Compare commits

..

4 commits

Author SHA1 Message Date
434db551fa update to 3.7.1 (bugfixes)
(cherry picked from commit 64afcf22fe)
2013-10-30 08:11:40 +01:00
c533749740 clean
(cherry picked from commit 18130dfcb7)
2013-10-25 15:08:20 +02:00
248e56dc46 - update to 3.7
- requires ca-certificates for ca-bundle.crt
2013-10-25 14:51:59 +02:00
Paul Wouters
359196afe0 * Thu Sep 12 2013 Paul Wouters <pwouters@redhat.com> - 3.6.1-1
- update to 3.6.1, various bugs and security fixes:
  CVE-2013-4338 CVE-2013-4339 CVE-2013-4340
2013-09-11 22:09:27 -04:00
17 changed files with 227 additions and 975 deletions

4
.gitignore vendored
View file

@ -1,2 +1,4 @@
*spec~
clog
/wordpress-*.tar.gz
/wordpress-3.7.tar.gz
/wordpress-3.7.1.tar.gz

View file

@ -1,5 +1,3 @@
-------------------------------------------------------------------------------
Wordpress is a database driven blogging program designed to make it exceedingly
easy to publish an online blog, sometimes also called a weblog or journal.
@ -46,8 +44,6 @@ open a web browser to http://localhost/wordpress/wp-admin/install.php and
follow the instructions given to you on the pages you see to set up the
database tables and begin publishing your blog.
-------------------------------------------------------------------------------
Wordpress ships with Flash and Silverlight plugins for the 'plupload' file
uploader and the 'mediaelement' media player embedder. The idea is to try and
be able to provide a multi-file uploader and an embedded video player when
@ -68,19 +64,3 @@ b) If you try to embed media into a Wordpress post using the [video] and
a browser that has HTML5 support for the media format in question; if not, the
'Download Media' link will be offered. No Flash or Silverlight-based player
element will be included.
-------------------------------------------------------------------------------
Optional dependencies:
You may wish to install the following packages:
php-pecl-imagick: optimize image transformation
php-pecl-ssh2: for file transfert using ssh
An opcode cache is also recommended:
php 5.5: php-opcache
php 5.4: php-pecl-zendopcache
php 5.3: php-pecl-apc
-------------------------------------------------------------------------------

View file

@ -1 +1 @@
SHA512 (wordpress-7.1.tar.gz) = 4bb95bddeb0d30778b9d744e42f7e21507ed3070fda3e34dd41918073618181e350cf77ea8dfaacc48c59a00f50273b4a1b7a6e4c43d2a81ccfd35f27df342bc
8af9a4885ad134d354eb5f12dcc17fd9 wordpress-3.7.1.tar.gz

View file

@ -0,0 +1,11 @@
--- wordpress/wp-includes/js/mediaelement/mediaelement-and-player.min.js 2013-08-01 06:47:23.000000000 -0700
+++ wordpress/wp-includes/js/mediaelement/mediaelement-and-player.min.js.new 2013-08-23 16:02:01.491295485 -0700
@@ -37,7 +37,7 @@
this.attributes},removeAttribute:function(a){delete this.attributes[a]},getAttribute:function(a){if(this.hasAttribute(a))return this.attributes[a];return""},setAttribute:function(a,b){this.attributes[a]=b},remove:function(){mejs.Utility.removeSwf(this.pluginElement.id);mejs.MediaPluginBridge.unregisterPluginElement(this.pluginElement.id)}};
mejs.MediaPluginBridge={pluginMediaElements:{},htmlMediaElements:{},registerPluginElement:function(a,b,c){this.pluginMediaElements[a]=b;this.htmlMediaElements[a]=c},unregisterPluginElement:function(a){delete this.pluginMediaElements[a];delete this.htmlMediaElements[a]},initPlugin:function(a){var b=this.pluginMediaElements[a],c=this.htmlMediaElements[a];if(b){switch(b.pluginType){case "flash":b.pluginElement=b.pluginApi=document.getElementById(a);break;case "silverlight":b.pluginElement=document.getElementById(b.id);
b.pluginApi=b.pluginElement.Content.MediaElementJS}b.pluginApi!=null&&b.success&&b.success(b,c)}},fireEvent:function(a,b,c){var d,e;if(a=this.pluginMediaElements[a]){b={type:b,target:a};for(d in c){a[d]=c[d];b[d]=c[d]}e=c.bufferedTime||0;b.target.buffered=b.buffered={start:function(){return 0},end:function(){return e},length:1};a.dispatchEvent(b.type,b)}}};
-mejs.MediaElementDefaults={mode:"auto",plugins:["flash","silverlight","youtube","vimeo"],enablePluginDebug:false,httpsBasicAuthSite:false,type:"",pluginPath:mejs.Utility.getScriptPath(["mediaelement.js","mediaelement.min.js","mediaelement-and-player.js","mediaelement-and-player.min.js"]),flashName:"flashmediaelement.swf",flashStreamer:"",enablePluginSmoothing:false,enablePseudoStreaming:false,pseudoStreamingStartQueryParam:"start",silverlightName:"silverlightmediaelement.xap",defaultVideoWidth:480,
+mejs.MediaElementDefaults={mode:"auto",plugins:["youtube","vimeo"],enablePluginDebug:false,httpsBasicAuthSite:false,type:"",pluginPath:mejs.Utility.getScriptPath(["mediaelement.js","mediaelement.min.js","mediaelement-and-player.js","mediaelement-and-player.min.js"]),flashName:"flashmediaelement.swf",flashStreamer:"",enablePluginSmoothing:false,enablePseudoStreaming:false,pseudoStreamingStartQueryParam:"start",silverlightName:"silverlightmediaelement.xap",defaultVideoWidth:480,
defaultVideoHeight:270,pluginWidth:-1,pluginHeight:-1,pluginVars:[],timerRate:250,startVolume:0.8,success:function(){},error:function(){}};mejs.MediaElement=function(a,b){return mejs.HtmlMediaElementShim.create(a,b)};
mejs.HtmlMediaElementShim={create:function(a,b){var c=mejs.MediaElementDefaults,d=typeof a=="string"?document.getElementById(a):a,e=d.tagName.toLowerCase(),f=e==="audio"||e==="video",g=f?d.getAttribute("src"):d.getAttribute("href");e=d.getAttribute("poster");var h=d.getAttribute("autoplay"),l=d.getAttribute("preload"),j=d.getAttribute("controls"),k;for(k in b)c[k]=b[k];g=typeof g=="undefined"||g===null||g==""?null:g;e=typeof e=="undefined"||e===null?"":e;l=typeof l=="undefined"||l===null||l==="false"?
"none":l;h=!(typeof h=="undefined"||h===null||h==="false");j=!(typeof j=="undefined"||j===null||j==="false");k=this.determinePlayback(d,c,mejs.MediaFeatures.supportsMediaTag,f,g);k.url=k.url!==null?mejs.Utility.absolutizeUrl(k.url):"";if(k.method=="native"){if(mejs.MediaFeatures.isBustedAndroid){d.src=k.url;d.addEventListener("click",function(){d.play()},false)}return this.updateNative(k,c,h,l)}else if(k.method!=="")return this.createPlugin(k,c,e,h,l,j);else{this.createErrorMessage(k,c,e);return this}},

View file

@ -0,0 +1,18 @@
--- wordpress/wp-includes/script-loader.php 2013-08-01 06:47:23.000000000 -0700
+++ wordpress/wp-includes/script-loader.php.new 2013-08-23 00:10:37.406222565 -0700
@@ -252,15 +252,6 @@
$scripts->add( 'wp-plupload', "/wp-includes/js/plupload/wp-plupload$suffix.js", array('plupload-all', 'jquery', 'json2', 'media-models'), false, 1 );
did_action( 'init' ) && $scripts->localize( 'wp-plupload', 'pluploadL10n', $uploader_l10n );
- // keep 'swfupload' for back-compat.
- $scripts->add( 'swfupload', '/wp-includes/js/swfupload/swfupload.js', array(), '2201-20110113');
- $scripts->add( 'swfupload-swfobject', '/wp-includes/js/swfupload/plugins/swfupload.swfobject.js', array('swfupload', 'swfobject'), '2201a');
- $scripts->add( 'swfupload-queue', '/wp-includes/js/swfupload/plugins/swfupload.queue.js', array('swfupload'), '2201');
- $scripts->add( 'swfupload-speed', '/wp-includes/js/swfupload/plugins/swfupload.speed.js', array('swfupload'), '2201');
- $scripts->add( 'swfupload-all', false, array('swfupload', 'swfupload-swfobject', 'swfupload-queue'), '2201');
- $scripts->add( 'swfupload-handlers', "/wp-includes/js/swfupload/handlers$suffix.js", array('swfupload-all', 'jquery'), '2201-20110524');
- did_action( 'init' ) && $scripts->localize( 'swfupload-handlers', 'swfuploadL10n', $uploader_l10n );
-
$scripts->add( 'comment-reply', "/wp-includes/js/comment-reply$suffix.js" );
$scripts->add( 'json2', "/wp-includes/js/json2$suffix.js", array(), '2011-02-23');

File diff suppressed because one or more lines are too long

View file

@ -1,35 +0,0 @@
diff -up wordpress/wp-includes/js/tinymce/plugins/media/plugin.js.orig wordpress/wp-includes/js/tinymce/plugins/media/plugin.js
--- wordpress/wp-includes/js/tinymce/plugins/media/plugin.js.orig 2019-02-21 14:59:28.793415420 +0100
+++ wordpress/wp-includes/js/tinymce/plugins/media/plugin.js 2019-02-21 15:00:14.319647286 +0100
@@ -166,7 +166,6 @@ var media = (function () {
mp4: 'video/mp4',
webm: 'video/webm',
ogg: 'video/ogg',
- swf: 'application/x-shockwave-flash'
};
var fileEnd = url.toLowerCase().split('.').pop();
var mime = mimes[fileEnd];
@@ -424,14 +423,6 @@ var media = (function () {
var allowFullscreen = data.allowFullscreen ? ' allowFullscreen="1"' : '';
return '<iframe src="' + data.source1 + '" width="' + data.width + '" height="' + data.height + '"' + allowFullscreen + '></iframe>';
};
- var getFlashHtml = function (data) {
- var html = '<object data="' + data.source1 + '" width="' + data.width + '" height="' + data.height + '" type="application/x-shockwave-flash">';
- if (data.poster) {
- html += '<img src="' + data.poster + '" width="' + data.width + '" height="' + data.height + '" />';
- }
- html += '</object>';
- return html;
- };
var getAudioHtml = function (data, audioTemplateCallback) {
if (audioTemplateCallback) {
return audioTemplateCallback(data);
@@ -494,8 +485,6 @@ var media = (function () {
});
if (data.type === 'iframe') {
return getIframeHtml(data);
- } else if (data.source1mime === 'application/x-shockwave-flash') {
- return getFlashHtml(data);
} else if (data.source1mime.indexOf('audio') !== -1) {
return getAudioHtml(data, audioTemplateCallback);
} else if (data.type === 'script') {

View file

@ -1,35 +0,0 @@
diff -up wordpress/wp-config.php.rpm wordpress/wp-config.php
--- wordpress/wp-config.php.rpm 2020-10-20 15:05:26.351765085 +0200
+++ wordpress/wp-config.php 2020-10-20 15:05:48.663684089 +0200
@@ -66,6 +66,22 @@ define( 'NONCE_SALT', 'put your un
$table_prefix = 'wp_';
/**
+ * See http://make.wordpress.org/core/2013/10/25/the-definitive-guide-to-disabling-auto-updates-in-wordpress-3-7
+ */
+
+/* Disable all file change, as RPM base installation are read-only */
+define('DISALLOW_FILE_MODS', true);
+
+/* Please ensure that this is either 'direct', 'ssh2', 'ftpext', 'ftpsockets' or false */
+define('FS_METHOD', 'direct');
+
+/* Disable automatic updater, in case you want to allow
+ above FILE_MODS for plugins, themes, ... */
+define('AUTOMATIC_UPDATER_DISABLED', true);
+
+/* Core update is always disabled, WP_AUTO_UPDATE_CORE value is ignore */
+
+/**
* For developers: WordPress debugging mode.
*
* Change this to true to enable the display of notices during development.
@@ -83,7 +99,7 @@ define( 'WP_DEBUG', false );
/** Absolute path to the WordPress directory. */
if ( ! defined( 'ABSPATH' ) ) {
- define( 'ABSPATH', __DIR__ . '/' );
+ define('ABSPATH', '/usr/share/wordpress');
}
/** Sets up WordPress vars and included files. */

View file

@ -1,38 +0,0 @@
diff -up wordpress/wp-includes/js/mediaelement/mediaelement-and-player.js.no wordpress/wp-includes/js/mediaelement/mediaelement-and-player.js
--- wordpress/wp-includes/js/mediaelement/mediaelement-and-player.js.no 2020-09-29 17:53:06.000000000 +0200
+++ wordpress/wp-includes/js/mediaelement/mediaelement-and-player.js 2020-12-09 09:44:27.954254919 +0100
@@ -6135,6 +6135,7 @@ if (hasFlash) {
}
});
+/* swf files removed from RPM
var FlashMediaElementVideoRenderer = {
name: 'flash_video',
options: {
@@ -6219,6 +6220,7 @@ if (hasFlash) {
create: FlashMediaElementRenderer.create
};
_renderer.renderer.add(FlashMediaElementAudioOggRenderer);
+*/
}
},{"2":2,"25":25,"27":27,"28":28,"3":3,"5":5,"7":7,"8":8}],21:[function(_dereq_,module,exports){
diff -up wordpress/wp-includes/js/mediaelement/mediaelement.js.no wordpress/wp-includes/js/mediaelement/mediaelement.js
--- wordpress/wp-includes/js/mediaelement/mediaelement.js.no 2020-09-29 17:53:06.000000000 +0200
+++ wordpress/wp-includes/js/mediaelement/mediaelement.js 2020-12-09 09:44:38.532227178 +0100
@@ -1842,6 +1842,7 @@ if (hasFlash) {
}
});
+/* swf files removed from RPM
var FlashMediaElementVideoRenderer = {
name: 'flash_video',
options: {
@@ -1926,6 +1927,7 @@ if (hasFlash) {
create: FlashMediaElementRenderer.create
};
_renderer.renderer.add(FlashMediaElementAudioOggRenderer);
+*/
}
},{"16":16,"18":18,"19":19,"2":2,"3":3,"5":5,"7":7,"8":8}],12:[function(_dereq_,module,exports){

View file

@ -1,91 +0,0 @@
diff -up wordpress/wp-admin/includes/admin-filters.php.orig wordpress/wp-admin/includes/admin-filters.php
--- wordpress/wp-admin/includes/admin-filters.php.orig 2026-03-09 00:49:37.395081000 +0100
+++ wordpress/wp-admin/includes/admin-filters.php 2026-08-25 07:30:05.010828032 +0200
@@ -130,7 +130,6 @@ add_action( 'personal_options_update', '
add_action( 'load-plugins.php', 'wp_plugin_update_rows', 20 ); // After wp_update_plugins() is called.
add_action( 'load-themes.php', 'wp_theme_update_rows', 20 ); // After wp_update_themes() is called.
-add_action( 'admin_notices', 'update_nag', 3 );
add_action( 'admin_notices', 'deactivated_plugins_notice', 5 );
add_action( 'admin_notices', 'paused_plugins_notice', 5 );
add_action( 'admin_notices', 'paused_themes_notice', 5 );
diff -up wordpress/wp-admin/includes/class-core-upgrader.php.orig wordpress/wp-admin/includes/class-core-upgrader.php
--- wordpress/wp-admin/includes/class-core-upgrader.php.orig 2026-02-13 19:34:41.944764000 +0100
+++ wordpress/wp-admin/includes/class-core-upgrader.php 2026-08-25 07:30:05.010951923 +0200
@@ -277,6 +277,9 @@ class Core_Upgrader extends WP_Upgrader
* @return bool True if we should update to the offered version, otherwise false.
*/
public static function should_update_to_version( $offered_ver ) {
+ // RPM: nether allow core update
+ return false;
+
require ABSPATH . WPINC . '/version.php'; // $wp_version; // x.y.z
$current_branch = implode( '.', array_slice( preg_split( '/[.-]/', $wp_version ), 0, 2 ) ); // x.y
diff -up wordpress/wp-admin/includes/class-wp-automatic-updater.php.orig wordpress/wp-admin/includes/class-wp-automatic-updater.php
--- wordpress/wp-admin/includes/class-wp-automatic-updater.php.orig 2026-07-29 10:01:50.858475000 +0200
+++ wordpress/wp-admin/includes/class-wp-automatic-updater.php 2026-08-25 07:30:05.011078018 +0200
@@ -41,7 +41,7 @@ class WP_Automatic_Updater {
}
// More fine grained control can be done through the WP_AUTO_UPDATE_CORE constant and filters.
- $disabled = defined( 'AUTOMATIC_UPDATER_DISABLED' ) && AUTOMATIC_UPDATER_DISABLED;
+ $disabled = !defined( 'AUTOMATIC_UPDATER_DISABLED' ) || AUTOMATIC_UPDATER_DISABLED;
/**
* Filters whether to entirely disable background updates.
diff -up wordpress/wp-admin/includes/file.php.orig wordpress/wp-admin/includes/file.php
--- wordpress/wp-admin/includes/file.php.orig 2026-07-29 10:01:50.858475000 +0200
+++ wordpress/wp-admin/includes/file.php 2026-08-25 07:30:05.011274367 +0200
@@ -2270,7 +2270,7 @@ function WP_Filesystem( $args = false, $
*/
function get_filesystem_method( $args = array(), $context = '', $allow_relaxed_file_ownership = false ) {
// Please ensure that this is either 'direct', 'ssh2', 'ftpext', or 'ftpsockets'.
- $method = defined( 'FS_METHOD' ) ? FS_METHOD : false;
+ $method = defined( 'FS_METHOD' ) ? FS_METHOD : 'direct';
if ( ! $context ) {
$context = WP_CONTENT_DIR;
diff -up wordpress/wp-admin/includes/update.php.orig wordpress/wp-admin/includes/update.php
--- wordpress/wp-admin/includes/update.php.orig 2026-07-30 16:55:49.613388000 +0200
+++ wordpress/wp-admin/includes/update.php 2026-08-25 07:31:37.114050011 +0200
@@ -382,12 +382,7 @@ function update_right_now_message() {
$cur = get_preferred_from_update_core();
if ( isset( $cur->response ) && 'upgrade' === $cur->response ) {
- $msg .= sprintf(
- '<a href="%s" class="button" aria-describedby="wp-version">%s</a>',
- network_admin_url( 'update-core.php' ),
- /* translators: %s: WordPress version number, or 'Latest' string. */
- sprintf( __( 'Update to %s' ), $cur->current ? $cur->current : __( 'Latest' ) )
- );
+ $msg .= '';
}
}
diff -up wordpress/wp-includes/load.php.orig wordpress/wp-includes/load.php
--- wordpress/wp-includes/load.php.orig 2026-08-07 21:13:51.810460000 +0200
+++ wordpress/wp-includes/load.php 2026-08-25 07:30:05.011640399 +0200
@@ -1835,7 +1835,7 @@ function wp_is_file_mod_allowed( $contex
* @param bool $file_mod_allowed Whether file modifications are allowed.
* @param string $context The usage context.
*/
- return apply_filters( 'file_mod_allowed', ! defined( 'DISALLOW_FILE_MODS' ) || ! DISALLOW_FILE_MODS, $context );
+ return apply_filters( 'file_mod_allowed', defined( 'DISALLOW_FILE_MODS' ) && ! DISALLOW_FILE_MODS, $context );
}
/**
diff -up wordpress/wp-includes/update.php.orig wordpress/wp-includes/update.php
--- wordpress/wp-includes/update.php.orig 2026-07-06 23:09:52.376708000 +0200
+++ wordpress/wp-includes/update.php 2026-08-25 07:30:05.011769619 +0200
@@ -1087,10 +1087,6 @@ function _maybe_update_themes() {
* @since 3.1.0
*/
function wp_schedule_update_checks() {
- if ( ! wp_next_scheduled( 'wp_version_check' ) && ! wp_installing() ) {
- wp_schedule_event( time(), 'twicedaily', 'wp_version_check' );
- }
-
if ( ! wp_next_scheduled( 'wp_update_plugins' ) && ! wp_installing() ) {
wp_schedule_event( time(), 'twicedaily', 'wp_update_plugins' );
}

View file

@ -1,11 +0,0 @@
diff -up wordpress/wp-includes/script-loader.php.orig wordpress/wp-includes/script-loader.php
--- wordpress/wp-includes/script-loader.php.orig 2026-08-25 07:26:03.212320361 +0200
+++ wordpress/wp-includes/script-loader.php 2026-08-25 07:26:08.488274508 +0200
@@ -1205,7 +1205,6 @@ function wp_default_scripts( $scripts )
$scripts->add( 'wp-codemirror', '/wp-includes/js/codemirror/codemirror.min.js', array(), '5.65.20' );
$scripts->add( 'csslint', '/wp-includes/js/codemirror/csslint.js', array(), '1.0.5' );
$scripts->add( 'esprima', '/wp-includes/js/codemirror/esprima.js', array(), '4.0.1' ); // Deprecated.
- $scripts->add( 'jshint', '/wp-includes/js/codemirror/fakejshint.js', array( 'esprima' ), '2.9.5' ); // Deprecated.
$scripts->add( 'jsonlint', '/wp-includes/js/codemirror/jsonlint.js', array(), '1.6.3' );
$scripts->add( 'htmlhint', '/wp-includes/js/codemirror/htmlhint.js', array(), '1.9.2' );
$scripts->add( 'htmlhint-kses', '/wp-includes/js/codemirror/htmlhint-kses.js', array( 'htmlhint' ) );

View file

@ -1,17 +1,15 @@
diff -up wordpress/wp-content/plugins/hello.php.dolly wordpress/wp-content/plugins/hello.php
--- wordpress/wp-content/plugins/hello.php.dolly 2025-04-16 08:21:31.710644174 +0200
+++ wordpress/wp-content/plugins/hello.php 2025-04-16 08:23:15.011000365 +0200
@@ -6,7 +6,7 @@
--- wordpress/wp-content/plugins/hello.php 2013-05-22 14:08:40.000000000 -0700
+++ wordpress/wp-content/plugins/hello.php.new 2013-08-22 23:46:04.594788007 -0700
@@ -6,42 +6,26 @@
/*
Plugin Name: Hello Dolly
Plugin URI: http://wordpress.org/plugins/hello-dolly/
-Description: This is not just a plugin, it symbolizes the hope and enthusiasm of an entire generation summed up in two words sung most famously by Louis Armstrong: Hello, Dolly. When activated you will randomly see a lyric from <cite>Hello, Dolly</cite> in the upper right of your admin screen on every page.
+Description: This is not just a plugin, it symbolizes the hope and enthusiasm of an entire generation summed up in two words sung most famously by Richard M. Stallman: Free Software. When activated you will randomly see a lyric from the <cite>Free Software Song</cite> in the upper right of your admin screen on every page.
Author: Matt Mullenweg
Version: 1.7.2
Version: 1.6
Author URI: http://ma.tt/
@@ -18,34 +18,19 @@ if ( ! defined( 'ABSPATH' ) ) {
}
*/
function hello_dolly_get_lyric() {
- /** These are the lyrics to Hello Dolly */
@ -22,11 +20,12 @@ diff -up wordpress/wp-content/plugins/hello.php.dolly wordpress/wp-content/plugi
-I can tell, Dolly
-You're still glowin', you're still crowin'
-You're still goin' strong
-I feel the room swayin'
-We feel the room swayin'
-While the band's playin'
-One of our old favorite songs from way back when
-One of your old favourite songs from way back when
-So, take her wrap, fellas
-Dolly, never go away again
-Find her an empty lap, fellas
-Dolly'll never go away again
-Hello, Dolly
-Well, hello, Dolly
-It's so nice to have you back where you belong
@ -34,16 +33,16 @@ diff -up wordpress/wp-content/plugins/hello.php.dolly wordpress/wp-content/plugi
-I can tell, Dolly
-You're still glowin', you're still crowin'
-You're still goin' strong
-I feel the room swayin'
-We feel the room swayin'
-While the band's playin'
-One of our old favorite songs from way back when
-So, golly, gee, fellas
-Have a little faith in me, fellas
-Dolly, never go away
-Promise, you'll never go away
-One of your old favourite songs from way back when
-Golly, gee, fellas
-Find her a vacant knee, fellas
-Dolly'll never go away
-Dolly'll never go away
-Dolly'll never go away again";
+ // These are the lyrics to the Free Software Song
+ $lyrics = "Join us now and share the software;
+$lyrics = "Join us now and share the software;
+You'll be free, hackers, you'll be free.
+Hoarders may get piles of money,
+That is true, hackers, that is true.
@ -56,5 +55,5 @@ diff -up wordpress/wp-content/plugins/hello.php.dolly wordpress/wp-content/plugi
+Join us now and share the software;
+You'll be free, hackers, you'll be free.";
// Here we split it into lines.
// Here we split it into lines
$lyrics = explode( "\n", $lyrics );

View file

@ -1,23 +1,23 @@
Alias /wordpress /usr/share/wordpress
# Access is only allowed via local access
# Change this once configured
<Directory /usr/share/wordpress>
AllowOverride Options
<IfModule mod_authz_core.c>
# Apache 2.4
Require local
</Directory>
<Directory /usr/share/wordpress/wp-content/uploads>
# Deny access to any php file in the uploads directory
<FilesMatch "\.(php|phar)$">
Require all denied
</FilesMatch>
</IfModule>
<IfModule !mod_authz_core.c>
# Apache 2.2
Order Deny,Allow
Deny from All
Allow from 127.0.0.1
Allow from ::1
</IfModule>
</Directory>
<Directory /usr/share/wordpress/wp-content/plugins/akismet>
# Deny access to any php file in the akismet directory
<FilesMatch "\.(php|txt)$">
Require all denied
Order Deny,Allow
Deny from all
</FilesMatch>
</Directory>

View file

@ -1,16 +0,0 @@
<?php
require '/usr/share/php/Patchwork/autoload-jsqueeze.php';
$in = file_get_contents($_SERVER['argv'][1]);
if (!$in) exit(1);
$jsqueeze = new \Patchwork\JSqueeze();
$out = $jsqueeze->squeeze($in);
if ($out) {
printf("+ minify from %s to %s: %2d%% of %6d\n",
basename($_SERVER['argv'][1]), basename($_SERVER['argv'][2]),
round(strlen($out)*100/strlen($in)), strlen($in));
file_put_contents($_SERVER['argv'][2], $out);
} else {
exit(2);
}

View file

@ -0,0 +1,30 @@
diff -up wordpress/wp-includes/default-constants.php.rhbz522897 wordpress/wp-includes/default-constants.php
--- wordpress/wp-includes/default-constants.php.rhbz522897 2010-05-26 04:42:15.000000000 +0200
+++ wordpress/wp-includes/default-constants.php 2011-06-02 12:29:57.919714584 +0200
@@ -39,7 +39,7 @@ function wp_initial_constants( ) {
@ini_set('memory_limit', WP_MEMORY_LIMIT);
if ( !defined('WP_CONTENT_DIR') )
- define( 'WP_CONTENT_DIR', ABSPATH . 'wp-content' ); // no trailing slash, full paths only - WP_CONTENT_URL is defined further down
+ define( 'WP_CONTENT_DIR', '/var/www/wordpress/wp-content' ); // no trailing slash, full paths only - WP_CONTENT_URL is defined further down
// Add define('WP_DEBUG', true); to wp-config.php to enable display of notices during development.
if ( !defined('WP_DEBUG') )
@@ -75,7 +75,7 @@ function wp_initial_constants( ) {
*/
function wp_plugin_directory_constants( ) {
if ( !defined('WP_CONTENT_URL') )
- define( 'WP_CONTENT_URL', get_option('siteurl') . '/wp-content'); // full url - WP_CONTENT_DIR is defined further up
+ define( 'WP_CONTENT_URL', get_option('siteurl')); // full url - WP_CONTENT_DIR is defined further up
/**
* Allows for the plugins directory to be moved from the default location.
@@ -100,7 +100,7 @@ function wp_plugin_directory_constants(
* @deprecated
*/
if ( !defined('PLUGINDIR') )
- define( 'PLUGINDIR', 'wp-content/plugins' ); // Relative to ABSPATH. For back compat.
+ define( 'PLUGINDIR', WP_CONTENT_DIR . 'plugins' ); // Relative to ABSPATH. For back compat.
/**
* Allows for the mu-plugins directory to be moved from the default location.

View file

@ -1,35 +0,0 @@
# Wordpress
location = /wordpress {
alias /usr/share/wordpress/;
}
location /wordpress/ {
root /usr/share;
index index.php;
location ~ ^/wordpress/wp-content/uploads/(.+)\.php$ {
# Deny access to any php file in the uploads directory
deny all;
}
location ~ ^/wordpress/wp-content/plugins/akismet/(.+)\.php$ {
# Deny access to any php file in the akismet directory
deny all;
}
# Access is only allowed via local access
# Change this once configured
location ~ ^/wordpress/(.+\.php)$ {
allow 127.0.0.1;
allow ::1;
deny all;
try_files $uri =404;
fastcgi_intercept_errors on;
include fastcgi_params;
fastcgi_param SERVER_NAME $host;
fastcgi_param SCRIPT_FILENAME $document_root$fastcgi_script_name;
fastcgi_pass php-fpm;
}
}

View file

@ -1,193 +1,144 @@
# Fedora spec file for wordpress
#
# License: MIT
# http://opensource.org/licenses/MIT
#
# Please preserve changelog entries
#
%global wp_content %{_datadir}/wordpress/wp-content
%global upstream_version 7.1
#global upstream_prever RC5
#global upstream_lower rc5
%if 0%{?rhel} == 5
%global with_cacert 0
%else
%global with_cacert 1
%endif
Summary: Blog tool and publishing platform
URL: https://wordpress.org/
URL: http://www.wordpress.org
Name: wordpress
Version: %{upstream_version}%{?upstream_prever:~%upstream_lower}
Version: 3.7.1
Group: Applications/Publishing
Release: 1%{?dist}
# Wordpress is GPL-2.0-or-later
# php-simplepie is BSD-3-Clause
# php-getid3 is LGPL-3.0-or-later (or some others)
# php-mailer is LGPL-2.1-only
License: GPL-2.0-or-later AND BSD-3-Clause AND LGPL-3.0-or-later AND LGPL-2.1-only
License: GPLv2
Source0: https://wordpress.org/%{name}-%{upstream_version}%{?upstream_prever:-%{upstream_prever}}.tar.gz
Source0: http://wordpress.org/%{name}-%{version}.tar.gz
Source1: wordpress-httpd-conf
Source2: README.fedora.wordpress
Source3: README.fedora.wordpress-mu
Source4: wordpress-nginx-conf
# To minify JS assets
Source5: wordpress-minify.php
# Patch out copyrighted text of Hello, Dolly
# (and replace it with Free Software Song)
Patch0: wordpress-6.8-hello.patch
Patch0: wordpress-debian_patches_hello.patch
# Move wp-content to /var/www/wordpress/
# This patch doesnt work well, see bugzilla.redhat.com/522897
Patch1: wordpress-move-wp-content.patch
# Drop swfupload: not built from source, not reasonably possible to do
Patch2: wordpress-3.6-no_swfupload.patch
# Adjust tinymce's media plugin not to use its SWF plugin. This changes
# 'p.getParam("flash_video_player_url",u.convertUrl(u.url+"/moxieplayer.swf"))'
# to 'false'
Patch3: wordpress-5.1-tinymce_noflash.patch
# We drop the SWF files from mediaelement
Patch4: wordpress-5.6-mediaelement_no_swf.patch
# RPM configuration:
# Path to installation
# Disable auto-updater
Patch5: wordpress-5.4-config.patch
# RPM are readonly
# disable version check and updated
# change DISALLOW_FILE_MODS default value to true
# ignore WP_AUTO_UPDATE_CORE (always false)
Patch6: wordpress-7.1-noupdate.patch
# Debian patch for jshint
Patch8: wordpress-7.1-remove-jshint-refs.patch
Patch3: wordpress-3.6-tinymce_noflash.patch
# Adjust mediaelement not to use its SWF and Silverlight plugins. This
# changes 'plugins:["flash,"silverlight","youtube","vimeo"]' to
# 'plugins:["youtube","vimeo"]'
Patch4: wordpress-3.6-mediaelement-noflash_silverlight.patch
BuildRoot: %{_tmppath}/%{name}-%{version}-%{release}-root-%(%{__id_u} -n)
BuildArch: noarch
BuildRequires: php-cli
BuildRequires: php-patchwork-jsqueeze
BuildRequires: php(language) >= 7.2
Requires: webserver
Requires: php(httpd)
Suggests: httpd
# For directory ownership
Requires: httpd-filesystem
Requires: nginx-filesystem
Requires: php(language) >= 7.2
Requires: php-sodium
Requires: php-ctype
Requires: php-filter
Requires: php-mysqli
# From phpcompatinfo report for version 4.5.3
%if 0%{?rhel} == 5
Requires: php53 >= 5.2.4
Requires: php53-simplepie >= 1.3.1
%else
Requires: php >= 5.2.4
Requires: php-simplepie >= 1.3.1
%endif
# Required php extension (detected by phpcompatinfo)
Requires: php-curl
Requires: php-date
Requires: php-dom
Requires: php-enchant
# not yet available for RHEL Requires: php-ereg
Requires: php-exif
Requires: php-fileinfo
Requires: php-gd
# not yet available for RHEL Requires: php-filter
Requires: php-gettext
Requires: php-hash
Requires: php-iconv
Requires: php-intl
Requires: php-json
Requires: php-libxml
Requires: php-mbstring
Requires: php-mysql
Requires: php-openssl
Requires: php-pcre
Requires: php-pdo
Requires: php-posix
Requires: php-reflection
Requires: php-simplexml
Requires: php-xml
Requires: php-xmlreader
Requires: php-sockets
Requires: php-spl
Requires: php-tokenizer
Requires: php-zip
Requires: php-zlib
Requires: httpd
# Unbundled
Requires: /etc/pki/ca-trust/extracted/pem/tls-ca-bundle.pem
# Bundled
# grep "SIMPLEPIE_VERSION'" wordpress/wp-includes/class-simplepie.php
Provides: bundled(php-simplepie) = 1.9.0
# grep ' VERSION ' wordpress/wp-includes/ID3/getid3.php
Provides: bundled(php-getid3) = 1.9.25
# grep ' VERSION ' wordpress/wp-includes/PHPMailer/PHPMailer.php
Provides: bundled(php-phpmailer) = 7.1.1
# Unbundled libraries
Requires: php-PHPMailer
Requires: webserver
%if %{with_cacert}
Requires: ca-certificates
%endif
Provides: wordpress-mu = %{version}-%{release}
Obsoletes: wordpress-mu < 2.9.3
%description
Wordpress is an online publishing / weblog package that makes it very easy,
almost trivial, to get information out to people on the web.
Important information in %{_pkgdocdir}/README.fedora
%prep
%setup -q -n wordpress
# Drop pre-compiled binary lumps: Flash and Silverlight
# This means that Flash video fallbacks in Wordpress' media support
# and the tinymce plugin, the plupload Flash and Silverlight
# uploaders, and swfupload are not available.
# To re-introduce these they would have to be built from the
# ActionScript source as part of this package build, they cannot be
# shipped pre-compiled. Removing plupload.flash.js and
# plupload.silverlight.js causes plupload only to try and use the html4
# or html5 uploaders; if you just wipe the binaries but leave the
# .js files, it will try and use the Flash or Silverlight uploaders
# and draw a non-functional button. - AdamW, 2013/08
# https://fedoraproject.org/wiki/Packaging:Guidelines#No_inclusion_of_pre-built_binaries_or_libraries
rm -f wp-includes/js/mediaelement/silverlightmediaelement.xap
rm -f wp-includes/js/mediaelement/flashmediaelement.sw
rm -f wp-includes/js/tinymce/plugins/media/moxieplayer.swf
rm -f wp-includes/js/plupload/plupload.silverlight.xap
rm -f wp-includes/js/plupload/plupload.silverlight.js
rm -f wp-includes/js/plupload/plupload.flash.swf
rm -f wp-includes/js/plupload/plupload.flash.js
# swfupload can just die in its entirety
rm -rf wp-includes/js/swfupload
# remove .htaccess, protected by httpd config file
rm wp-content/plugins/akismet/.htaccess
# only for PHP < 7.0 without random_int
rm -rf wp-includes/random_compat
# only for PHP < 7.2 without sodium_crypto_box
rm -rf wp-includes/sodium_compat
%patch -P0 -p1 -b .dolly
%patch -P3 -p1
# Adjust mediaelement not to use its SWF
%patch -P4 -p1
%patch -P8 -p1
# We patch .js files, so minify them
php %{SOURCE5} \
wp-includes/js/tinymce/plugins/media/plugin.js \
wp-includes/js/tinymce/plugins/media/plugin.min.js
php %{SOURCE5} \
wp-includes/js/mediaelement/mediaelement-and-player.js \
wp-includes/js/mediaelement/mediaelement-and-player.min.js
php %{SOURCE5} \
wp-includes/js/mediaelement/mediaelement.js \
wp-includes/js/mediaelement/mediaelement.min.js
# Re-Generated the archive
arc=wp-includes/js/tinymce/wp-tinymce.js
grep "^// Source" $arc | while read a b c
do
if [ -f $c ]; then
echo -e "\n$a $b $c"
cat $c
else
exit 1
fi
done >$arc.tmp
if [ -s $arc.tmp ]; then
gzip -c $arc > $arc.gz
ls -l $arc*
mv $arc.tmp $arc
else
exit 1
fi
# Create RPM configuration
sed -e 's/\r//' wp-config-sample.php >wp-config.php
%patch -P5 -p1
%patch -P6 -p1
%patch0 -p1 -b .dolly
#%patch1 -p1 -b .rhbz522897
%patch2 -p1
%patch3 -p1
%patch4 -p1
# disable wp_version_check, updates are always installed via rpm
sed -i -e "s,\(.*\)'wp_version_check'\(.*\),#\1'wp_version_check'\2,g" \
wp-includes/update.php
# disable update_nag() function
sed -i -e "s,\(.*\)'update_nag'\(.*\),#\1'update_nag'\2,g; \
s,\(.*\)\$msg .=\(.*\),\1\$msg .= '';,g;" \
wp-admin/includes/update.php
# fix file encoding
sed -i -e 's/\r//' license.txt
: Bundled library versions
grep ' VERSION ' wp-includes/SimplePie/src/SimplePie.php
grep ' VERSION ' wp-includes/ID3/getid3.php
grep ' VERSION ' wp-includes/PHPMailer/PHPMailer.php
%build
%install
# Apache configuration
install -m 0644 -D -p %{SOURCE1} ${RPM_BUILD_ROOT}%{_sysconfdir}/httpd/conf.d/wordpress.conf
install -m 0644 -D -p %{SOURCE4} ${RPM_BUILD_ROOT}%{_sysconfdir}/nginx/default.d/wordpress.conf
# Application
mkdir -p ${RPM_BUILD_ROOT}%{_datadir}/wordpress
mkdir -p ${RPM_BUILD_ROOT}%{_sysconfdir}/wordpress
install -m 0644 -D -p %{SOURCE1} ${RPM_BUILD_ROOT}%{_sysconfdir}/httpd/conf.d/wordpress.conf
cp -pr * ${RPM_BUILD_ROOT}%{_datadir}/wordpress
# Configuration
install -m 0644 -D wp-config.php ${RPM_BUILD_ROOT}%{_sysconfdir}/wordpress/wp-config.php
cat wp-config-sample.php | sed -e "s|dirname(__FILE__).'/'|'/usr/share/wordpress/'|g" > \
${RPM_BUILD_ROOT}%{_sysconfdir}/wordpress/wp-config.php
/bin/ln -sf ../../../etc/wordpress/wp-config.php ${RPM_BUILD_ROOT}%{_datadir}/wordpress/wp-config.php
/bin/cp %{SOURCE2} ./README.fedora
/bin/cp %{SOURCE3} ./README.fedora-multiuser
@ -199,560 +150,76 @@ find ${RPM_BUILD_ROOT} -type f -empty -exec rm -vf {} \;
# These are docs, remove them from here, docify them later
rm -f ${RPM_BUILD_ROOT}%{_datadir}/wordpress/{license.txt,readme.html}
# Remove bundled php-simplepie and link to system copy
rm ${RPM_BUILD_ROOT}%{_datadir}/wordpress/wp-includes/class-simplepie.php
rm -rf ${RPM_BUILD_ROOT}%{_datadir}/wordpress/wp-includes/SimplePie
%if 0%{?rhel} == 5
ln -sf /usr/share/php/php53-simplepie/autoloader.php \
%else
ln -sf /usr/share/php/php-simplepie/autoloader.php \
%endif
${RPM_BUILD_ROOT}%{_datadir}/wordpress/wp-includes/class-simplepie.php
# Remove bundled PHPMailer and link to system one
# Note POP3 is not from PHPMailer but from SquirrelMail
for fic in phpmailer smtp; do
rm ${RPM_BUILD_ROOT}%{_datadir}/wordpress/wp-includes/class-$fic.php
ln -sf /usr/share/php/PHPMailer/class.$fic.php \
${RPM_BUILD_ROOT}%{_datadir}/wordpress/wp-includes/class-$fic.php
done
# Remove bundled ca-bundle.crt
%if %{with_cacert}
rm ${RPM_BUILD_ROOT}%{_datadir}/wordpress/wp-includes/certificates/ca-bundle.crt
ln -s %{_sysconfdir}/pki/ca-trust/extracted/pem/tls-ca-bundle.pem \
ln -s /etc/pki/tls/certs/ca-bundle.crt \
${RPM_BUILD_ROOT}%{_datadir}/wordpress/wp-includes/certificates/ca-bundle.crt
%endif
# Remove backup copies of patches
find ${RPM_BUILD_ROOT} \( -name \*.dolly -o -name \*.rhbz522897 -o -name \*.orig \) \
-print -delete
## Move wp-content directory to /var/www location
#mkdir -p ${RPM_BUILD_ROOT}%{_localstatedir}/www/wordpress
#mv -v ${RPM_BUILD_ROOT}%{wp_content}/ \
# ${RPM_BUILD_ROOT}%{_localstatedir}/www/wordpress
%pretrans -p <lua>
-- Remove link to system library
path = "%{_datadir}/wordpress/wp-includes/PHPMailer"
st = posix.stat(path)
if st and st.type == "link" then
os.remove(path)
end
#%post
#if [ $1 -eq 2 ] ; then
## In case user has old wp-content from previous version, move it to
## the new location.
#mv -uf %{wp_content}/* %{_localstatedir}/www/wordpress/
#/sbin/restorecon -R %{_localstatedir}/www/wordpress/
#fi
%clean
rm -rf ${RPM_BUILD_ROOT}
%files
%defattr(-,root,root,-)
%config(noreplace) %{_sysconfdir}/httpd/conf.d/wordpress.conf
%config(noreplace) %{_sysconfdir}/nginx/default.d/wordpress.conf
%dir %{_datadir}/wordpress
%{_datadir}/wordpress/wp-admin
%{_datadir}/wordpress/wp-includes
%{_datadir}/wordpress/index.php
%dir %{wp_content}/
%{wp_content}/index.php
%dir %attr(2775,apache,ftp) %{wp_content}/plugins
%dir %attr(2775,apache,ftp) %{wp_content}/themes
%dir %attr(2775,apache,ftp) %{wp_content}/upgrade
%dir %attr(2775,apache,ftp) %{wp_content}/uploads
%dir %attr(0775,apache,ftp) %{wp_content}/plugins
%dir %attr(0775,apache,ftp) %{wp_content}/themes
%dir %attr(0775,apache,ftp) %{wp_content}/upgrade
%dir %attr(0775,apache,ftp) %{wp_content}/uploads
%{wp_content}/plugins/*
%{wp_content}/themes/*
%{!?_licensedir:%global license %%doc}
%license license.txt
%doc license.txt
%doc readme.html
%doc README.fedora
%doc README.fedora-multiuser
%{_datadir}/wordpress/wp-*.php
%attr(750,root,apache) %dir %{_sysconfdir}/wordpress
%attr(640,root,apache) %config(noreplace) %{_sysconfdir}/wordpress/wp-config.php
%config(noreplace) %{_sysconfdir}/wordpress/wp-config.php
%{_datadir}/wordpress/xmlrpc.php
%dir %{_sysconfdir}/wordpress
%changelog
* Tue Aug 25 2026 Remi Collet <remi@remirepo.net> -7.1-1
- WordPress 7.1 “Mary Lou”
* Thu Aug 13 2026 Remi Collet <remi@remirepo.net> -7.0.4-1
- WordPress 7.0.4 Release
* Fri Aug 7 2026 Remi Collet <remi@remirepo.net> -7.0.3-1
- WordPress 7.0.3 Release
* Tue Jul 21 2026 Remi Collet <remi@remirepo.net> -7.0.2-1
- WordPress 7.0.2 Release
* Fri Jul 17 2026 Fedora Release Engineering <releng@fedoraproject.org> - 7.0.1-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_45_Mass_Rebuild
* Fri Jul 10 2026 Remi Collet <remi@remirepo.net> -7.0.1-1
- WordPress 7.0.1 Maintenance Release
* Tue May 26 2026 Remi Collet <remi@remirepo.net> -7.0-1
- WordPress 7.0 “Armstrong”
* Thu Mar 12 2026 Remi Collet <remi@remirepo.net> - 6.9.4-1
- WordPress 6.9.4 Release
* Wed Mar 11 2026 Remi Collet <remi@remirepo.net> - 6.9.3-1
- WordPress 6.9.3 Release
* Wed Feb 4 2026 Remi Collet <remi@remirepo.net> - 6.9.1-1
- WordPress 6.9.1 Maintenance Release
* Sat Jan 17 2026 Fedora Release Engineering <releng@fedoraproject.org> - 6.9-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_44_Mass_Rebuild
* Wed Dec 3 2025 Remi Collet <remi@remirepo.net> - 6.9-1
- WordPress 6.9 “Gene”
* Wed Oct 1 2025 Remi Collet <remi@remirepo.net> - 6.8.3-1
- WordPress 6.8.3 Security Release
* Mon Jul 28 2025 Remi Collet <remi@remirepo.net> - 6.8.2-3
- fix system certificates path
* Fri Jul 25 2025 Fedora Release Engineering <releng@fedoraproject.org> - 6.8.2-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild
* Tue Jul 22 2025 Remi Collet <remi@remirepo.net> - 6.8.2-1
- WordPress 6.8.2 Maintenance Release
* Mon May 5 2025 Remi Collet <remi@remirepo.net> - 6.8.1-1
- WordPress 6.8.1 Maintenance Release
* Wed Apr 16 2025 Remi Collet <remi@remirepo.net> - 6.8-1
- WordPress 6.8 “Cecil”
* Wed Feb 12 2025 Remi Collet <remi@remirepo.net> - 6.7.2-1
- WordPress 6.7.2 Maintenance Release
* Sun Jan 19 2025 Fedora Release Engineering <releng@fedoraproject.org> - 6.7.1-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_42_Mass_Rebuild
* Fri Nov 22 2024 Remi Collet <remi@remirepo.net> - 6.7.1-1
- WordPress 6.7.1 Maintenance Release
* Wed Nov 13 2024 Remi Collet <remi@remirepo.net> - 6.7-1
- WordPress 6.7 “Rollins”
* Wed Sep 11 2024 Remi Collet <remi@remirepo.net> - 6.6.2-1
- WordPress 6.6.2 Maintenance Release
* Wed Jul 24 2024 Remi Collet <remi@remirepo.net> - 6.6.1-1
- WordPress 6.6.1 Maintenance Release
* Sat Jul 20 2024 Fedora Release Engineering <releng@fedoraproject.org> - 6.6-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_41_Mass_Rebuild
* Wed Jul 17 2024 Remi Collet <remi@remirepo.net> - 6.6-1
- WordPress 6.6 “Dorsey”
* Tue Jul 2 2024 Remi Collet <remi@remirepo.net> - 6.5.5-1
- WordPress 6.4.2 Maintenance & Security Release
* Thu Jun 6 2024 Remi Collet <remi@remirepo.net> - 6.5.4-1
- WordPress 6.5.4 Maintenance Release
* Mon May 13 2024 Remi Collet <remi@remirepo.net> - 6.5.3-1
- WordPress 6.5.3 Maintenance Release
* Wed Apr 10 2024 Remi Collet <remi@remirepo.net> - 6.5.2-1
- WordPress 6.5.2 Maintenance and Security Release
* Wed Apr 3 2024 Remi Collet <remi@remirepo.net> - 6.5-1
- WordPress 6.5 “Regina”
* Thu Feb 1 2024 Remi Collet <remi@remirepo.net> - 6.4.3-1
- WordPress 6.4.3 Maintenance & Security Release
* Sat Jan 27 2024 Fedora Release Engineering <releng@fedoraproject.org> - 6.4.2-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild
* Thu Dec 7 2023 Remi Collet <remi@remirepo.net> - 6.4.2-1
- WordPress 6.4.2 Maintenance & Security Release
* Thu Nov 9 2023 Remi Collet <remi@remirepo.net> - 6.4.1-1
- WordPress 6.4.1 Maintenance Release
* Wed Nov 8 2023 Remi Collet <remi@remirepo.net> - 6.4-1
- WordPress 6.4 “Shirley”
* Mon Oct 16 2023 Remi Collet <remi@remirepo.net> - 6.3.2-1
- WordPress 6.3.2 Maintenance and Security release
* Thu Aug 31 2023 Remi Collet <remi@remirepo.net> - 6.3.1-1
* WordPress 6.3.1 Maintenance Release
* Sun Aug 20 2023 Remi Collet <remi@remirepo.net> - 6.3-1
- WordPress 6.3 “Lionel”
* Sat Jul 22 2023 Fedora Release Engineering <releng@fedoraproject.org> - 6.2.2-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_39_Mass_Rebuild
* Sun May 21 2023 Remi Collet <remi@remirepo.net> - 6.2.2-1
- WordPress 6.2.2 Security Release
* Wed May 17 2023 Remi Collet <remi@remirepo.net> - 6.2.1-1
- WordPress 6.2.1 Maintenance & Security Release
* Thu Mar 30 2023 Remi Collet <remi@remirepo.net> - 6.2-1
- WordPress 6.2 “Dolphy”
- use SPDX license IDs
* Sat Jan 21 2023 Fedora Release Engineering <releng@fedoraproject.org> - 6.1.1-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_38_Mass_Rebuild
* Wed Nov 16 2022 Remi Collet <remi@remirepo.net> - 6.1.1-1
- WordPress 6.1.1 Maintenance Release
* Wed Nov 2 2022 Remi Collet <remi@remirepo.net> - 6.1-1
- WordPress 6.1 “Misha”
* Tue Oct 18 2022 Remi Collet <remi@remirepo.net> - 6.0.3-1
- WordPress 6.0.3 Security Release
* Thu Sep 8 2022 Remi Collet <remi@remirepo.net> - 6.0.2-1
- WordPress 6.0.2 Security and Maintenance Release
* Sat Jul 23 2022 Fedora Release Engineering <releng@fedoraproject.org> - 6.0.1-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_37_Mass_Rebuild
* Wed Jul 13 2022 Remi Collet <remi@remirepo.net> - 6.0.1-1
- WordPress 6.0.1 Maintenance Release
* Wed May 25 2022 Remi Collet <remi@remirepo.net> - 6.0-1
- WordPress 6.0 “Arturo”
* Wed Apr 6 2022 Remi Collet <remi@remirepo.net> - 5.9.3-1
- WordPress 5.9.3 Maintenance Release
* Fri Mar 11 2022 Remi Collet <remi@remirepo.net> - 5.9.2-1
- WordPress 5.9.2 Security & Maintenance Release
* Wed Feb 23 2022 Remi Collet <remi@remirepo.net> - 5.9.1-1
- WordPress 5.9.1 Maintenance Release
* Wed Jan 26 2022 Remi Collet <remi@remirepo.net> - 5.9-1
- WordPress 5.9 Josephine
* Sat Jan 22 2022 Fedora Release Engineering <releng@fedoraproject.org> - 5.8.3-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_36_Mass_Rebuild
* Fri Jan 7 2022 Remi Collet <remi@remirepo.net> - 5.8.3-1
- WordPress 5.8.3 Security Release
* Tue Dec 7 2021 Remi Collet <remi@remirepo.net> - 5.8.2-2
- use bundled libraries
* Thu Nov 11 2021 Remi Collet <remi@remirepo.net> - 5.8.2-1
- WordPress 5.8.2 Security and Maintenance Release
* Thu Sep 9 2021 Remi Collet <remi@remirepo.net> - 5.8.1-1
- WordPress 5.8.1 Security and Maintenance Release
* Fri Jul 23 2021 Fedora Release Engineering <releng@fedoraproject.org> - 5.8-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_35_Mass_Rebuild
* Wed Jul 21 2021 Remi Collet <remi@remirepo.net> - 5.8-1
- WordPress 5.8 Tatum
* Thu May 13 2021 Remi Collet <remi@remirepo.net> - 5.7.2-1
- WordPress 5.7.2 Security Release
* Thu Apr 15 2021 Remi Collet <remi@remirepo.net> - 5.7.1-1
- WordPress 5.7.1 Security and Maintenance Release
* Wed Mar 10 2021 Remi Collet <remi@remirepo.net> - 5.7-1
- WordPress 5.7 “Esperanza”
* Tue Feb 23 2021 Remi Collet <remi@remirepo.net> - 5.6.2-1
- WordPress 5.6.2 Maintenance Release
* Fri Feb 5 2021 Remi Collet <remi@remirepo.net> - 5.6.1-1
- WordPress 5.6.1 Maintenance Release
* Wed Jan 27 2021 Fedora Release Engineering <releng@fedoraproject.org> - 5.6-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_34_Mass_Rebuild
* Wed Dec 9 2020 Remi Collet <remi@remirepo.net> - 5.6-1
- WordPress 5.6 “Simone”
* Sat Oct 31 2020 Remi Collet <remi@remirepo.net> - 5.5.3-1
- WordPress 5.5.3 Maintenance Release
* Fri Oct 30 2020 Remi Collet <remi@remirepo.net> - 5.5.2-1
- WordPress 5.5.2 Security and Maintenance Release
* Tue Oct 20 2020 Remi Collet <remi@remirepo.net> - 5.5.1-2
- Change FS_METHOD default to 'direct' to allow enabling FILE_MODS #1889644
* Wed Sep 2 2020 Remi Collet <remi@remirepo.net> - 5.5.1-1
- WordPress 5.5.1 Maintenance Release
* Wed Aug 12 2020 Remi Collet <remi@remirepo.net> - 5.5-1
- WordPress 5.5 “Eckstine”
- requires php-phpmailer6 instead of old php-PHPMailer
* Wed Jul 29 2020 Fedora Release Engineering <releng@fedoraproject.org> - 5.4.2-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_33_Mass_Rebuild
* Thu Jun 11 2020 Remi Collet <remi@remirepo.net> - 5.4.2-1
- WordPress 5.4.2 Security and Maintenance Release
* Thu Apr 30 2020 Remi Collet <remi@remirepo.net> - 5.4.1-1
- WordPress 5.4.1 Security and Maintenance Release
* Wed Apr 1 2020 Remi Collet <remi@remirepo.net> - 5.4-1
- WordPress 5.4 “Adderley”
* Mon Mar 30 2020 Remi Collet <remi@remirepo.net> - 5.4~rc5-1
- WordPress 5.4 RC 5
* Wed Mar 25 2020 Remi Collet <remi@remirepo.net> - 5.4~rc4-1
- WordPress 5.4 RC 4
* Fri Jan 31 2020 Fedora Release Engineering <releng@fedoraproject.org> - 5.3.2-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_32_Mass_Rebuild
* Thu Dec 19 2019 Remi Collet <remi@remirepo.net> - 5.3.2-1
- WordPress 5.3.2 Maintenance Release
* Fri Dec 13 2019 Remi Collet <remi@remirepo.net> - 5.3.1-1
- WordPress 5.3.1 Security and Maintenance Release
* Wed Nov 13 2019 Remi Collet <remi@remirepo.net> - 5.3-1
- WordPress 5.3 “Kirk”
* Tue Oct 15 2019 Remi Collet <remi@remirepo.net> - 5.2.4-1
- WordPress 5.2.4 Security Release
* Thu Sep 5 2019 Remi Collet <remi@remirepo.net> - 5.2.3-1
- WordPress 5.2.3 Security and Maintenance Release
* Sat Jul 27 2019 Fedora Release Engineering <releng@fedoraproject.org> - 5.2.2-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_31_Mass_Rebuild
* Wed Jun 19 2019 Remi Collet <remi@remirepo.net> - 5.2.2-1
- WordPress 5.2.2 Maintenance Release
* Wed May 22 2019 Remi Collet <remi@remirepo.net> - 5.2.1-1
- WordPress 5.2.1 Maintenance Release
* Wed May 8 2019 Remi Collet <remi@remirepo.net> - 5.2.0-1
- WordPress 5.2 “Jaco”
* Fri Apr 26 2019 Remi Collet <remi@remirepo.net> - 5.2.0~rc1-1
- WordPress 5.2 RC 1
* Wed Apr 17 2019 Remi Collet <remi@remirepo.net> - 5.2.0~beta3-1
- WordPress 5.2 Beta 3
* Tue Apr 9 2019 Remi Collet <remi@remirepo.net> - 5.2.0~beta2-1
- WordPress 5.2 Beta 2
* Thu Mar 28 2019 Remi Collet <remi@remirepo.net> - 5.2.0~beta1-1
- WordPress 5.2 Beta 1
- raise dependency on PHP 7.2
* Fri Mar 22 2019 Remi Collet <remi@remirepo.net> - 5.1.1-4
- fix wp-tinymce.js is missing, wp-tinymce.js.gz is empty #1691524
* Wed Mar 13 2019 Remi Collet <remi@remirepo.net> - 5.1.1-1
- WordPress 5.1.1 Security and Maintenance Release
* Fri Feb 22 2019 Remi Collet <remi@remirepo.net> - 5.1-1
- WordPress 5.1 “Betty”
* Thu Feb 21 2019 Remi Collet <remi@remirepo.net> - 5.1~RC2-1
- WordPress 5.1-RC2
* Sun Feb 03 2019 Fedora Release Engineering <releng@fedoraproject.org> - 5.0.3-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_30_Mass_Rebuild
* Fri Jan 11 2019 Remi Collet <remi@remirepo.net> - 5.0.3-1
- WordPress 5.0.3 Maintenance Release
* Thu Dec 20 2018 Remi Collet <remi@remirepo.net> - 5.0.2-1
- WordPress 5.0.2 Maintenance Release
* Thu Dec 13 2018 Remi Collet <remi@remirepo.net> - 5.0.1-1
- WordPress 5.0.1 Security Release
* Wed Dec 12 2018 Remi Collet <remi@remirepo.net> - 5.0-1
- WordPress 5.0 “Bebo”
* Fri Aug 03 2018 Kevin Fenzi <kevin@scrye.com> - 4.9.8-1
- Update to 4.9.8. Fixes bug #1611877
* Sat Jul 14 2018 Fedora Release Engineering <releng@fedoraproject.org> - 4.9.7-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_29_Mass_Rebuild
* Thu Jul 05 2018 Kevin Fenzi <kevin@scrye.com> - 4.9.7-1
- Update to 4.9.7 security update. Fixes bug #1598612
- Fixes CVE-2018-12895 bugs #1595584 and #1595585
* Fri May 18 2018 Kevin Fenzi <kevin@scrye.com> - 4.9.6-1
- Update to 4.9.6. Fixes bug #1579584
* Wed Apr 4 2018 Remi Collet <remi@remirepo.net> - 4.9.5-1
- WordPress 4.9.5 Security and Maintenance Release
* Wed Feb 7 2018 Remi Collet <remi@remirepo.net> - 4.9.4-1
- WordPress 4.9.4 Maintenance Release
* Wed Jan 17 2018 Remi Collet <remi@remirepo.net> - 4.9.2-1
- WordPress 4.9.2 Security and Maintenance Release
- drop non-free jshint.js file #1528765
* Thu Nov 30 2017 Remi Collet <remi@remirepo.net> - 4.9.1-1
- WordPress 4.9.1 Security and Maintenance Release
* Thu Nov 16 2017 Remi Collet <remi@remirepo.net> - 4.9-1
- WordPress 4.9 “Tipton”
- minify patched JS files
* Tue Oct 31 2017 Kevin Fenzi <kevin@scrye.com> - 4.8.3-1
- Update to 4.8.3. Security release. Fixes bug #1508255
* Wed Sep 20 2017 Remi Collet <remi@remirepo.net> - 4.8.2-1
- Update to 4.8.2 Security and Maintenance Release
* Thu Aug 3 2017 Remi Collet <remi@remirepo.net> - 4.8.1-1
- Update to 4.8.1 Maintenance Release.
* Thu Jul 27 2017 Fedora Release Engineering <releng@fedoraproject.org> - 4.8-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild
* Fri Jun 9 2017 Remi Collet <remi@remirepo.net> - 4.8-1
- WordPress 4.8 “Evans”
* Wed May 17 2017 Remi Collet <remi@remirepo.net> - 4.7.5-1
- WordPress 4.7.5 Security and Maintenance Release
* Wed May 10 2017 Remi Collet <remi@remirepo.net> - 4.7.4-2
- protect .phar from being executed from uploads directory
* Sat Apr 22 2017 Kevin Fenzi <kevin@scrye.com> - 4.7.4-1
- Update to 4.7.4. Maintenance Release.
* Tue Mar 7 2017 Remi Collet <remi@fedoraproject.org> - 4.7.3-1
- WordPress 4.7.3 Security and Maintenance Release
* Sat Feb 11 2017 Fedora Release Engineering <releng@fedoraproject.org> - 4.7.2-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_26_Mass_Rebuild
* Fri Jan 27 2017 Remi Collet <remi@fedoraproject.org> - 4.7.2-1
- WordPress 4.7.2 Security Release
* Thu Jan 12 2017 Remi Collet <remi@fedoraproject.org> - 4.7.1-1
- WordPress 4.7.1 Security and Maintenance Release
* Wed Dec 7 2016 Remi Collet <remi@fedoraproject.org> - 4.7.0-1
- WordPress 4.7 “Vaughan”
* Thu Sep 8 2016 Remi Collet <remi@fedoraproject.org> - 4.6.1-1
- WordPress 4.6.1 Security and Maintenance Release
* Sat Sep 3 2016 Remi Collet <remi@fedoraproject.org> - 4.6-2
- WordPress 4.6 “Pepper”
- fix directory permissions #1305687
* Mon Jun 27 2016 Remi Collet <remi@fedoraproject.org> - 4.5.3-2
- add patch to drop ereg dependency, see
https://core.trac.wordpress.org/ticket/37194
* Wed Jun 22 2016 Remi Collet <remi@fedoraproject.org> - 4.5.3-1
- WordPress 4.5.3 Maintenance and Security Release
* Sat May 14 2016 Remi Collet <remi@fedoraproject.org> - 4.5.2-2
- never bundle ca-bundle.crt (EL-5)
- provide nginx configuration (fedora)
- drop mandatory dependency on httpd (suggested) #1336091
- protect php files in uploads directory
* Tue May 10 2016 Remi Collet <remi@fedoraproject.org> - 4.5.2-1
- WordPress 4.5.2 Security Release
* Wed Apr 27 2016 Remi Collet <remi@fedoraproject.org> - 4.5.1-1
- WordPress 4.5.1 Maintenance Release
* Wed Apr 13 2016 Remi Collet <remi@fedoraproject.org> - 4.5-1
- WordPress 4.5 “Coleman”
* Fri Mar 25 2016 Remi Collet <remi@fedoraproject.org> - 4.5-0.1.RC1
- WordPress 4.5 Release Candidate
* Wed Feb 3 2016 Remi Collet <remi@fedoraproject.org> - 4.4.2-1
- WordPress 4.4.2 Security and Maintenance Release
* Thu Jan 7 2016 Remi Collet <remi@fedoraproject.org> - 4.4.1-1
- WordPress 4.4.1 Security and Maintenance Release
* Wed Dec 9 2015 Remi Collet <remi@fedoraproject.org> - 4.4-1
- WordPress 4.4 “Clifford”
* Wed Sep 16 2015 Remi Collet <remi@fedoraproject.org> - 4.3.1-1
- WordPress 4.3.1 Security and Maintenance Release
* Wed Aug 26 2015 Remi Collet <remi@fedoraproject.org> - 4.3-1
- WordPress 4.3 “Billie”
* Tue Aug 4 2015 Remi Collet <remi@fedoraproject.org> - 4.2.4-1
- WordPress 4.2.4 Security and Maintenance Release
* Fri Jul 24 2015 Remi Collet <remi@fedoraproject.org> - 4.2.3-1
- WordPress 4.2.3 Security and Maintenance Release
* Fri Jun 19 2015 Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 4.2.2-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_23_Mass_Rebuild
* Thu May 7 2015 Remi Collet <remi@fedoraproject.org> - 4.2.2-1
- WordPress 4.2.2 Security and Maintenance Release
* Tue Apr 28 2015 Remi Collet <remi@fedoraproject.org> - 4.2.1-1
- WordPress 4.2.1 Security Release
* Fri Apr 24 2015 Remi Collet <remi@fedoraproject.org> - 4.2-1
- WordPress 4.2 “Powell”
* Thu Apr 23 2015 Remi Collet <remi@fedoraproject.org> - 4.1.2-1
- WordPress 4.1.2 Security Release
* Thu Feb 19 2015 Remi Collet <remi@fedoraproject.org> - 4.1.1-1
- WordPress 4.1.1 Maintenance Release
* Mon Dec 22 2014 Remi Collet <remi@fedoraproject.org> - 4.1-1
- WordPress 4.1 “Dinah”
* Fri Nov 21 2014 Remi Collet <remi@fedoraproject.org> - 4.0.1-1
- WordPress 4.0.1 Security Release
* Tue Sep 30 2014 Remi Collet <remi@fedoraproject.org> - 4.0-3
- use system php-getid3 when available #1145574
* Mon Sep 8 2014 Remi Collet <remi@fedoraproject.org> - 4.0-1
- WordPress 4.0 “Benny”
* Fri Aug 8 2014 Remi Collet <remi@fedoraproject.org> - 3.9.2-3
- config dir only readable by apache group, better fix for #1124582
- fix license handling
* Thu Aug 7 2014 Remi Collet <remi@fedoraproject.org> - 3.9.2-2
- update to 3.9.2 Security Release #1127547
- config file only readable by apache user (httpd or php-fpm) #1124582
* Sun Jun 08 2014 Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 3.9.1-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild
* Fri May 9 2014 Remi Collet <remi@fedoraproject.org> - 3.9.1-1
- update to 3.9.1 Maintenance Release
* Wed May 7 2014 Remi Collet <remi@fedoraproject.org> - 3.9-1
- update to 3.9 “Smith”
* Tue Apr 15 2014 Remi Collet <remi@fedoraproject.org> - 3.8.3-1
- update to 3.8.3 Maintenance Release
http://wordpress.org/news/2014/04/wordpress-3-8-3/
* Wed Apr 9 2014 Remi Collet <remi@fedoraproject.org> - 3.8.2-1
- update to 3.8.2 Security Release
- fix privilege escalation issue CVE-2014-0165
- fix authentication bypass issue CVE-2014-0166
* Sat Jan 25 2014 Remi Collet <remi@fedoraproject.org> - 3.8.1-3
- ignore WP_AUTO_UPDATE_CORE (always false)
* Fri Jan 24 2014 Remi Collet <remi@fedoraproject.org> - 3.8.1-2
- comment provided configuration about auto-updater
- disable auto-updater on default configuration #1057521
- switch some sed to patch (more robust)
* Thu Jan 23 2014 Adam Williamson <awilliam@redhat.com> - 3.8.1-1
- new upstream release 3.8.1 (bugfixes)
* Mon Dec 16 2013 Remi Collet <rcollet@redhat.com> - 3.8-1
- update to 3.8 “Parker” #1043104
- link to README.fedora in package description
- add note about optional packages #1037516
- add php dependencies: ereg, ftp, gd, xml
- del php dependencies: pdo, reflection
* Wed Oct 30 2013 Remi Collet <rcollet@redhat.com> - 3.7.1-1
- update to 3.7.1 (bugfixes)