| 20 Feb 2023 |
@etu:failar.nu | I think that for phpunit it may matter which version of PHP you run it with | 09:55:38 |
@etu:failar.nu | And then it should be below php-packages so you can select version | 09:55:53 |
Pol | I don't think the same, maybe we should discuss that in the thread then? WDYT ? | 10:03:57 |
Pol | I think we shouldn't take care of the PHP version here and always use the latest. | 10:04:15 |
Pol | In reply to @etu:failar.nu I think that for phpunit it may matter which version of PHP you run it with I could also ask Sebastian (phpunit's father) about that. We could also check how they do in other distro? | 10:06:46 |
@etu:failar.nu | I think most people install it with composer | 10:19:07 |
@etu:failar.nu | Then you have all the right things in place | 10:19:15 |
@etu:failar.nu | I'm pretty confident that phpunit evaluates PHP with the version of PHP as you run PHP unit with. | 10:19:54 |
@etu:failar.nu | So if you have phpunit built on php81 running against a codebase that requires php82 features... you'll have a bad time. | 10:20:26 |
Pol | We really need to try then | 10:21:02 |
Pol | Or ask Sebastian? | 10:21:15 |
@etu:failar.nu | Sure, do it either way, then there were also a comment on the PR that is good | 10:21:42 |
@etu:failar.nu | * Sure, do it either way, then there were also a comment on the PR that is good to consider | 10:21:59 |
Pol | Which one? | 10:42:23 |
| 23 Feb 2023 |
| void joined the room. | 13:23:59 |
void | https://bugs.php.net/bug.php?id=81744 | 13:24:11 |
void | hexa ^^^ | 13:24:24 |
hexa | cc Pol etu tgerbet | 13:25:13 |
void | * https://bugs.php.net/bug.php?id=81744 https://github.com/php/php-src/security/advisories/GHSA-7fj2-8x79-rjf4 | 13:26:52 |
@etu:failar.nu |  Download image.png | 13:27:29 |
tgerbet | Will took a look | 13:27:40 |
@etu:failar.nu | Seems like we should be covered: https://github.com/php/php-src/security/advisories/GHSA-7fj2-8x79-rjf4 | 13:27:45 |
tgerbet | * https://github.com/NixOS/nixpkgs/pull/216348 | 13:27:50 |
tgerbet | Yep it was part of the last round of upgrades | 13:28:06 |
tgerbet | It's also fixed on stable | 13:28:33 |
Pol | I noticed that ryantm-bot does not do any updates for PHP packages. Look at composer, he hasn't been updated since last december... what can we do against that? | 13:28:50 |
Pol | In reply to @void68:matrix.org https://bugs.php.net/bug.php?id=81744 https://github.com/php/php-src/security/advisories/GHSA-7fj2-8x79-rjf4 We are faster than the security advisories :D | 13:35:33 |
void | In reply to @drupol:matrix.org We are faster than the security advisories :D glad you are ;) | 13:39:40 |
tgerbet | In reply to @drupol:matrix.org I noticed that ryantm-bot does not do any updates for PHP packages. Look at composer, he hasn't been updated since last december... what can we do against that? From the look of it, it is because the attr path deducted from the package name on Repology is not correct
https://r.ryantm.com/log/php-composer/2023-02-18.log
| 21:42:34 |
Pol | Ho nice finding ! | 21:43:14 |