Bug 1518716

Summary: [dokuwiki] package orphaned/unmaintained since 2015, automated CVE bugs got ignored
Product: [Fedora] Fedora Reporter: Pascal Ernster <pascal.ernster+bugzilla.redhat.com>
Component: dokuwikiAssignee: Andrew Colin Kissa <andrew>
Status: CLOSED RAWHIDE QA Contact: Fedora Extras Quality Assurance <extras-qa>
Severity: urgent Docs Contact:
Priority: unspecified    
Version: 28CC: andrewniemants, andrew, fedora, mvermaes, pessoft, vonsch
Target Milestone: ---   
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2018-08-26 20:18:36 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description Pascal Ernster 2017-11-29 13:57:51 UTC
All Fedora releases from 25 up to Rawhide ship dokuwiki 20150810a, which contains a bunch of security vulnerabilites:

https://www.dokuwiki.org/changes

https://src.fedoraproject.org/cgit/rpms/dokuwiki.git/log/


There's also been a bunch of (automated) bugs about some of there vulnerabilites, but it seems those have been ignored, and the package is actually unmaintained / de facto orphaned:

https://bugzilla.redhat.com/buglist.cgi?bug_status=__open__&content=dokuwiki&list_id=8166066

Comment 1 Fedora End Of Life 2018-02-20 15:33:11 UTC
This bug appears to have been reported against 'rawhide' during the Fedora 28 development cycle.
Changing version to '28'.

Comment 2 Artur Frenszek-Iwicki 2018-08-26 20:18:36 UTC
The package was updated to latest upstream version (2018-04-22a) and built for Rawhide and F29:
https://koji.fedoraproject.org/koji/buildinfo?buildID=1139333
https://koji.fedoraproject.org/koji/buildinfo?buildID=1139334

Successful builds have also been done for F28 and F27:
https://koji.fedoraproject.org/koji/buildinfo?buildID=1139337
https://koji.fedoraproject.org/koji/buildinfo?buildID=1139339
I'm wondering whether these should be pushed as updates, or not. On one hand, there's the risk of breaking changes, on the other - the package has security flaws, so not updating it leaves its users vulnerable to potential attacks.