Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Package Request] - Update PHP8.3 => 8.3.15 #887

Open
adnweedon opened this issue Jan 16, 2025 · 3 comments
Open

[Package Request] - Update PHP8.3 => 8.3.15 #887

adnweedon opened this issue Jan 16, 2025 · 3 comments
Labels
bug Something isn't working fixed-upstream Bug fix is present in an upstream tree/release packages Package request

Comments

@adnweedon
Copy link

What package is missing from Amazon Linux 2023? Please describe and include package name.
Please can PHP 8.3 be upgraded from 8.3.10 to 8.3.15, so we can benefit from 6 months worth of bug fixes and security patches.

Is this an update to existing package or new package request?
Update

Is this package available in Amazon Linux 2? If it is available via external sources such as EPEL, please specify.
I have no idea - I can't find a package list like I can for AL2023, sorry!

Any additional information you'd like to include. (use-cases, etc)
This brings in fixes for some CVEs, including two that have CVSS of 9.8:

@stewartsmith
Copy link
Member

For completeness, Amazon Linux 2023 is Not Affected by CVE-2024-11236, and we have evaluated CVE-2024-8932.html in the context of Amazon Linux (details at https://explore.alas.aws.amazon.com/CVE-2024-8932.html ). Notably, https://explore.alas.aws.amazon.com/CVE-2024-8932.html affects running 32-bit, of which AL2023 does not ship 32bit packages.

I'm keeping this issue open for a general PHP update though.

@stewartsmith stewartsmith added bug Something isn't working packages Package request fixed-upstream Bug fix is present in an upstream tree/release labels Jan 24, 2025
@gregnetau
Copy link

PHP 8.3.16 is now available.

I had similar "long-out-of-date" issues with PHP8.1 back on Amazon Linux 2 - and we seem to be back to this situation again.

The issue now is, I can't just go using EPEL and add 3rd party repositories like I did with Remi on AL2 - as they do not work in AL2023 - which means Amazon needs to increase their cadence of application updates for the N & N-1 versions of application frameworks that their vast majority of customers use on AWS.

@Fnu-Nishant
Copy link

Thanks for reaching out to us. We have opened work to update PHP. It will be available in future release, please keep an eye on release notes.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug Something isn't working fixed-upstream Bug fix is present in an upstream tree/release packages Package request
Projects
None yet
Development

No branches or pull requests

4 participants