From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from lists.gentoo.org (pigeon.gentoo.org [208.92.234.80]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits)) (No client certificate requested) by finch.gentoo.org (Postfix) with ESMTPS id E5990158083 for ; Fri, 13 Sep 2024 01:46:18 +0000 (UTC) Received: from pigeon.gentoo.org (localhost [127.0.0.1]) by pigeon.gentoo.org (Postfix) with SMTP id A4352E29AA; Fri, 13 Sep 2024 01:46:14 +0000 (UTC) Received: from ciao.gmane.io (ciao.gmane.io [116.202.254.214]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange ECDHE (prime256v1) server-signature RSA-PSS (4096 bits) server-digest SHA256) (No client certificate requested) by pigeon.gentoo.org (Postfix) with ESMTPS id 7C008E29A6 for ; Fri, 13 Sep 2024 01:46:14 +0000 (UTC) Received: from list by ciao.gmane.io with local (Exim 4.92) (envelope-from ) id 1sovO1-0007XK-7E for gentoo-dev@lists.gentoo.org; Fri, 13 Sep 2024 03:46:13 +0200 X-Injected-Via-Gmane: http://gmane.org/ To: gentoo-dev@lists.gentoo.org From: Duncan <1i5t5.duncan@cox.net> Subject: [gentoo-dev] Re: Last rites EAPI=6 packages: dev-php/* Date: Fri, 13 Sep 2024 01:46:08 -0000 (UTC) Message-ID: References: <5babde00-594b-42d6-aeec-9c2398e30a7f@uls.co.za> Precedence: bulk List-Post: List-Help: List-Unsubscribe: List-Subscribe: List-Id: Gentoo Linux mail X-BeenThere: gentoo-dev@lists.gentoo.org Reply-to: gentoo-dev@lists.gentoo.org X-Auto-Response-Suppress: DR, RN, NRN, OOF, AutoReply Mime-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit User-Agent: Pan/0.160 (Toresk; f2b262f0ddc28c343250f353027745bbd31e8915) X-Archives-Salt: a9bc44c6-1734-4d0a-b121-8f35306164be X-Archives-Hash: 07a10f263116d04cf3ce27e63e9dadda Jaco Kroon posted on Wed, 11 Sep 2024 09:33:10 +0200 as excerpted: > I missed this announcement, looking specifically for composer again. > > If I make the effort of bumping to newest version, is this something > that would be re-added to the tree? > > I note there were active security vulnerabilities under very specific > conditions (composer.phar is exposed via http). > > Or should I rather just deploy this into a local overlay? [Tree or local overlay?] You seem to have missed the obvious middle option, deploying to a public overlay. If there's many related packages (another reply mentioned a bunch of deps; not being a PHP person I wouldn't know...) that might most appropriately be a dedicated overlay. For single packages, particularly if there's likely to be others interested, the guru overlay seems to be quite popular as a middle ground, allowing multiple people to help without the full bureaucracy of the main tree. -- Duncan - List replies preferred. No HTML msgs. "Every nonfree program has a lord, a master -- and if you use the program, he is your master." Richard Stallman