Discover Centmin Mod today
Register Now

PHP git source repo compromise!

Discussion in 'Nginx and PHP-FPM news & discussions' started by eva2000, Mar 29, 2021.

Tags:
  1. eva2000

    eva2000 Administrator Staff Member

    58,916
    12,490
    113
    May 24, 2014
    Brisbane, Australia
    Ratings:
    +19,122
    Local Time:
    3:31 AM
    Nginx 1.31.x
    MariaDB 10.x/11.4+/12.3+
    Seems the official PHP git source repo server might have been compromised with unauthorized commits php.internals: Changes to Git commit workflow. They are now switching away from their own Git server and using Github mirror as the official Git repo at php/php-src



     
  2. buik

    buik “The best traveler is one without a camera.”

    2,044
    527
    113
    Apr 29, 2016
    Flanders
    Ratings:
    +1,691
    Local Time:
    7:31 PM
    Fortunately, no commits have been made in specific release branches, but in the master.:)

    Relatively harmless. Nice to see that the PHP team took immediate action!
     
  3. eva2000

    eva2000 Administrator Staff Member

    58,916
    12,490
    113
    May 24, 2014
    Brisbane, Australia
    Ratings:
    +19,122
    Local Time:
    3:31 AM
    Nginx 1.31.x
    MariaDB 10.x/11.4+/12.3+
    Indeed lucky! Happy to see them move to using Github repo as official version :D