• Bug#1065067: bookworm-pu: package php-doctrine-lexer/2.1.0-2+deb12u1

    From David =?UTF-8?Q?Pr=C3=A9vot?=@21:1/5 to All on Thu Feb 29 12:20:02 2024
    XPost: linux.debian.devel.release

    --ZEeAKNCWkSqYrjXI
    Content-Type: text/plain; charset=utf-8
    Content-Disposition: inline
    Content-Transfer-Encoding: quoted-printable

    Package: release.debian.org
    Severity: normal
    Tags: bookworm
    X-Debbugs-Cc: php-doctrine-lexer@packages.debian.org, team@security.debian.org Control: affects -1 + src:php-doctrine-lexer
    User: release.debian.org@packages.debian.org
    Usertags: pu

    [8/9 for bookworm]

    This is a follow up from composer/DSA-5632-1.

    In order to fix a Debian-specific issue related to CVE-2024-24821, we
    agreed with the security team to push related dependencies via the next
    point release.

    The only change (besides changelog entry) in the binary package is the following (thanks to diffoscope).

    │ │ ├── ./usr/share/php/Doctrine/Common/Lexer/autoload.php
    │ │ │ @@ -1,11 +1,11 @@
    │ │ │ <?php
    │ │ │
    │ │ │ // Require
    │ │ │ -require_once 'Doctrine/Deprecations/autoload.php';
    │ │ │ +require_once __DIR__ . '/../../Deprecations/autoload.php';
    │ │ │
    │ │ │ // Suggest

    The goal is to ensure related dependencies are loaded from the system
    path.

    The attached debdiff is a bit bigger, since it aims at keeping the
    testsuite at buildtime effective.

    [ Checklist ]
    [x] *all* changes are documented in the d/changelog
    [x] I reviewed all changes and I approve them
    [x] attach debdiff against the package in (old)stable
    [x] the issue is verified as fixed in unstable

    TIA for considering.

    Cheers,

    taffit

    --ZEeAKNCWkSqYrjXI
    Content-Type: text/x-diff; charset=iso-8859-1
    Content-Disposition: attachment;
    filename="php-doctrine-lexer_2.1.0-2+deb12u1.patch" Content-Transfer-Encoding: quoted-printable

    diff -Nru php-doctrine-lexer-2.1.0/debian/autoload.php.tpl php-doctrine-lexer-2.1.0/debian/autoload.php.tpl
    --- php-doctrine-lexer-2.1.0/debian/autoload.php.tpl 1970-01-01 01:00:00.000000000 +0100
    +++ php-doctrine-lexer-2.1.0/debian/autoload.php.tpl 2024-02-15 23:22:05.000000000 +0100
    @@ -0,0 +1,29 @@
    +<?php
    +
    +// Require
    +require_once __DIR__ . '/../../Deprecations/autoload.php';
    +
    +// Suggest
    +
    +// @codingStandardsIgnoreFile
    +// @codeCoverageIgnoreStart
    +// this is an autogenerated file - do not edit
    +spl_autoload_register(
    + function($class) {
    + static $classes = null;
    + if ($classes === null) {
    + $classes = array(
    + ___CLASSLIST___
    + );
    + }
    + $cn = strtolower($class);
    + if (isset($classes[$cn])) {
    + require ___BASEDIR___$classes[$cn];
    + }
    + },
    + ___EXCEPTION___,
    + ___PREPEND___
    +);
    +// @codeCoverageIgnoreEnd
    +
    +// Files
    diff -Nru php-doctrine-lexer-2.1.0/debian/changelog php-doctrine-lexer-2.1.0/debian/changelog
    --- php-doctrine-lexer-2.1.0/debian/changelog 2023-01-01 10:13:59.0
  • From Adam D. Barratt@21:1/5 to All on Mon Mar 25 20:00:03 2024
    XPost: linux.debian.devel.release

    Control: tags -1 + confirmed

    On Thu, 2024-02-29 at 12:08 +0100, David Prévot wrote:
    This is a follow up from composer/DSA-5632-1.

    In order to fix a Debian-specific issue related to CVE-2024-24821, we
    agreed with the security team to push related dependencies via the
    next
    point release.

    Again the branch name probably wants adjusting.

    Please go ahead.

    Regards,

    Adam

    --- SoupGate-Win32 v1.05
    * Origin: fsxNet Usenet Gateway (21:1/5)
  • From Jonathan Wiltshire@21:1/5 to All on Thu Mar 28 18:40:02 2024
    XPost: linux.debian.devel.release

    package release.debian.org
    tags 1065067 = bookworm pending
    thanks

    Hi,

    The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian bookworm.

    Thanks for your contribution!

    Upload details
    ==============

    Package: php-doctrine-lexer
    Version: 2.1.0-2+deb12u1

    Explanation: force system dependency loading

    --- SoupGate-Win32 v1.05
    * Origin: fsxNet Usenet Gateway (21:1/5)