← Back to all sparks
S

SimpleSAMLphp

DEVOPS
Velocity5.0

SAML identity and service provider implementation in PHP

Two maintenance branches, patched in lockstep, with release notes that say nothing but a checksum.

samlidentitysecurity-releasesmaintenancedual-branch
Current state
SimpleSAMLphp is running parallel 2.4 and 2.5 maintenance branches and patching both whenever a fix lands. The August sequence is representative: a 2.4.9 bugfix, a coordinated 2.5.3 security drop re-tagged hours later as 2.5.3.1, and now a 2.4.10 bugfix closing the month on the older branch. Release bodies carry no changelog text at all, just a download link, an upgrade-notes pointer and SHA256 checksums, so the feed tells operators when to patch but never what changed.
Where it's heading
This is maintenance cadence, not product development, and the shape of it is stable enough to predict. Security issues get simultaneous twin tags across both supported branches; everything else lands as a branch-local bugfix point, alternating between 2.4 and 2.5 every few weeks. The only release in the window that documented its own content was v2.4.6/v2.5.1 in May, which listed three GHSA advisories — the exception that shows the notes could carry detail and normally do not.
Prediction
Expect the alternation to continue, with the next paired 2.4.x and 2.5.x tags arriving together whenever an advisory lands and content again deferred to the external changelog.

Recent moves

  1. 16d ago

    Bugfix release on the 2.4 maintenance branch

    A bugfix point release on the older 2.4 branch, arriving three weeks after the 2.5 security drop with the same checksum-only body. It keeps the legacy branch current for sites that have not moved to 2.5, and describes nothing user-visible.

    View source ↗
  2. 1mo ago

    Security release on the 2.5 branch (re-tagged)

    A security release on the 2.5 branch, tagged v2.5.3.1 roughly seven hours after the v2.5.3 tag with different checksums — a re-tag of the same release rather than a second fix. Operators need to patch, but the body documents nothing beyond hashes.

    View source ↗
  3. 1mo ago

    Security release on the 2.5 branch

    The original v2.5.3 security tag, twinned with the v2.5.3.1 re-tag later the same day. Same maintenance rhythm as the rest of the feed: patch now, read the external changelog to find out why.

    View source ↗
  4. 1mo ago

    Bugfix release on the 2.4 maintenance branch

    A bugfix point release on the older 2.4 branch, landing a day before the 2.5 security drop. Nothing user-visible is described — it keeps the legacy branch current for sites that have not moved to 2.5.

    View source ↗
  5. 2mo ago

    Bugfix release on the 2.4 maintenance branch

    Another 2.4 bugfix point with a checksum-only body. It fits the branch-local maintenance half of the pattern, where non-security work ships alone rather than as a twin.

    View source ↗
  6. 3mo ago

    Bugfix release on the 2.5 branch

    A 2.5 bugfix release from June, documented only by its hashes. Paired in time with the 2.4.7 tag the day before, showing the branches move together even outside security events.

    View source ↗