sektioneins / suhosin7

Suhosin Extension for PHP 7.x
https://www.suhosin.org
Other
120 stars 25 forks source link

Release ETA #20

Open MBlagui opened 7 years ago

MBlagui commented 7 years ago

Hi,

Do you have any production grade release for PHP 7? We are using suhosin in Open Source project sentora and been planning to support PHP 7.0 but we can't do that as long we use the old suhosin.

Thanks for the help & support.

bef commented 7 years ago

We hope to continue active development some time this year. In the meantime, you are welcome to contribute.

RowdyElectron commented 7 years ago

Is there anything I can do to help? Not much of a C coder these days, but I have access to many different PHP projects on 7.0 - 7.2 and good experience breaking things

szepeviktor commented 6 years ago

@bef Do you have clients with PHP7 at SektionEins? I would be nice to release suhosin in production.

iPublicis commented 6 years ago

@MBlagui it seems it works: https://github.com/sektioneins/suhosin7/issues/16

MBlagui commented 6 years ago

@iPublicis ok I will try to test it but I don't see any official release. We are building an open source project relying on suhosin for sansboxing php but I fear we ship it and we get a lot of bugs on production.

RowdyElectron commented 6 years ago

@MBlagui On that point i feel like we need a docker container with this environment, available on a public registry. I've observed that Suhosin is like SELinux/AppArmour; many people just do away with it because it isn't easy to conceptualize (as is any risk since we are humans) and it can just get in the way. @bef Would it make sense that if there were an out-of-the-box solution that we'd see more usage? With a container'd build that has options/settings exposed, this project might get the attention it had.

bef commented 6 years ago

@RowdyElectron Thank you for the suggestion. It is not the attention, that this project needs, but rather more time to complete its development. Due to a lot of actual workload in the IT security field, the suhosin7 open source development may need to wait a little longer.

MBlagui commented 6 years ago

I'm working on updating the installers/testing. For docker once we are able to separate as it should be the server config from the panel it will be easier to manage. I'm focusing more on a clean dev environnement so you can test it easily & give a hand.

yusha commented 6 years ago

Any update yet @bef ??? I’ve been waiting for 1 year..... :( so do other thousands of people out there who use Sentora as their web host manager. Please give some updates. Thanks.