[pkg-php-pear] Bug#1065056: bookworm-pu: package php-composer-class-map-generator/1.0.0-2+deb12u1

David Prévot taffit at debian.org
Thu Feb 29 10:10:40 GMT 2024


Package: release.debian.org
Severity: normal
Tags: bookworm
X-Debbugs-Cc: php-composer-class-map-generator at packages.debian.org, team at security.debian.org
Control: affects -1 + src:php-composer-class-map-generator
User: release.debian.org at packages.debian.org
Usertags: pu

[1/9 for bookworm]

This is a follow up from composer/DSA-5632-1.

In order to fix a Debian-specific issue related to CVE-2024-24821, we
agreed with the security team to push related dependencies via the next
point release.

The only change (besides changelog entry) in the binary package is the
following (thanks to diffoscope).

│ │ ├── ./usr/share/php/Composer/ClassMapGenerator/autoload.php
│ │ │ @@ -1,12 +1,12 @@
│ │ │  <?php
│ │ │
│ │ │  // Require
│ │ │ -require_once 'Composer/Pcre/autoload.php';
│ │ │ -require_once 'Symfony/Component/Finder/autoload.php';
│ │ │ +require_once __DIR__ . '/../Pcre/autoload.php';
│ │ │ +require_once __DIR__ . '/../../Symfony/Component/Finder/autoload.php';
│ │ │
│ │ │  // Suggest

The goal is to ensure related dependencies are loaded from the system
path.

The attached debdiff is a bit bigger, since it aims at keeping the
testsuite at buildtime effective.

[ Checklist ]
  [x] *all* changes are documented in the d/changelog
  [x] I reviewed all changes and I approve them
  [x] attach debdiff against the package in (old)stable
  [x] the issue is verified as fixed in unstable

TIA for considering.

Cheers,

taffit
-------------- next part --------------
A non-text attachment was scrubbed...
Name: php-composer-class-map-generator_1.0.0-2+deb12u1.patch
Type: text/x-diff
Size: 4160 bytes
Desc: not available
URL: <http://alioth-lists.debian.net/pipermail/pkg-php-pear/attachments/20240229/f698b1dc/attachment-0001.patch>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 488 bytes
Desc: not available
URL: <http://alioth-lists.debian.net/pipermail/pkg-php-pear/attachments/20240229/f698b1dc/attachment-0001.sig>


More information about the pkg-php-pear mailing list