mediawiki (1:1.39.13-1~deb12u1) bookworm-security; urgency=medium * New upstream version 1.39.13, fixing CVE-2025-6590, CVE-2025-6591, CVE-2025-6593, CVE-2025-6594, CVE-2025-6597, CVE-2025-32072. -- Taavi Väänänen <taavi@debian.org> Tue, 01 Jul 2025 19:31:26 +0300 mediawiki (1:1.39.12-1~deb12u1) bookworm-security; urgency=medium [ Kunal Mehta ] * Update gbp.conf to use upstream-1.39 branch * New upstream version 1.39.12, fixing CVE-2025-3469, CVE-2025-32696, CVE-2025-32697, CVE-2025-32698, CVE-2025-32699, CVE-2025-32700. [ Taavi Väänänen ] * Stop changing permissions for files that no longer exist -- Kunal Mehta <legoktm@debian.org> Fri, 11 Apr 2025 00:01:01 -0400 mediawiki (1:1.39.10-1~deb12u1) bookworm-security; urgency=medium * New upstream version 1.39.10, fixing T372998 (AbuseFilter API not properly checking permissions, CVE-2024-47913). -- Taavi Väänänen <taavi@debian.org> Wed, 02 Oct 2024 17:44:10 +0300 mediawiki (1:1.39.7-1~deb12u1) bookworm-security; urgency=medium * New upstream version 1.39.7, fixing CVE-2023-51704, T355538 (XSS in edit summary parser, CVE-2024-34507) and T357760 (DoS in Special:MovePage, CVE-2024-34506). -- Taavi Väänänen <hi@taavi.wtf> Fri, 29 Mar 2024 13:51:27 +0200 mediawiki (1:1.39.5-1~deb12u1) bookworm-security; urgency=medium * New upstream version 1.39.5, fixing CVE-2023-3550, CVE-2023-45359, CVE-2023-45360, CVE-2023-45361, CVE-2023-45362, CVE-2023-45363, CVE-2023-45364. -- Kunal Mehta <legoktm@debian.org> Mon, 09 Oct 2023 14:34:13 -0400 mediawiki (1:1.39.4-1~deb12u1) bookworm-security; urgency=medium [ Taavi Väänänen ] * New upstream version 1.39.4, fixing CVE-2023-29141, CVE-2023-36674 and CVE-2023-36675. * The bundled guzzlehttp/guzzle library was updated to 2.4.5 to fix CVE-2023-29197. * Update config for the bookworm branch. [ Kunal Mehta ] * Set Breaks/Replaces for mediawiki-extensions-math (Closes: #1039075) -- Kunal Mehta <legoktm@debian.org> Tue, 04 Jul 2023 15:19:28 -0400 mediawiki (1:1.39.2-1) unstable; urgency=medium * New upstream version 1.39.2 * d/control: Raise minimum PHP version to 7.4 -- Taavi Väänänen <hi@taavi.wtf> Thu, 23 Feb 2023 15:13:02 +0200 mediawiki (1:1.39.1-2) unstable; urgency=medium * d/copyright: Remove stale entry for vendor/wikimedia/dodo/* * d/rules: Raise Standards-Version to 4.6.2, no changes needed * d/control: Add a Breaks: for old GreyStuff versions -- Taavi Väänänen <hi@taavi.wtf> Tue, 27 Dec 2022 12:34:25 +0200 mediawiki (1:1.39.1-1) unstable; urgency=medium * New upstream version 1.39.1 -- Taavi Väänänen <hi@taavi.wtf> Fri, 23 Dec 2022 12:09:19 +0200 mediawiki (1:1.39.0-2) unstable; urgency=medium * Cherry-pick upstream patch to fix 32-bit issues in wikimedia/idle-dom -- Kunal Mehta <legoktm@debian.org> Sun, 11 Dec 2022 20:10:05 -0500 mediawiki (1:1.39.0-1) unstable; urgency=medium * New upstream version 1.39.0 -- Taavi Väänänen <hi@taavi.wtf> Sun, 04 Dec 2022 22:20:45 +0200 mediawiki (1:1.39.0~rc.1-1) experimental; urgency=medium * New upstream version 1.39.0~rc.1 * Drop patch merged upstream -- Kunal Mehta <legoktm@debian.org> Sun, 16 Oct 2022 16:34:30 -0400 mediawiki (1:1.39.0~rc.0-1) experimental; urgency=medium [ Taavi Väänänen ] * New upstream version 1.39.0~rc.0 * Update packaging for 1.39 changes * php-intl is now required * Add patch to drop symfony/php73-polyfill dependency * Standards-Version: 4.6.1, no changes needed [ Kunal Mehta ] * Have SyntaxHighlight use packaged pygmentize, rather than bundled * Promote imagemagick to Recommends, remove from Suggests -- Kunal Mehta <legoktm@debian.org> Sun, 25 Sep 2022 19:32:19 -0400 mediawiki (1:1.35.7-1) unstable; urgency=medium [ Taavi Väänänen ] * New upstream release 1.35.7, fixing CVE-2022-27776 and CVE-2022-29248 in the embedded guzzlehttp/guzzle library. [ Kunal Mehta ] * Officially switch to team maintenance, add Taavi to uploaders -- Kunal Mehta <legoktm@debian.org> Sun, 03 Jul 2022 11:14:52 -0700 mediawiki (1:1.35.6-1) unstable; urgency=medium * Team upload. * New upstream version 1.35.6, fixing CVE-2022-28201, CVE-2022-28202, CVE-2022-28203. This version is not affected by CVE-2022-28204. * Update php extension recommends from composer.json -- Taavi Väänänen <hi@taavi.wtf> Fri, 01 Apr 2022 16:49:04 +0300 mediawiki (1:1.35.5-2) unstable; urgency=medium [ Lucas Werkmeister ] * Remove PHP 5 support from mediawiki.conf [ Kunal Mehta ] * Make it easier to debug autopkgtest failures * Increase PHP's max_execution_time for autopkgtests to 300s, thanks to Paul Gevers and Bryce Harrington for input and helping test. -- Kunal Mehta <legoktm@debian.org> Thu, 27 Jan 2022 00:46:22 -0800 mediawiki (1:1.35.5-1) unstable; urgency=high [ Kunal Mehta ] * New upstream version 1.35.5, fixing CVE-2021-44854, CVE-2021-44855, CVE-2021-44856, CVE-2021-44857, CVE-2021-44858, CVE-2021-45038. [ Debian Janitor ] * Remove constraints unnecessary since buster -- Kunal Mehta <legoktm@debian.org> Thu, 30 Sep 2021 20:42:36 -0700 mediawiki (1:1.35.4-1) unstable; urgency=medium * New upstream version 1.35.4, fixing CVE-2021-41798, CVE-2021-41799, CVE-2021-41800, CVE-2021-41801. -- Kunal Mehta <legoktm@debian.org> Thu, 30 Sep 2021 10:49:49 -0700 mediawiki (1:1.35.3-1) unstable; urgency=medium [ Kunal Mehta ] * New upstream version 1.35.3, fixing CVE-2021-35197. [ Tobias Wiese ] * d/tests: update test restrictions (Closes: #987976) * d/tests: Add systemd as test dependency -- Kunal Mehta <legoktm@debian.org> Fri, 20 Aug 2021 23:56:23 -0700 mediawiki (1:1.35.2-1) unstable; urgency=high * New upstream version 1.35.2, fixing CVE-2021-30152, CVE-2021-30153, CVE-2021-30154, CVE-2021-30155, CVE-2021-30157, CVE-2021-30158, CVE-2021-30159, CVE-2021-30458. * Bundled pygments was updated to fix CVE-2021-20270, CVE-2021-27291. -- Kunal Mehta <legoktm@debian.org> Thu, 08 Apr 2021 13:41:18 -0700 mediawiki (1:1.35.1-2) unstable; urgency=medium * Make it easier to install for use with SQLite (Closes: #979686) -- Kunal Mehta <legoktm@debian.org> Wed, 03 Feb 2021 15:01:01 -0800 mediawiki (1:1.35.1-1) unstable; urgency=medium * New upstream version 1.35.1, fixing CVE-2020-35474, CVE-2020-35475, CVE-2020-35477, CVE-2020-35478, CVE-2020-35479, CVE-2020-35480. * Respect $wgRedirectOnLogin configuration setting (Closes: #971986). * Flatten footer links without triggering a PHP warning (Closes: #971985). * Drop patches merged upstream -- Kunal Mehta <legoktm@debian.org> Thu, 17 Dec 2020 17:53:57 -0800 mediawiki (1:1.35.0-2) unstable; urgency=medium * Refactor autopkgtests to make easier to reuse * Fixup lintian overrides * d/watch: Switch to version=4 * Add patches for PHP 8.0 and newer Postgres compatibility * Standards-Version: 4.5.1, no changes needed -- Kunal Mehta <legoktm@debian.org> Mon, 14 Dec 2020 10:56:11 -0800 mediawiki (1:1.35.0-1) unstable; urgency=medium * Upload to unstable. * New upstream version 1.35.0, fixing CVE-2020-25812, CVE-2020-25813, CVE-2020-25814, CVE-2020-25815, CVE-2020-25827, CVE-2020-25828. * Additionally, mitigations for firejail's CVE-2020-17367, CVE-2020-17368 are included as well. * Require PHP 7.3+ (thanks to Platonides for the suggestion). -- Kunal Mehta <legoktm@debian.org> Sun, 27 Sep 2020 04:16:53 -0700 mediawiki (1:1.35.0~rc.3-1) experimental; urgency=medium * New upstream version 1.35.0~rc.3 -- Kunal Mehta <legoktm@debian.org> Sat, 05 Sep 2020 02:48:24 -0700 mediawiki (1:1.35.0~rc.2-1) experimental; urgency=medium * New upstream version 1.35.0~rc.2 * Avoid installing more sets of PHPUnit tests * Don't have logrotate create files as root:adm * Recommend php-gmp for a performance boost -- Kunal Mehta <legoktm@debian.org> Fri, 21 Aug 2020 23:49:28 -0700 mediawiki (1:1.35.0~rc.1-1) experimental; urgency=medium * New upstream version 1.35.0~rc.1 * Drop legacy /etc/mediawiki-extensions/extensions-available/ directory * Log errors, exceptions and fatals by default * Stop installing legacy /etc/mediawiki/mediawiki.conf * Use mime.types provided by MediaWiki (Closes: #903876) * Set $wgCacheDirectory = '/var/cache/mediawiki' by default -- Kunal Mehta <legoktm@debian.org> Fri, 07 Aug 2020 14:50:37 -0700 mediawiki (1:1.35.0~rc.0-1) experimental; urgency=medium * New upstream version 1.35.0~rc.0 * Recommend php-luasandbox/lua5.1 for the Scribunto extension * Includes Parsoid library (Closes: #831424) * Switch to debhelper compat 13 * Fix autopkgtests by using a "stronger" password and explicitly passing --scriptpath to the installer. -- Kunal Mehta <legoktm@debian.org> Sat, 01 Aug 2020 01:40:37 -0700 mediawiki (1:1.31.8-1) unstable; urgency=medium * New upstream version 1.31.8, fixing CVE-2020-15005. * Use debhelper 12 and dh_installsystemd. -- Kunal Mehta <legoktm@debian.org> Wed, 24 Jun 2020 14:25:22 -0700 mediawiki (1:1.31.7-1) unstable; urgency=medium * New upstream version 1.31.7, fixing CVE-2020-10960. CVE-2020-10959 does not affect this version of MediaWiki. * A hardening fix was included for the OATHAuth extension to limit access of user-controlled JavaScript. * Standards-Version: 4.5.0, no changes needed -- Kunal Mehta <legoktm@debian.org> Thu, 26 Mar 2020 15:30:16 -0700 mediawiki (1:1.31.6-1) unstable; urgency=medium * New upstream version 1.31.6, fixing CVE-2019-19709. * Drop Postgres patches merged upstream * Suppress a bunch of lintian warnings that are ignored on purpose * Sync d/upstream/signing-key.asc with upstream * autopkgtests: set allow-stderr for all tests that use sudo. Thanks to Mathieu Trudel-Lapierre for reporting and fixing in Ubuntu. (Closes: #946665) -- Kunal Mehta <legoktm@debian.org> Thu, 19 Dec 2019 13:20:56 -0800 mediawiki (1:1.31.5-3) unstable; urgency=medium * In autopkgtests, skip testing against mysql-server if it isn't available, such as in Debian testing * Move packaging git repository to Salsa and update relevant documentation * Set up and configure Salsa CI * Sync d/upstream/signing-key.asc with upstream -- Kunal Mehta <legoktm@debian.org> Mon, 25 Nov 2019 00:59:49 -0800 mediawiki (1:1.31.5-2) unstable; urgency=medium * Add extra debugging information to autopkgtests * Backport patches from upstream for Postgresql 12 compatibility (Closes: #944650) -- Kunal Mehta <legoktm@debian.org> Fri, 15 Nov 2019 15:28:16 -0800 mediawiki (1:1.31.5-1) unstable; urgency=medium * New upstream version 1.31.5 * Incorporate MySQL autopkgtest improvements from Lars Tangvald and Robie Basak from Ubuntu: * Use a different method besides MySQL 8.0's default authentication because PHP doesn't currently support it. * Explicitly test MySQL and MariaDB regardless of which one is the default. * Standards-Version: 4.4.1, no changes needed -- Kunal Mehta <legoktm@debian.org> Sat, 26 Oct 2019 18:01:59 -0700 mediawiki (1:1.31.4-1) unstable; urgency=medium * New upstream version 1.31.4 (security release), fixing CVE-2019-16738. -- Kunal Mehta <legoktm@debian.org> Fri, 11 Oct 2019 14:47:07 -0700 # Older entries have been removed from this changelog. # To read the complete changelog use `apt changelog mediawiki`.
Generated by dwww version 1.15 on Fri Aug 29 21:29:20 CEST 2025.