Skip to content

Repair wp/6.5 branch Actions: Fix wp-env Docker builds broken by archived Debian Buster/Bullseye repositories and expired Debian Stretch signing keys - #127

Closed
desrosj wants to merge 4 commits into
fix-actions-6.5/fix-composer-platform-overridefrom
fix-actions-6.5/fix-wp-env-debian-buster
Closed

desrosj wants to merge 4 commits into
fix-actions-6.5/fix-composer-platform-overridefrom
fix-actions-6.5/fix-wp-env-debian-buster

Conversation

@desrosj

@desrosj desrosj commented Aug 29, 2026 •

Copy link
Copy Markdown
Owner

What?

Cherry-picks two upstream trunk fixes, plus one additional hand-written fix, into this branch's wp-env package source (packages/env/lib/init-config.js) to fix Docker build failures caused by Debian repositories being archived after their releases reached end-of-life:

  • cc1f5bd2698f99f03ab05517087aee98cc797ed3 (#70718) — Debian Buster.
  • d21304e3323571401364805242fc26d1cf03a52d (#82478) — Debian Bullseye.
  • A further fix (no upstream commit to port — this issue doesn't exist on trunk) for Debian Stretch's archive mirror now also having expired GPG signing keys, with no replacement key ever going to be published for this fully end-of-life suite.

Why?

Debian moves a release's package repositories to its archive server once that release reaches end-of-life. wp-env start's Docker build fails with apt-get 404s against the regular mirrors for any PHP version whose base image relies on an archived Debian release. This branch supports PHP versions across the range affected by Buster, Bullseye, and Stretch, so all three fixes are needed — even for PHP versions this branch doesn't actively test in CI, since a contributor may still need to run wp-env locally against any officially supported version.

Stretch is a further, distinct case: the existing archive.debian.org URL rewrite is enough to fix Buster and Bullseye, but Stretch's own signing keys on the archive have themselves since expired, with no replacement ever going to be published. apt-get -qy update still succeeds (with GPG warnings), but the following apt-get -qy install steps then fail with:

E: There were unauthenticated packages and -y was used without --allow-unauthenticated

This is fixed with a conditional apt.conf.d override that allows unauthenticated packages, scoped to only take effect when the Stretch suite is actually present in /etc/apt/sources.list — matching how the existing stretch/buster/bullseye sed rewrites above it are each scoped by matching suite name rather than by PHP version, so Buster, Bullseye, and any newer Debian-based build stay unaffected. Verified directly against a real wordpress:php7.0 image: apt-get -qy install $PHPIZE_DEPS/git/sudo all fail without this change and succeed with it.

Use of AI Tools

This PR was created by Claude Code under my supervision. All code should be treated as AI-produced and not yet reviewed by a human until this PR is marked Ready for Review.

@desrosj
desrosj removed this pull request from stack #87 September 10, 2026 19:37
@desrosj
desrosj force-pushed the fix-actions-6.5/fix-wp-env-debian-buster branch from 3896345 to 074e8bc Compare September 10, 2026 19:39
@desrosj
desrosj added this pull request to stack #190 September 10, 2026 19:40
@desrosj
desrosj force-pushed the fix-actions-6.5/fix-wp-env-debian-buster branch from 074e8bc to 67f0913 Compare September 11, 2026 00:04
@desrosj
desrosj force-pushed the fix-actions-6.5/fix-wp-env-debian-buster branch from 67f0913 to 19ca8d4 Compare September 11, 2026 00:29
@desrosj
desrosj force-pushed the fix-actions-6.5/fix-wp-env-debian-buster branch from 19ca8d4 to 9595584 Compare September 11, 2026 01:14
@desrosj
desrosj force-pushed the fix-actions-6.5/fix-wp-env-debian-buster branch from 9595584 to 4e62fe0 Compare September 11, 2026 02:18
@desrosj
desrosj force-pushed the fix-actions-6.5/fix-wp-env-debian-buster branch from 4e62fe0 to 1afffa1 Compare September 11, 2026 02:31
@desrosj
desrosj marked this pull request as ready for review September 11, 2026 03:11
@desrosj
desrosj marked this pull request as draft September 11, 2026 03:21
@github-actions

github-actions Bot commented Sep 11, 2026 •

Copy link
Copy Markdown

The following accounts have interacted with this PR and/or linked issues. I will continue to update these lists as activity occurs. You can also manually ask me to refresh this list by adding the props-bot label.

If you're merging code through a pull request on GitHub, copy and paste the following into the bottom of the merge commit message.

Co-authored-by: t-hamano <wildworks@git.wordpress.org>
Co-authored-by: desrosj <desrosj@git.wordpress.org>

To understand the WordPress project's expectations around crediting contributors, please review the Contributor Attribution page in the Core Handbook.

@desrosj desrosj changed the title Repair wp/6.5 branch Actions: Fix wp-env Docker builds broken by archived Debian Buster repositories Repair wp/6.5 branch Actions: Fix wp-env Docker builds broken by archived Debian Buster and Bullseye repositories Sep 11, 2026
@desrosj
desrosj force-pushed the fix-actions-6.5/fix-wp-env-debian-buster branch from 9603c85 to b303b86 Compare September 13, 2026 01:28
desrosj added a commit that referenced this pull request Sep 13, 2026
…ning keys.

wp-env's existing archive.debian.org rewrite already redirects the Stretch
suite's package mirrors (used by the PHP 7.0/7.1 Docker images), since
Debian moved Stretch to its archive server. Since then, the archive's own
Stretch-suite GPG signing keys have themselves expired, with no replacement
key ever going to be published for this now fully end-of-life suite (unlike
Buster/Bullseye, whose archived keys are still valid). apt-get -qy update
still succeeds (with GPG warnings), but apt-get -qy install $PHPIZE_DEPS
then fails with:

E: There were unauthenticated packages and -y was used without --allow-unauthenticated

This adds a conditional apt.conf.d override that allows unauthenticated
packages, scoped to only take effect when the Stretch suite is actually
present in /etc/apt/sources.list (matching how the existing
stretch/buster/bullseye sed rewrites above it are each scoped by
matching suite name rather than by PHP version), so Buster, Bullseye, and any
newer Debian-based build stay unaffected.

Ported verbatim from wp/6.5's equivalent fix (#127).
@desrosj desrosj changed the title Repair wp/6.5 branch Actions: Fix wp-env Docker builds broken by archived Debian Buster and Bullseye repositories Repair wp/6.5 branch Actions: Fix wp-env Docker builds broken by archived Debian Buster/Bullseye repositories and expired Debian Stretch signing keys Sep 13, 2026
desrosj added a commit that referenced this pull request Sep 13, 2026
…ning keys.

wp-env's existing archive.debian.org rewrite already redirects the Stretch
suite's package mirrors (used by the PHP 7.0/7.1 Docker images), since
Debian moved Stretch to its archive server. Since then, the archive's own
Stretch-suite GPG signing keys have themselves expired, with no replacement
key ever going to be published for this now fully end-of-life suite (unlike
Buster/Bullseye, whose archived keys are still valid). apt-get -qy update
still succeeds (with GPG warnings), but apt-get -qy install $PHPIZE_DEPS
then fails with:

E: There were unauthenticated packages and -y was used without --allow-unauthenticated

This adds a conditional apt.conf.d override that allows unauthenticated
packages, scoped to only take effect when the Stretch suite is actually
present in /etc/apt/sources.list (matching how the existing
stretch/bullseye sed rewrites above it are each scoped by matching suite
name rather than by PHP version), so Bullseye and any newer Debian-based
build stay unaffected. This branch has no Buster block to worry about
(wp/6.3 never had the Buster fix backported), unlike wp/6.4/wp/6.5.

Ported verbatim from wp/6.5's equivalent fix (#127),
already also ported to wp/6.4 (#126).
desrosj added a commit that referenced this pull request Sep 14, 2026
…ning keys.

wp-env's existing archive.debian.org rewrite already redirects the Stretch
suite's package mirrors (used by the PHP 7.0/7.1 Docker images), since
Debian moved Stretch to its archive server. Since then, the archive's own
Stretch-suite GPG signing keys have themselves expired, with no replacement
key ever going to be published for this now fully end-of-life suite (unlike
Buster/Bullseye, whose archived keys are still valid). apt-get -qy update
still succeeds (with GPG warnings), but apt-get -qy install $PHPIZE_DEPS
then fails with:

E: There were unauthenticated packages and -y was used without --allow-unauthenticated

This adds a conditional apt.conf.d override that allows unauthenticated
packages, scoped to only take effect when the Stretch suite is actually
present in /etc/apt/sources.list (matching how the existing
stretch/buster/bullseye sed rewrites above it are each scoped by
matching suite name rather than by PHP version), so Buster, Bullseye, and any
newer Debian-based build stay unaffected.

Ported verbatim from wp/6.5's equivalent fix (#127).
desrosj added a commit that referenced this pull request Sep 14, 2026
…ning keys.

wp-env's existing archive.debian.org rewrite already redirects the Stretch
suite's package mirrors (used by the PHP 7.0/7.1 Docker images), since
Debian moved Stretch to its archive server. Since then, the archive's own
Stretch-suite GPG signing keys have themselves expired, with no replacement
key ever going to be published for this now fully end-of-life suite (unlike
Buster/Bullseye, whose archived keys are still valid). apt-get -qy update
still succeeds (with GPG warnings), but apt-get -qy install $PHPIZE_DEPS
then fails with:

E: There were unauthenticated packages and -y was used without --allow-unauthenticated

This adds a conditional apt.conf.d override that allows unauthenticated
packages, scoped to only take effect when the Stretch suite is actually
present in /etc/apt/sources.list (matching how the existing
stretch/bullseye sed rewrites above it are each scoped by matching suite
name rather than by PHP version), so Bullseye and any newer Debian-based
build stay unaffected. This branch has no Buster block to worry about
(wp/6.3 never had the Buster fix backported), unlike wp/6.4/wp/6.5.

Ported verbatim from wp/6.5's equivalent fix (#127),
already also ported to wp/6.4 (#126).
@desrosj
desrosj force-pushed the fix-actions-6.5/fix-wp-env-debian-buster branch from 299e069 to edc741b Compare September 14, 2026 01:57
desrosj added a commit that referenced this pull request Sep 14, 2026
…ning keys.

wp-env's existing archive.debian.org rewrite already redirects the Stretch
suite's package mirrors (used by the PHP 7.0/7.1 Docker images), since
Debian moved Stretch to its archive server. Since then, the archive's own
Stretch-suite GPG signing keys have themselves expired, with no replacement
key ever going to be published for this now fully end-of-life suite (unlike
Buster/Bullseye, whose archived keys are still valid). apt-get -qy update
still succeeds (with GPG warnings), but apt-get -qy install $PHPIZE_DEPS
then fails with:

E: There were unauthenticated packages and -y was used without --allow-unauthenticated

This adds a conditional apt.conf.d override that allows unauthenticated
packages, scoped to only take effect when the Stretch suite is actually
present in /etc/apt/sources.list (matching how the existing
stretch/bullseye sed rewrites above it are each scoped by matching suite
name rather than by PHP version), so Bullseye and any newer Debian-based
build stay unaffected. This branch has no Buster block to worry about
(wp/6.3 never had the Buster fix backported), unlike wp/6.4/wp/6.5.

Ported verbatim from wp/6.5's equivalent fix (#127),
already also ported to wp/6.4 (#126).
@desrosj
desrosj marked this pull request as ready for review September 15, 2026 19:02
desrosj added a commit that referenced this pull request Sep 15, 2026
…ning keys.

wp-env's existing archive.debian.org rewrite already redirects the Stretch
suite's package mirrors (used by the PHP 7.0/7.1 Docker images), since
Debian moved Stretch to its archive server. Since then, the archive's own
Stretch-suite GPG signing keys have themselves expired, with no replacement
key ever going to be published for this now fully end-of-life suite (unlike
Buster/Bullseye, whose archived keys are still valid). apt-get -qy update
still succeeds (with GPG warnings), but apt-get -qy install $PHPIZE_DEPS
then fails with:

E: There were unauthenticated packages and -y was used without --allow-unauthenticated

This adds a conditional apt.conf.d override that allows unauthenticated
packages, scoped to only take effect when the Stretch suite is actually
present in /etc/apt/sources.list (matching how the existing
stretch/bullseye sed rewrites above it are each scoped by matching suite
name rather than by PHP version), so Bullseye and any newer Debian-based
build stay unaffected. This branch has no Buster block to worry about
(wp/6.3 never had the Buster fix backported), unlike wp/6.4/wp/6.5.

Ported verbatim from wp/6.5's equivalent fix (#127),
already also ported to wp/6.4 (#126).
t-hamano and others added 4 commits September 15, 2026 15:19
…Press#70718)

Co-authored-by: t-hamano <wildworks@git.wordpress.org>
Co-authored-by: Mamaduka <mamaduka@git.wordpress.org>
Cherry-picks d21304e
(WordPress#82478) into the `wp/6.5` branch to
fix failures encountered when attempting to use a version of PHP that relies on
Debian Bullseye.

Debian 11 ("bullseye") reached end-of-life on 2026-08-31 and its packages left
the regular mirrors. Since then, `wp-env start`'s Docker build for the
bullseye-based WordPress images fails during `apt-get -qy install sudo` with
404s against `deb.debian.org`. This is the same class of problem as the earlier
Buster fix in this same PR, now extended to the Bullseye suite: point it at
`archive.debian.org`, dropping the `bullseye-security`/`bullseye-updates`
suites entirely (rather than rewriting them) since `archive.debian.org` doesn't
carry `bullseye-security` yet.
…ning keys.

`wp-env`'s existing `archive.debian.org` rewrite already redirects the Stretch
suite's package mirrors (used by the `PHP 7.0`/`7.1` Docker images), since
Debian moved Stretch to its archive server. Since then, the archive's own
Stretch-suite GPG signing keys have themselves expired, with no replacement
key ever going to be published for this now fully end-of-life suite (unlike
Buster/Bullseye, whose archived keys are still valid). `apt-get -qy update`
still succeeds (with GPG warnings), but `apt-get -qy install $PHPIZE_DEPS`
then fails with:

```
E: There were unauthenticated packages and -y was used without --allow-unauthenticated
```

This adds a conditional `apt.conf.d` override that allows unauthenticated
packages, scoped to only take effect when the Stretch suite is actually
present in `/etc/apt/sources.list` (matching how the existing
`stretch`/`buster`/`bullseye` `sed` rewrites above it are each scoped by
matching suite name rather than by PHP version), so Buster, Bullseye, and any
newer Debian-based build stay unaffected.

Verified directly against a real `wordpress:php7.0` image: `apt-get -qy
install $PHPIZE_DEPS`/`git`/`sudo` all fail without this change and succeed
with it.
packages/README.md requires a changelog entry under "Unreleased" for
every package PR. This PR's wp-env fix spans all three affected Debian
suites (Stretch, Buster, and Bullseye), so the entry covers all three
rather than just one.
desrosj added a commit that referenced this pull request Sep 15, 2026
…ning keys.

wp-env's existing archive.debian.org rewrite already redirects the Stretch
suite's package mirrors (used by the PHP 7.0/7.1 Docker images), since
Debian moved Stretch to its archive server. Since then, the archive's own
Stretch-suite GPG signing keys have themselves expired, with no replacement
key ever going to be published for this now fully end-of-life suite (unlike
Buster/Bullseye, whose archived keys are still valid). apt-get -qy update
still succeeds (with GPG warnings), but apt-get -qy install $PHPIZE_DEPS
then fails with:

E: There were unauthenticated packages and -y was used without --allow-unauthenticated

This adds a conditional apt.conf.d override that allows unauthenticated
packages, scoped to only take effect when the Stretch suite is actually
present in /etc/apt/sources.list (matching how the existing
stretch/buster/bullseye sed rewrites above it are each scoped by
matching suite name rather than by PHP version), so Buster, Bullseye, and any
newer Debian-based build stay unaffected.

Ported verbatim from wp/6.5's equivalent fix (#127).
@desrosj
desrosj force-pushed the fix-actions-6.5/fix-wp-env-debian-buster branch from 5ccf30d to 72e9377 Compare September 15, 2026 19:23
@desrosj
desrosj removed this pull request from stack #190 September 15, 2026 21:18
@desrosj
desrosj added this pull request to stack #376 September 15, 2026 21:22
@desrosj

desrosj commented Sep 16, 2026

Copy link
Copy Markdown
Owner Author

Migrated to the real WordPress/gutenberg repository as WordPress#82995.

@desrosj desrosj closed this Sep 16, 2026
desrosj added a commit that referenced this pull request Sep 21, 2026
…ning keys.

wp-env's existing archive.debian.org rewrite already redirects the Stretch
suite's package mirrors (used by the PHP 7.0/7.1 Docker images), since
Debian moved Stretch to its archive server. Since then, the archive's own
Stretch-suite GPG signing keys have themselves expired, with no replacement
key ever going to be published for this now fully end-of-life suite (unlike
Buster/Bullseye, whose archived keys are still valid). apt-get -qy update
still succeeds (with GPG warnings), but apt-get -qy install $PHPIZE_DEPS
then fails with:

E: There were unauthenticated packages and -y was used without --allow-unauthenticated

This adds a conditional apt.conf.d override that allows unauthenticated
packages, scoped to only take effect when the Stretch suite is actually
present in /etc/apt/sources.list (matching how the existing
stretch/bullseye sed rewrites above it are each scoped by matching suite
name rather than by PHP version), so Bullseye and any newer Debian-based
build stay unaffected. This branch has no Buster block to worry about
(wp/6.3 never had the Buster fix backported), unlike wp/6.4/wp/6.5.

Ported verbatim from wp/6.5's equivalent fix (#127),
already also ported to wp/6.4 (#126).
desrosj added a commit that referenced this pull request Sep 21, 2026
…ning keys.

wp-env's existing archive.debian.org rewrite already redirects the Stretch
suite's package mirrors (used by the PHP 7.0/7.1 Docker images), since
Debian moved Stretch to its archive server. Since then, the archive's own
Stretch-suite GPG signing keys have themselves expired, with no replacement
key ever going to be published for this now fully end-of-life suite (unlike
Buster/Bullseye, whose archived keys are still valid). apt-get -qy update
still succeeds (with GPG warnings), but apt-get -qy install $PHPIZE_DEPS
then fails with:

E: There were unauthenticated packages and -y was used without --allow-unauthenticated

This adds a conditional apt.conf.d override that allows unauthenticated
packages, scoped to only take effect when the Stretch suite is actually
present in /etc/apt/sources.list (matching how the existing
stretch/bullseye sed rewrites above it are each scoped by matching suite
name rather than by PHP version), so Bullseye and any newer Debian-based
build stay unaffected. This branch has no Buster block to worry about
(wp/6.3 never had the Buster fix backported), unlike wp/6.4/wp/6.5.

Ported verbatim from wp/6.5's equivalent fix (#127),
already also ported to wp/6.4 (#126).
desrosj added a commit that referenced this pull request Sep 21, 2026
…ning keys.

wp-env's existing archive.debian.org rewrite already redirects the Stretch
suite's package mirrors (used by the PHP 7.0/7.1 Docker images), since
Debian moved Stretch to its archive server. Since then, the archive's own
Stretch-suite GPG signing keys have themselves expired, with no replacement
key ever going to be published for this now fully end-of-life suite (unlike
Buster/Bullseye, whose archived keys are still valid). apt-get -qy update
still succeeds (with GPG warnings), but apt-get -qy install $PHPIZE_DEPS
then fails with:

E: There were unauthenticated packages and -y was used without --allow-unauthenticated

This adds a conditional apt.conf.d override that allows unauthenticated
packages, scoped to only take effect when the Stretch suite is actually
present in /etc/apt/sources.list (matching how the existing
stretch/buster/bullseye sed rewrites above it are each scoped by
matching suite name rather than by PHP version), so Buster, Bullseye, and any
newer Debian-based build stay unaffected.

Ported verbatim from wp/6.5's equivalent fix (#127).
desrosj added a commit that referenced this pull request Sep 21, 2026
…ning keys.

wp-env's existing archive.debian.org rewrite already redirects the Stretch
suite's package mirrors (used by the PHP 7.0/7.1 Docker images), since
Debian moved Stretch to its archive server. Since then, the archive's own
Stretch-suite GPG signing keys have themselves expired, with no replacement
key ever going to be published for this now fully end-of-life suite (unlike
Buster/Bullseye, whose archived keys are still valid). apt-get -qy update
still succeeds (with GPG warnings), but apt-get -qy install $PHPIZE_DEPS
then fails with:

E: There were unauthenticated packages and -y was used without --allow-unauthenticated

This adds a conditional apt.conf.d override that allows unauthenticated
packages, scoped to only take effect when the Stretch suite is actually
present in /etc/apt/sources.list (matching how the existing
stretch/buster/bullseye sed rewrites above it are each scoped by matching
suite name rather than by PHP version), so Buster, Bullseye, and any newer
Debian-based build stay unaffected.

Ported verbatim from wp/6.5's equivalent fix (#127),
already also ported to wp/6.4 (#126).

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01DtSAAJkQ9P6vPtDumqStg8
desrosj added a commit that referenced this pull request Sep 21, 2026
…ning keys.

wp-env's existing archive.debian.org rewrite already redirects the Stretch
suite's package mirrors (used by the PHP 7.0/7.1 Docker images), since
Debian moved Stretch to its archive server. Since then, the archive's own
Stretch-suite GPG signing keys have themselves expired, with no replacement
key ever going to be published for this now fully end-of-life suite (unlike
Buster/Bullseye, whose archived keys are still valid). apt-get -qy update
still succeeds (with GPG warnings), but apt-get -qy install $PHPIZE_DEPS
then fails with:

E: There were unauthenticated packages and -y was used without --allow-unauthenticated

This adds a conditional apt.conf.d override that allows unauthenticated
packages, scoped to only take effect when the Stretch suite is actually
present in /etc/apt/sources.list (matching how the existing
stretch/buster/bullseye sed rewrites above it are each scoped by
matching suite name rather than by PHP version), so Buster, Bullseye, and any
newer Debian-based build stay unaffected.

Ported verbatim from wp/6.5's equivalent fix (#127).
desrosj added a commit that referenced this pull request Sep 21, 2026
…ning keys.

wp-env's existing archive.debian.org rewrite already redirects the Stretch
suite's package mirrors (used by the PHP 7.0/7.1 Docker images), since
Debian moved Stretch to its archive server. Since then, the archive's own
Stretch-suite GPG signing keys have themselves expired, with no replacement
key ever going to be published for this now fully end-of-life suite (unlike
Buster/Bullseye, whose archived keys are still valid). apt-get -qy update
still succeeds (with GPG warnings), but apt-get -qy install $PHPIZE_DEPS
then fails with:

E: There were unauthenticated packages and -y was used without --allow-unauthenticated

This adds a conditional apt.conf.d override that allows unauthenticated
packages, scoped to only take effect when the Stretch suite is actually
present in /etc/apt/sources.list (matching how the existing
stretch/buster/bullseye sed rewrites above it are each scoped by
matching suite name rather than by PHP version), so Buster, Bullseye, and any
newer Debian-based build stay unaffected.

Ported verbatim from wp/6.5's equivalent fix (#127).
desrosj added a commit that referenced this pull request Sep 21, 2026
…ning keys.

wp-env's existing archive.debian.org rewrite already redirects the Stretch
suite's package mirrors (used by the PHP 7.0/7.1 Docker images), since
Debian moved Stretch to its archive server. Since then, the archive's own
Stretch-suite GPG signing keys have themselves expired, with no replacement
key ever going to be published for this now fully end-of-life suite (unlike
Buster/Bullseye, whose archived keys are still valid). apt-get -qy update
still succeeds (with GPG warnings), but apt-get -qy install $PHPIZE_DEPS
then fails with:

E: There were unauthenticated packages and -y was used without --allow-unauthenticated

This adds a conditional apt.conf.d override that allows unauthenticated
packages, scoped to only take effect when the Stretch suite is actually
present in /etc/apt/sources.list (matching how the existing
stretch/buster/bullseye sed rewrites above it are each scoped by
matching suite name rather than by PHP version), so Buster, Bullseye, and any
newer Debian-based build stay unaffected.

Ported verbatim from wp/6.5's equivalent fix (#127).
desrosj added a commit that referenced this pull request Sep 22, 2026
…ning keys.

wp-env's existing archive.debian.org rewrite already redirects the Stretch
suite's package mirrors (used by the PHP 7.0/7.1 Docker images), since
Debian moved Stretch to its archive server. Since then, the archive's own
Stretch-suite GPG signing keys have themselves expired, with no replacement
key ever going to be published for this now fully end-of-life suite (unlike
Buster/Bullseye, whose archived keys are still valid). apt-get -qy update
still succeeds (with GPG warnings), but apt-get -qy install $PHPIZE_DEPS
then fails with:

E: There were unauthenticated packages and -y was used without --allow-unauthenticated

This adds a conditional apt.conf.d override that allows unauthenticated
packages, scoped to only take effect when the Stretch suite is actually
present in /etc/apt/sources.list (matching how the existing
stretch/buster/bullseye sed rewrites above it are each scoped by
matching suite name rather than by PHP version), so Buster, Bullseye, and any
newer Debian-based build stay unaffected.

Ported verbatim from wp/6.5's equivalent fix (#127).
desrosj added a commit that referenced this pull request Sep 22, 2026
…ning keys.

wp-env's existing archive.debian.org rewrite already redirects the Stretch
suite's package mirrors (used by the PHP 7.0/7.1 Docker images), since
Debian moved Stretch to its archive server. Since then, the archive's own
Stretch-suite GPG signing keys have themselves expired, with no replacement
key ever going to be published for this now fully end-of-life suite (unlike
Buster/Bullseye, whose archived keys are still valid). apt-get -qy update
still succeeds (with GPG warnings), but apt-get -qy install $PHPIZE_DEPS
then fails with:

E: There were unauthenticated packages and -y was used without --allow-unauthenticated

This adds a conditional apt.conf.d override that allows unauthenticated
packages, scoped to only take effect when the Stretch suite is actually
present in /etc/apt/sources.list (matching how the existing
stretch/buster/bullseye sed rewrites above it are each scoped by matching
suite name rather than by PHP version), so Buster, Bullseye, and any newer
Debian-based build stay unaffected.

Ported verbatim from wp/6.5's equivalent fix (#127),
already also ported to wp/6.4 (#126).

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01DtSAAJkQ9P6vPtDumqStg8
desrosj added a commit that referenced this pull request Sep 22, 2026
…ning keys.

wp-env's existing archive.debian.org rewrite already redirects the Stretch
suite's package mirrors (used by the PHP 7.0/7.1 Docker images), since
Debian moved Stretch to its archive server. Since then, the archive's own
Stretch-suite GPG signing keys have themselves expired, with no replacement
key ever going to be published for this now fully end-of-life suite (unlike
Buster/Bullseye, whose archived keys are still valid). apt-get -qy update
still succeeds (with GPG warnings), but apt-get -qy install $PHPIZE_DEPS
then fails with:

E: There were unauthenticated packages and -y was used without --allow-unauthenticated

This adds a conditional apt.conf.d override that allows unauthenticated
packages, scoped to only take effect when the Stretch suite is actually
present in /etc/apt/sources.list (matching how the existing
stretch/buster/bullseye sed rewrites above it are each scoped by matching
suite name rather than by PHP version), so Buster, Bullseye, and any newer
Debian-based build stay unaffected.

Ported verbatim from wp/6.5's equivalent fix (#127),
already also ported to wp/6.4 (#126).

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01DtSAAJkQ9P6vPtDumqStg8
desrosj added a commit that referenced this pull request Sep 22, 2026
…ning keys.

wp-env's existing archive.debian.org rewrite already redirects the Stretch
suite's package mirrors (used by the PHP 7.0/7.1 Docker images), since
Debian moved Stretch to its archive server. Since then, the archive's own
Stretch-suite GPG signing keys have themselves expired, with no replacement
key ever going to be published for this now fully end-of-life suite (unlike
Buster/Bullseye, whose archived keys are still valid). apt-get -qy update
still succeeds (with GPG warnings), but apt-get -qy install $PHPIZE_DEPS
then fails with:

E: There were unauthenticated packages and -y was used without --allow-unauthenticated

This adds a conditional apt.conf.d override that allows unauthenticated
packages, scoped to only take effect when the Stretch suite is actually
present in /etc/apt/sources.list (matching how the existing
stretch/buster/bullseye sed rewrites above it are each scoped by
matching suite name rather than by PHP version), so Buster, Bullseye, and any
newer Debian-based build stay unaffected.

Ported verbatim from wp/6.5's equivalent fix (#127).
desrosj added a commit that referenced this pull request Sep 23, 2026
…ning keys.

wp-env's existing archive.debian.org rewrite already redirects the Stretch
suite's package mirrors (used by the PHP 7.0/7.1 Docker images), since
Debian moved Stretch to its archive server. Since then, the archive's own
Stretch-suite GPG signing keys have themselves expired, with no replacement
key ever going to be published for this now fully end-of-life suite (unlike
Buster/Bullseye, whose archived keys are still valid). apt-get -qy update
still succeeds (with GPG warnings), but apt-get -qy install $PHPIZE_DEPS
then fails with:

E: There were unauthenticated packages and -y was used without --allow-unauthenticated

This adds a conditional apt.conf.d override that allows unauthenticated
packages, scoped to only take effect when the Stretch suite is actually
present in /etc/apt/sources.list (matching how the existing
stretch/buster/bullseye sed rewrites above it are each scoped by
matching suite name rather than by PHP version), so Buster, Bullseye, and any
newer Debian-based build stay unaffected.

Ported verbatim from wp/6.5's equivalent fix (#127).
desrosj added a commit that referenced this pull request Sep 23, 2026
…ning keys.

wp-env's existing archive.debian.org rewrite already redirects the Stretch
suite's package mirrors (used by the PHP 7.0/7.1 Docker images), since
Debian moved Stretch to its archive server. Since then, the archive's own
Stretch-suite GPG signing keys have themselves expired, with no replacement
key ever going to be published for this now fully end-of-life suite (unlike
Buster/Bullseye, whose archived keys are still valid). apt-get -qy update
still succeeds (with GPG warnings), but apt-get -qy install $PHPIZE_DEPS
then fails with:

E: There were unauthenticated packages and -y was used without --allow-unauthenticated

This adds a conditional apt.conf.d override that allows unauthenticated
packages, scoped to only take effect when the Stretch suite is actually
present in /etc/apt/sources.list (matching how the existing
stretch/buster/bullseye sed rewrites above it are each scoped by matching
suite name rather than by PHP version), so Buster, Bullseye, and any newer
Debian-based build stay unaffected.

Ported verbatim from wp/6.5's equivalent fix (#127),
already also ported to wp/6.4 (#126).

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01DtSAAJkQ9P6vPtDumqStg8
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants