Repository navigation
Repair wp/6.5 branch Actions: Fix wp-env Docker builds broken by archived Debian Buster/Bullseye repositories and expired Debian Stretch signing keys - #127
Closed
desrosj wants to merge 4 commits into
Conversation
desrosj
removed this pull request from stack #87
September 10, 2026 19:37
desrosj
force-pushed
the
fix-actions-6.5/fix-wp-env-debian-buster
branch
from
September 10, 2026 19:39
3896345 to
074e8bc
Compare
desrosj
added this pull request to stack #190
September 10, 2026 19:40
desrosj
force-pushed
the
fix-actions-6.5/fix-wp-env-debian-buster
branch
from
September 11, 2026 00:04
074e8bc to
67f0913
Compare
desrosj
force-pushed
the
fix-actions-6.5/fix-wp-env-debian-buster
branch
from
September 11, 2026 00:29
67f0913 to
19ca8d4
Compare
desrosj
force-pushed
the
fix-actions-6.5/fix-wp-env-debian-buster
branch
from
September 11, 2026 01:14
19ca8d4 to
9595584
Compare
desrosj
force-pushed
the
fix-actions-6.5/fix-wp-env-debian-buster
branch
from
September 11, 2026 02:18
9595584 to
4e62fe0
Compare
desrosj
force-pushed
the
fix-actions-6.5/fix-wp-env-debian-buster
branch
from
September 11, 2026 02:31
4e62fe0 to
1afffa1
Compare
desrosj
marked this pull request as ready for review
September 11, 2026 03:11
desrosj
marked this pull request as draft
September 11, 2026 03:21
|
The following accounts have interacted with this PR and/or linked issues. I will continue to update these lists as activity occurs. You can also manually ask me to refresh this list by adding the If you're merging code through a pull request on GitHub, copy and paste the following into the bottom of the merge commit message. To understand the WordPress project's expectations around crediting contributors, please review the Contributor Attribution page in the Core Handbook. |
wp/6.5 branch Actions: Fix wp-env Docker builds broken by archived Debian Buster repositorieswp/6.5 branch Actions: Fix wp-env Docker builds broken by archived Debian Buster and Bullseye repositories
desrosj
force-pushed
the
fix-actions-6.5/fix-wp-env-debian-buster
branch
from
September 13, 2026 01:28
9603c85 to
b303b86
Compare
desrosj
added a commit
that referenced
this pull request
Sep 13, 2026
…ning keys. wp-env's existing archive.debian.org rewrite already redirects the Stretch suite's package mirrors (used by the PHP 7.0/7.1 Docker images), since Debian moved Stretch to its archive server. Since then, the archive's own Stretch-suite GPG signing keys have themselves expired, with no replacement key ever going to be published for this now fully end-of-life suite (unlike Buster/Bullseye, whose archived keys are still valid). apt-get -qy update still succeeds (with GPG warnings), but apt-get -qy install $PHPIZE_DEPS then fails with: E: There were unauthenticated packages and -y was used without --allow-unauthenticated This adds a conditional apt.conf.d override that allows unauthenticated packages, scoped to only take effect when the Stretch suite is actually present in /etc/apt/sources.list (matching how the existing stretch/buster/bullseye sed rewrites above it are each scoped by matching suite name rather than by PHP version), so Buster, Bullseye, and any newer Debian-based build stay unaffected. Ported verbatim from wp/6.5's equivalent fix (#127).
wp/6.5 branch Actions: Fix wp-env Docker builds broken by archived Debian Buster and Bullseye repositorieswp/6.5 branch Actions: Fix wp-env Docker builds broken by archived Debian Buster/Bullseye repositories and expired Debian Stretch signing keys
desrosj
added a commit
that referenced
this pull request
Sep 13, 2026
…ning keys. wp-env's existing archive.debian.org rewrite already redirects the Stretch suite's package mirrors (used by the PHP 7.0/7.1 Docker images), since Debian moved Stretch to its archive server. Since then, the archive's own Stretch-suite GPG signing keys have themselves expired, with no replacement key ever going to be published for this now fully end-of-life suite (unlike Buster/Bullseye, whose archived keys are still valid). apt-get -qy update still succeeds (with GPG warnings), but apt-get -qy install $PHPIZE_DEPS then fails with: E: There were unauthenticated packages and -y was used without --allow-unauthenticated This adds a conditional apt.conf.d override that allows unauthenticated packages, scoped to only take effect when the Stretch suite is actually present in /etc/apt/sources.list (matching how the existing stretch/bullseye sed rewrites above it are each scoped by matching suite name rather than by PHP version), so Bullseye and any newer Debian-based build stay unaffected. This branch has no Buster block to worry about (wp/6.3 never had the Buster fix backported), unlike wp/6.4/wp/6.5. Ported verbatim from wp/6.5's equivalent fix (#127), already also ported to wp/6.4 (#126).
desrosj
added a commit
that referenced
this pull request
Sep 14, 2026
…ning keys. wp-env's existing archive.debian.org rewrite already redirects the Stretch suite's package mirrors (used by the PHP 7.0/7.1 Docker images), since Debian moved Stretch to its archive server. Since then, the archive's own Stretch-suite GPG signing keys have themselves expired, with no replacement key ever going to be published for this now fully end-of-life suite (unlike Buster/Bullseye, whose archived keys are still valid). apt-get -qy update still succeeds (with GPG warnings), but apt-get -qy install $PHPIZE_DEPS then fails with: E: There were unauthenticated packages and -y was used without --allow-unauthenticated This adds a conditional apt.conf.d override that allows unauthenticated packages, scoped to only take effect when the Stretch suite is actually present in /etc/apt/sources.list (matching how the existing stretch/buster/bullseye sed rewrites above it are each scoped by matching suite name rather than by PHP version), so Buster, Bullseye, and any newer Debian-based build stay unaffected. Ported verbatim from wp/6.5's equivalent fix (#127).
desrosj
added a commit
that referenced
this pull request
Sep 14, 2026
…ning keys. wp-env's existing archive.debian.org rewrite already redirects the Stretch suite's package mirrors (used by the PHP 7.0/7.1 Docker images), since Debian moved Stretch to its archive server. Since then, the archive's own Stretch-suite GPG signing keys have themselves expired, with no replacement key ever going to be published for this now fully end-of-life suite (unlike Buster/Bullseye, whose archived keys are still valid). apt-get -qy update still succeeds (with GPG warnings), but apt-get -qy install $PHPIZE_DEPS then fails with: E: There were unauthenticated packages and -y was used without --allow-unauthenticated This adds a conditional apt.conf.d override that allows unauthenticated packages, scoped to only take effect when the Stretch suite is actually present in /etc/apt/sources.list (matching how the existing stretch/bullseye sed rewrites above it are each scoped by matching suite name rather than by PHP version), so Bullseye and any newer Debian-based build stay unaffected. This branch has no Buster block to worry about (wp/6.3 never had the Buster fix backported), unlike wp/6.4/wp/6.5. Ported verbatim from wp/6.5's equivalent fix (#127), already also ported to wp/6.4 (#126).
desrosj
force-pushed
the
fix-actions-6.5/fix-wp-env-debian-buster
branch
from
September 14, 2026 01:57
299e069 to
edc741b
Compare
desrosj
added a commit
that referenced
this pull request
Sep 14, 2026
…ning keys. wp-env's existing archive.debian.org rewrite already redirects the Stretch suite's package mirrors (used by the PHP 7.0/7.1 Docker images), since Debian moved Stretch to its archive server. Since then, the archive's own Stretch-suite GPG signing keys have themselves expired, with no replacement key ever going to be published for this now fully end-of-life suite (unlike Buster/Bullseye, whose archived keys are still valid). apt-get -qy update still succeeds (with GPG warnings), but apt-get -qy install $PHPIZE_DEPS then fails with: E: There were unauthenticated packages and -y was used without --allow-unauthenticated This adds a conditional apt.conf.d override that allows unauthenticated packages, scoped to only take effect when the Stretch suite is actually present in /etc/apt/sources.list (matching how the existing stretch/bullseye sed rewrites above it are each scoped by matching suite name rather than by PHP version), so Bullseye and any newer Debian-based build stay unaffected. This branch has no Buster block to worry about (wp/6.3 never had the Buster fix backported), unlike wp/6.4/wp/6.5. Ported verbatim from wp/6.5's equivalent fix (#127), already also ported to wp/6.4 (#126).
desrosj
marked this pull request as ready for review
September 15, 2026 19:02
desrosj
added a commit
that referenced
this pull request
Sep 15, 2026
…ning keys. wp-env's existing archive.debian.org rewrite already redirects the Stretch suite's package mirrors (used by the PHP 7.0/7.1 Docker images), since Debian moved Stretch to its archive server. Since then, the archive's own Stretch-suite GPG signing keys have themselves expired, with no replacement key ever going to be published for this now fully end-of-life suite (unlike Buster/Bullseye, whose archived keys are still valid). apt-get -qy update still succeeds (with GPG warnings), but apt-get -qy install $PHPIZE_DEPS then fails with: E: There were unauthenticated packages and -y was used without --allow-unauthenticated This adds a conditional apt.conf.d override that allows unauthenticated packages, scoped to only take effect when the Stretch suite is actually present in /etc/apt/sources.list (matching how the existing stretch/bullseye sed rewrites above it are each scoped by matching suite name rather than by PHP version), so Bullseye and any newer Debian-based build stay unaffected. This branch has no Buster block to worry about (wp/6.3 never had the Buster fix backported), unlike wp/6.4/wp/6.5. Ported verbatim from wp/6.5's equivalent fix (#127), already also ported to wp/6.4 (#126).
…Press#70718) Co-authored-by: t-hamano <wildworks@git.wordpress.org> Co-authored-by: Mamaduka <mamaduka@git.wordpress.org>
Cherry-picks d21304e (WordPress#82478) into the `wp/6.5` branch to fix failures encountered when attempting to use a version of PHP that relies on Debian Bullseye. Debian 11 ("bullseye") reached end-of-life on 2026-08-31 and its packages left the regular mirrors. Since then, `wp-env start`'s Docker build for the bullseye-based WordPress images fails during `apt-get -qy install sudo` with 404s against `deb.debian.org`. This is the same class of problem as the earlier Buster fix in this same PR, now extended to the Bullseye suite: point it at `archive.debian.org`, dropping the `bullseye-security`/`bullseye-updates` suites entirely (rather than rewriting them) since `archive.debian.org` doesn't carry `bullseye-security` yet.
…ning keys. `wp-env`'s existing `archive.debian.org` rewrite already redirects the Stretch suite's package mirrors (used by the `PHP 7.0`/`7.1` Docker images), since Debian moved Stretch to its archive server. Since then, the archive's own Stretch-suite GPG signing keys have themselves expired, with no replacement key ever going to be published for this now fully end-of-life suite (unlike Buster/Bullseye, whose archived keys are still valid). `apt-get -qy update` still succeeds (with GPG warnings), but `apt-get -qy install $PHPIZE_DEPS` then fails with: ``` E: There were unauthenticated packages and -y was used without --allow-unauthenticated ``` This adds a conditional `apt.conf.d` override that allows unauthenticated packages, scoped to only take effect when the Stretch suite is actually present in `/etc/apt/sources.list` (matching how the existing `stretch`/`buster`/`bullseye` `sed` rewrites above it are each scoped by matching suite name rather than by PHP version), so Buster, Bullseye, and any newer Debian-based build stay unaffected. Verified directly against a real `wordpress:php7.0` image: `apt-get -qy install $PHPIZE_DEPS`/`git`/`sudo` all fail without this change and succeed with it.
packages/README.md requires a changelog entry under "Unreleased" for every package PR. This PR's wp-env fix spans all three affected Debian suites (Stretch, Buster, and Bullseye), so the entry covers all three rather than just one.
desrosj
added a commit
that referenced
this pull request
Sep 15, 2026
…ning keys. wp-env's existing archive.debian.org rewrite already redirects the Stretch suite's package mirrors (used by the PHP 7.0/7.1 Docker images), since Debian moved Stretch to its archive server. Since then, the archive's own Stretch-suite GPG signing keys have themselves expired, with no replacement key ever going to be published for this now fully end-of-life suite (unlike Buster/Bullseye, whose archived keys are still valid). apt-get -qy update still succeeds (with GPG warnings), but apt-get -qy install $PHPIZE_DEPS then fails with: E: There were unauthenticated packages and -y was used without --allow-unauthenticated This adds a conditional apt.conf.d override that allows unauthenticated packages, scoped to only take effect when the Stretch suite is actually present in /etc/apt/sources.list (matching how the existing stretch/buster/bullseye sed rewrites above it are each scoped by matching suite name rather than by PHP version), so Buster, Bullseye, and any newer Debian-based build stay unaffected. Ported verbatim from wp/6.5's equivalent fix (#127).
desrosj
force-pushed
the
fix-actions-6.5/fix-wp-env-debian-buster
branch
from
September 15, 2026 19:23
5ccf30d to
72e9377
Compare
desrosj
removed this pull request from stack #190
September 15, 2026 21:18
desrosj
added this pull request to stack #376
September 15, 2026 21:22
Owner
Author
|
Migrated to the real |
desrosj
added a commit
that referenced
this pull request
Sep 21, 2026
…ning keys. wp-env's existing archive.debian.org rewrite already redirects the Stretch suite's package mirrors (used by the PHP 7.0/7.1 Docker images), since Debian moved Stretch to its archive server. Since then, the archive's own Stretch-suite GPG signing keys have themselves expired, with no replacement key ever going to be published for this now fully end-of-life suite (unlike Buster/Bullseye, whose archived keys are still valid). apt-get -qy update still succeeds (with GPG warnings), but apt-get -qy install $PHPIZE_DEPS then fails with: E: There were unauthenticated packages and -y was used without --allow-unauthenticated This adds a conditional apt.conf.d override that allows unauthenticated packages, scoped to only take effect when the Stretch suite is actually present in /etc/apt/sources.list (matching how the existing stretch/bullseye sed rewrites above it are each scoped by matching suite name rather than by PHP version), so Bullseye and any newer Debian-based build stay unaffected. This branch has no Buster block to worry about (wp/6.3 never had the Buster fix backported), unlike wp/6.4/wp/6.5. Ported verbatim from wp/6.5's equivalent fix (#127), already also ported to wp/6.4 (#126).
desrosj
added a commit
that referenced
this pull request
Sep 21, 2026
…ning keys. wp-env's existing archive.debian.org rewrite already redirects the Stretch suite's package mirrors (used by the PHP 7.0/7.1 Docker images), since Debian moved Stretch to its archive server. Since then, the archive's own Stretch-suite GPG signing keys have themselves expired, with no replacement key ever going to be published for this now fully end-of-life suite (unlike Buster/Bullseye, whose archived keys are still valid). apt-get -qy update still succeeds (with GPG warnings), but apt-get -qy install $PHPIZE_DEPS then fails with: E: There were unauthenticated packages and -y was used without --allow-unauthenticated This adds a conditional apt.conf.d override that allows unauthenticated packages, scoped to only take effect when the Stretch suite is actually present in /etc/apt/sources.list (matching how the existing stretch/bullseye sed rewrites above it are each scoped by matching suite name rather than by PHP version), so Bullseye and any newer Debian-based build stay unaffected. This branch has no Buster block to worry about (wp/6.3 never had the Buster fix backported), unlike wp/6.4/wp/6.5. Ported verbatim from wp/6.5's equivalent fix (#127), already also ported to wp/6.4 (#126).
desrosj
added a commit
that referenced
this pull request
Sep 21, 2026
…ning keys. wp-env's existing archive.debian.org rewrite already redirects the Stretch suite's package mirrors (used by the PHP 7.0/7.1 Docker images), since Debian moved Stretch to its archive server. Since then, the archive's own Stretch-suite GPG signing keys have themselves expired, with no replacement key ever going to be published for this now fully end-of-life suite (unlike Buster/Bullseye, whose archived keys are still valid). apt-get -qy update still succeeds (with GPG warnings), but apt-get -qy install $PHPIZE_DEPS then fails with: E: There were unauthenticated packages and -y was used without --allow-unauthenticated This adds a conditional apt.conf.d override that allows unauthenticated packages, scoped to only take effect when the Stretch suite is actually present in /etc/apt/sources.list (matching how the existing stretch/buster/bullseye sed rewrites above it are each scoped by matching suite name rather than by PHP version), so Buster, Bullseye, and any newer Debian-based build stay unaffected. Ported verbatim from wp/6.5's equivalent fix (#127).
desrosj
added a commit
that referenced
this pull request
Sep 21, 2026
…ning keys. wp-env's existing archive.debian.org rewrite already redirects the Stretch suite's package mirrors (used by the PHP 7.0/7.1 Docker images), since Debian moved Stretch to its archive server. Since then, the archive's own Stretch-suite GPG signing keys have themselves expired, with no replacement key ever going to be published for this now fully end-of-life suite (unlike Buster/Bullseye, whose archived keys are still valid). apt-get -qy update still succeeds (with GPG warnings), but apt-get -qy install $PHPIZE_DEPS then fails with: E: There were unauthenticated packages and -y was used without --allow-unauthenticated This adds a conditional apt.conf.d override that allows unauthenticated packages, scoped to only take effect when the Stretch suite is actually present in /etc/apt/sources.list (matching how the existing stretch/buster/bullseye sed rewrites above it are each scoped by matching suite name rather than by PHP version), so Buster, Bullseye, and any newer Debian-based build stay unaffected. Ported verbatim from wp/6.5's equivalent fix (#127), already also ported to wp/6.4 (#126). Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01DtSAAJkQ9P6vPtDumqStg8
desrosj
added a commit
that referenced
this pull request
Sep 21, 2026
…ning keys. wp-env's existing archive.debian.org rewrite already redirects the Stretch suite's package mirrors (used by the PHP 7.0/7.1 Docker images), since Debian moved Stretch to its archive server. Since then, the archive's own Stretch-suite GPG signing keys have themselves expired, with no replacement key ever going to be published for this now fully end-of-life suite (unlike Buster/Bullseye, whose archived keys are still valid). apt-get -qy update still succeeds (with GPG warnings), but apt-get -qy install $PHPIZE_DEPS then fails with: E: There were unauthenticated packages and -y was used without --allow-unauthenticated This adds a conditional apt.conf.d override that allows unauthenticated packages, scoped to only take effect when the Stretch suite is actually present in /etc/apt/sources.list (matching how the existing stretch/buster/bullseye sed rewrites above it are each scoped by matching suite name rather than by PHP version), so Buster, Bullseye, and any newer Debian-based build stay unaffected. Ported verbatim from wp/6.5's equivalent fix (#127).
desrosj
added a commit
that referenced
this pull request
Sep 21, 2026
…ning keys. wp-env's existing archive.debian.org rewrite already redirects the Stretch suite's package mirrors (used by the PHP 7.0/7.1 Docker images), since Debian moved Stretch to its archive server. Since then, the archive's own Stretch-suite GPG signing keys have themselves expired, with no replacement key ever going to be published for this now fully end-of-life suite (unlike Buster/Bullseye, whose archived keys are still valid). apt-get -qy update still succeeds (with GPG warnings), but apt-get -qy install $PHPIZE_DEPS then fails with: E: There were unauthenticated packages and -y was used without --allow-unauthenticated This adds a conditional apt.conf.d override that allows unauthenticated packages, scoped to only take effect when the Stretch suite is actually present in /etc/apt/sources.list (matching how the existing stretch/buster/bullseye sed rewrites above it are each scoped by matching suite name rather than by PHP version), so Buster, Bullseye, and any newer Debian-based build stay unaffected. Ported verbatim from wp/6.5's equivalent fix (#127).
desrosj
added a commit
that referenced
this pull request
Sep 21, 2026
…ning keys. wp-env's existing archive.debian.org rewrite already redirects the Stretch suite's package mirrors (used by the PHP 7.0/7.1 Docker images), since Debian moved Stretch to its archive server. Since then, the archive's own Stretch-suite GPG signing keys have themselves expired, with no replacement key ever going to be published for this now fully end-of-life suite (unlike Buster/Bullseye, whose archived keys are still valid). apt-get -qy update still succeeds (with GPG warnings), but apt-get -qy install $PHPIZE_DEPS then fails with: E: There were unauthenticated packages and -y was used without --allow-unauthenticated This adds a conditional apt.conf.d override that allows unauthenticated packages, scoped to only take effect when the Stretch suite is actually present in /etc/apt/sources.list (matching how the existing stretch/buster/bullseye sed rewrites above it are each scoped by matching suite name rather than by PHP version), so Buster, Bullseye, and any newer Debian-based build stay unaffected. Ported verbatim from wp/6.5's equivalent fix (#127).
desrosj
added a commit
that referenced
this pull request
Sep 22, 2026
…ning keys. wp-env's existing archive.debian.org rewrite already redirects the Stretch suite's package mirrors (used by the PHP 7.0/7.1 Docker images), since Debian moved Stretch to its archive server. Since then, the archive's own Stretch-suite GPG signing keys have themselves expired, with no replacement key ever going to be published for this now fully end-of-life suite (unlike Buster/Bullseye, whose archived keys are still valid). apt-get -qy update still succeeds (with GPG warnings), but apt-get -qy install $PHPIZE_DEPS then fails with: E: There were unauthenticated packages and -y was used without --allow-unauthenticated This adds a conditional apt.conf.d override that allows unauthenticated packages, scoped to only take effect when the Stretch suite is actually present in /etc/apt/sources.list (matching how the existing stretch/buster/bullseye sed rewrites above it are each scoped by matching suite name rather than by PHP version), so Buster, Bullseye, and any newer Debian-based build stay unaffected. Ported verbatim from wp/6.5's equivalent fix (#127).
desrosj
added a commit
that referenced
this pull request
Sep 22, 2026
…ning keys. wp-env's existing archive.debian.org rewrite already redirects the Stretch suite's package mirrors (used by the PHP 7.0/7.1 Docker images), since Debian moved Stretch to its archive server. Since then, the archive's own Stretch-suite GPG signing keys have themselves expired, with no replacement key ever going to be published for this now fully end-of-life suite (unlike Buster/Bullseye, whose archived keys are still valid). apt-get -qy update still succeeds (with GPG warnings), but apt-get -qy install $PHPIZE_DEPS then fails with: E: There were unauthenticated packages and -y was used without --allow-unauthenticated This adds a conditional apt.conf.d override that allows unauthenticated packages, scoped to only take effect when the Stretch suite is actually present in /etc/apt/sources.list (matching how the existing stretch/buster/bullseye sed rewrites above it are each scoped by matching suite name rather than by PHP version), so Buster, Bullseye, and any newer Debian-based build stay unaffected. Ported verbatim from wp/6.5's equivalent fix (#127), already also ported to wp/6.4 (#126). Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01DtSAAJkQ9P6vPtDumqStg8
desrosj
added a commit
that referenced
this pull request
Sep 22, 2026
…ning keys. wp-env's existing archive.debian.org rewrite already redirects the Stretch suite's package mirrors (used by the PHP 7.0/7.1 Docker images), since Debian moved Stretch to its archive server. Since then, the archive's own Stretch-suite GPG signing keys have themselves expired, with no replacement key ever going to be published for this now fully end-of-life suite (unlike Buster/Bullseye, whose archived keys are still valid). apt-get -qy update still succeeds (with GPG warnings), but apt-get -qy install $PHPIZE_DEPS then fails with: E: There were unauthenticated packages and -y was used without --allow-unauthenticated This adds a conditional apt.conf.d override that allows unauthenticated packages, scoped to only take effect when the Stretch suite is actually present in /etc/apt/sources.list (matching how the existing stretch/buster/bullseye sed rewrites above it are each scoped by matching suite name rather than by PHP version), so Buster, Bullseye, and any newer Debian-based build stay unaffected. Ported verbatim from wp/6.5's equivalent fix (#127), already also ported to wp/6.4 (#126). Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01DtSAAJkQ9P6vPtDumqStg8
desrosj
added a commit
that referenced
this pull request
Sep 22, 2026
…ning keys. wp-env's existing archive.debian.org rewrite already redirects the Stretch suite's package mirrors (used by the PHP 7.0/7.1 Docker images), since Debian moved Stretch to its archive server. Since then, the archive's own Stretch-suite GPG signing keys have themselves expired, with no replacement key ever going to be published for this now fully end-of-life suite (unlike Buster/Bullseye, whose archived keys are still valid). apt-get -qy update still succeeds (with GPG warnings), but apt-get -qy install $PHPIZE_DEPS then fails with: E: There were unauthenticated packages and -y was used without --allow-unauthenticated This adds a conditional apt.conf.d override that allows unauthenticated packages, scoped to only take effect when the Stretch suite is actually present in /etc/apt/sources.list (matching how the existing stretch/buster/bullseye sed rewrites above it are each scoped by matching suite name rather than by PHP version), so Buster, Bullseye, and any newer Debian-based build stay unaffected. Ported verbatim from wp/6.5's equivalent fix (#127).
desrosj
added a commit
that referenced
this pull request
Sep 23, 2026
…ning keys. wp-env's existing archive.debian.org rewrite already redirects the Stretch suite's package mirrors (used by the PHP 7.0/7.1 Docker images), since Debian moved Stretch to its archive server. Since then, the archive's own Stretch-suite GPG signing keys have themselves expired, with no replacement key ever going to be published for this now fully end-of-life suite (unlike Buster/Bullseye, whose archived keys are still valid). apt-get -qy update still succeeds (with GPG warnings), but apt-get -qy install $PHPIZE_DEPS then fails with: E: There were unauthenticated packages and -y was used without --allow-unauthenticated This adds a conditional apt.conf.d override that allows unauthenticated packages, scoped to only take effect when the Stretch suite is actually present in /etc/apt/sources.list (matching how the existing stretch/buster/bullseye sed rewrites above it are each scoped by matching suite name rather than by PHP version), so Buster, Bullseye, and any newer Debian-based build stay unaffected. Ported verbatim from wp/6.5's equivalent fix (#127).
desrosj
added a commit
that referenced
this pull request
Sep 23, 2026
…ning keys. wp-env's existing archive.debian.org rewrite already redirects the Stretch suite's package mirrors (used by the PHP 7.0/7.1 Docker images), since Debian moved Stretch to its archive server. Since then, the archive's own Stretch-suite GPG signing keys have themselves expired, with no replacement key ever going to be published for this now fully end-of-life suite (unlike Buster/Bullseye, whose archived keys are still valid). apt-get -qy update still succeeds (with GPG warnings), but apt-get -qy install $PHPIZE_DEPS then fails with: E: There were unauthenticated packages and -y was used without --allow-unauthenticated This adds a conditional apt.conf.d override that allows unauthenticated packages, scoped to only take effect when the Stretch suite is actually present in /etc/apt/sources.list (matching how the existing stretch/buster/bullseye sed rewrites above it are each scoped by matching suite name rather than by PHP version), so Buster, Bullseye, and any newer Debian-based build stay unaffected. Ported verbatim from wp/6.5's equivalent fix (#127), already also ported to wp/6.4 (#126). Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01DtSAAJkQ9P6vPtDumqStg8
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What?
Cherry-picks two upstream trunk fixes, plus one additional hand-written fix, into this branch's
wp-envpackage source (packages/env/lib/init-config.js) to fix Docker build failures caused by Debian repositories being archived after their releases reached end-of-life:cc1f5bd2698f99f03ab05517087aee98cc797ed3(#70718) — Debian Buster.d21304e3323571401364805242fc26d1cf03a52d(#82478) — Debian Bullseye.Why?
Debian moves a release's package repositories to its archive server once that release reaches end-of-life.
wp-env start's Docker build fails withapt-get404s against the regular mirrors for any PHP version whose base image relies on an archived Debian release. This branch supports PHP versions across the range affected by Buster, Bullseye, and Stretch, so all three fixes are needed — even for PHP versions this branch doesn't actively test in CI, since a contributor may still need to runwp-envlocally against any officially supported version.Stretch is a further, distinct case: the existing
archive.debian.orgURL rewrite is enough to fix Buster and Bullseye, but Stretch's own signing keys on the archive have themselves since expired, with no replacement ever going to be published.apt-get -qy updatestill succeeds (with GPG warnings), but the followingapt-get -qy installsteps then fail with:This is fixed with a conditional
apt.conf.doverride that allows unauthenticated packages, scoped to only take effect when the Stretch suite is actually present in/etc/apt/sources.list— matching how the existingstretch/buster/bullseyesedrewrites above it are each scoped by matching suite name rather than by PHP version, so Buster, Bullseye, and any newer Debian-based build stay unaffected. Verified directly against a realwordpress:php7.0image:apt-get -qy install $PHPIZE_DEPS/git/sudoall fail without this change and succeed with it.Use of AI Tools
This PR was created by Claude Code under my supervision. All code should be treated as AI-produced and not yet reviewed by a human until this PR is marked Ready for Review.