-
-
Notifications
You must be signed in to change notification settings - Fork 14.2k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
wordpress: 5.4.2 -> 5.5.1 #98302
wordpress: 5.4.2 -> 5.5.1 #98302
Conversation
This package badly needs a maintainer. @basvandijk does not maintain anymore, so it is effectively orphaned. If someone doesn't step up during the Any volunteers? 😆 |
@dasJ how about it? |
@aanderse I started working on Wordpress in #96910 but I'm still pretty new to NixOS. So I would probably be fine to be a maintainer but I can't guarantee that this will improve the current situation. I will probably update my PR tomorrow btw. Also what are your issues with the wordpress package currently? |
@mohe2015 the issue is just having someone stay on top of security updates/releases from upstream, making sure to backport when appropriate. Without an active maintainer it feels irresponsible to ship web based software with known CVEs. It isn't a huge job or anything... we just need one or more people to step up and be willing to create/review/test the PRs. If you're interested that is great. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Thanks @ajs124 🎉 Does this need a backport to 20.09
and 20.03
? Any security vulnerabilities patched here?
I can add myself as a maintainer, we run probably a dozen or so WordPress instances on NixOS. We don't use the module etc from nixpkgs though, as far as I remember. |
@ajs124 "The only current officially supported version is WordPress 5.5.1. Previous major releases before this may or may not get security updates as serious exploits are discovered." https://codex.wordpress.org/Supported_Versions |
Thanks for mentioning @mohe2015. If someone could open backport PRs it would be much appreciated. |
I opened a backport to 20.09 in #99388, 20.03 is on 5.4.3, which was never on master. We could still backport, but there aren't any CVEs (I think), just a general policy of "we probably closed some security issues". |
I agree but for safety I would personally prefer a backport also for 20.03. (I can do it if you don't want to @ajs124 ) |
Motivation for this change
Things done
sandbox
innix.conf
on non-NixOS linux)nix-shell -p nixpkgs-review --run "nixpkgs-review wip"
./result/bin/
)nix path-info -S
before and after)