [2025-02-28] Accepted symfony 7.2.4+dfsg-1 (source all) into experimental (David Prévot)
  • [2025-02-07] Accepted symfony 7.2.3+dfsg-1 (source all) into experimental (David Prévot)
  • [2025-02-01] symfony 6.4.18+dfsg-1 MIGRATED to testing (Debian testing watch)
  • [2025-01-29] Accepted symfony 6.4.18+dfsg-1 (source) into unstable (David Prévot)
  • [2025-01-17] symfony 6.4.17+dfsg-6 MIGRATED to testing (Debian testing watch)
  • [2025-01-14] Accepted symfony 6.4.17+dfsg-6 (source) into unstable (David Prévot)
  • [2025-01-14] Accepted symfony 6.4.17+dfsg-5 (source all) into unstable (David Prévot)
  • [2025-01-13] Accepted symfony 6.4.17+dfsg-4 (source) into unstable (David Prévot)
  • [2025-01-12] Accepted symfony 6.4.17+dfsg-3 (source) into unstable (David Prévot)
  • [2025-01-12] Accepted symfony 6.4.17+dfsg-2 (source) into unstable (David Prévot)
  • [2025-01-08] symfony 6.4.17+dfsg-1 MIGRATED to testing (Debian testing watch)
  • [2025-01-02] Accepted symfony 7.2.2+dfsg-1 (source all) into experimental (David Prévot)
  • [2025-01-02] Accepted symfony 6.4.17+dfsg-1 (source) into unstable (David Prévot)
  • [2024-12-26] symfony 6.4.16+dfsg-2 MIGRATED to testing (Debian testing watch)
  • [2024-12-23] Accepted symfony 6.4.16+dfsg-2 (source) into unstable (David Prévot)
  • 1
  • 2
bugs [bug history graph]
  • all: 4
  • RC: 0
  • I&N: 1
  • M&W: 3
  • F&P: 0
  • patch: 0
links
  • homepage
  • lintian (0, 5)
  • buildd: logs, exp, reproducibility
  • popcon
  • browse source code
  • edit tags
  • other distros
  • security tracker
  • l10n (-, 100)
  • debian patches
  • debci
ubuntu Ubuntu logo [Information about Ubuntu for Debian Developers]
  • version: 6.4.21+dfsg-2
  • 1 bug

Debian Package Tracker — Copyright 2013-2025 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing