[Buildroot] [PATCH] PHP: bump to 7.0.13

Vicente Olivert Riera Vincent.Riera at imgtec.com
Wed Nov 16 11:20:33 UTC 2016


Hi Gustavo,

On 16/11/16 11:12, Gustavo Zacarias wrote:
> On 16/11/16 06:38, Vincent Olivert Riera wrote:
> 
>> Hello Tatsuyuki,
>>
>> php has been already bumped to 7.0.13 in the next branch:
>>
>> https://git.busybox.net/buildroot/commit/?h=next&id=cd59cb6b388d00865d0084e6a25eb306c0b5fdd3
>>
>>
>> Is there any reason to bump it for master as well? If so, please tell
>> us and if the reason is valid a maintainer will cherry-pick the patch
>> from the next branch.
>>
>> Regards,
>>
>> Vincent.
> 
> Hi Vincent.
> It's a security release, you gotta read the ChangeLog more often:
> http://www.php.net/ChangeLog-7.php#7.0.13
> They usually don't wait for CVE assignments or ask for them after the
> release, hence no references in it.
> Sometimes looking at the oss-security mailing lists helps.

I remember I searched for "CVE" in the ChangeLog and there wasn't any
match, that's why I didn't specified it was a security update. They must
changed that page later in order to add the CVE references.

Vincent


> Regards.



More information about the buildroot mailing list