#1109365 ITP: php-guzzlehttp-guzzle -- PHP HTTP client library and framework

Package:
wnpp
Source:
wnpp
Submitter:
Ahmed Gamal
Date:
2025-08-10 18:31:01 UTC
Severity:
normal
Tags:
#1109365#5
Date:
2025-07-16 04:38:38 UTC
From:
To:
  Package name : php-guzzlehttp-guzzle
  Version : 7.9.3
  Upstream Author : Michael Dowling <mtdowling@gmail.com>
  URL : https://github.com/guzzle/guzzle
  License : MIT
  Programming Lang: PHP
  Description : PHP HTTP client library and framework

 Guzzle is a PHP HTTP client library and framework for building RESTful
 web service clients. It provides a simple interface for building HTTP
 clients and includes features like middleware system, PSR-7 HTTP message
 interface support, request/response mocking, connection pooling, request
 retry logic, cookie handling, and OAuth 1.0/2.0 support.

 - Why is this package useful/relevant?
   - This package is required by FOSSology (ITP: #924659) as a dependency
   - It's one of the most popular PHP HTTP client libraries with over 23K
stars on GitHub
   - Used by thousands of PHP applications for HTTP communication
   - Provides PSR-7 compliant HTTP message interface
   - Essential for modern PHP applications that need to make HTTP requests

 - Do you use it?
   - This is being packaged as part of the FOSSology packaging effort
   - FOSSology uses Guzzle for making HTTP requests to external APIs and
services

 - How do you plan to maintain it?
   - Will maintain as part of the FOSSology packaging team
   - Following Debian PHP packaging guidelines
   - Using pkg-php-tools for automated dependency management
   - Monitoring upstream releases for security updates

 - Are you looking for co-maintainers or a sponsor?
   - Looking for a sponsor to help publish this as a Debian package
   - Part of the larger FOSSology packaging effort
   - Open to co-maintainers given the package's popularity

 This package is a critical dependency for FOSSology (ITP: #924659) and is
 needed to complete the packaging of FOSSology for Debian. Guzzle is widely
 used in the PHP ecosystem and will benefit many other Debian packages.

 Thanks,
 Ahmed Gamal

#1109365#10
Date:
2025-07-16 22:20:40 UTC
From:
To:
Hello,
This is a follow-up regarding the ITP for php-guzzlehttp-guzzle.
Update:
After reviewing the requirements of the FOSSology project, I have
repackaged php-guzzlehttp-guzzle to use version 7.5.0 (instead of the
previously mentioned 7.9.3). This change ensures compatibility with
FOSSology, which specifically requires version 7.5.0 in its dependency list.
Summary of changes:
Downloaded and packaged the correct upstream version: 7.5.0
Updated all Debian packaging files to reflect this version
Verified that this version matches the requirements of FOSSology and avoids
any potential incompatibilities that could arise from using a newer version
If there are any questions or further steps needed, please let me know.
Thank you for your attention and support!
Best regards,
Ahmed Gamal

#1109365#15
Date:
2025-07-16 20:58:38 UTC
From:
To:
Hello,
This is a follow-up regarding the ITP for php-guzzlehttp-guzzle.
I have updated the packaging to use the version 7.5.0, which matches the
version required by the FOSSology project. The package includes all
necessary Debian packaging files and follows Debian PHP packaging
guidelines.
Summary of changes:
Downloaded and packaged the correct upstream version: 7.5.0
Ensured all packaging files (control, rules, changelog, copyright,
source/format, watch, install) are present and correct
The package is intended as a dependency for FOSSology, not as a general PHP
team package
Please let me know if further information is needed.
Thanks,
Ahmed Gamal

#1109365#22
Date:
2025-08-10 13:45:06 UTC
From:
To:
Please do some research before opening ITP/RFP bugs.
This package already exists in Debian.

#1109365#27
Date:
2025-08-10 22:27:09 UTC
From:
To:
Dear William,

I need to clarify the version-specific requirement that led to this ITP
filing.

VERSION COMPATIBILITY REQUIREMENT:
FOSSology requires php-guzzlehttp-guzzle version 7.9.3, which may differ
from the version currently available in Debian. This is essential for
FOSSology's HTTP client functionality and external API integration.

HTTP CLIENT DEPENDENCY:
FOSSology's license compliance system relies on specific Guzzle
functionality:
- HTTP requests to external license databases and APIs
- Integration with FOSSology's web-based compliance workflows
- PSR-7 HTTP message interface compatibility with FOSSology's HTTP stack
- Consistent HTTP client behavior for license data retrieval

TECHNICAL INTEGRATION REQUIREMENTS:
FOSSology's HTTP components expect:
- Specific Guzzle API methods from version 7.9.3
- Compatible PSR-7 HTTP message handling
- Integration with FOSSology's existing HTTP infrastructure
- Consistent behavior in external API communication

VERSION-SPECIFIC FUNCTIONALITY:
FOSSology's license compliance features rely on:
- Particular Guzzle HTTP client interfaces from 7.9.3
- Specific request/response handling capabilities
- Compatible middleware and PSR-7 integration
- Tested integration with FOSSology's compliance workflows

EVIDENCE FROM INTEGRATION:
FOSSology's composer dependencies specify Guzzle 7.9.3 to ensure:
- Reliable HTTP communication for license data
- Stable API integration for compliance workflows
- Compatibility with FOSSology's HTTP infrastructure
- Consistent external service communication

PROPOSED SOLUTION:
Package as php-guzzlehttp-guzzle-7.9 if the current Debian version differs,
ensuring FOSSology can use the tested and validated HTTP client version.

JUSTIFICATION:
FOSSology's license compliance accuracy depends on reliable HTTP
communication with external license databases and APIs, making version
compatibility critical.

REQUEST:
Please reopen to discuss providing Guzzle 7.9.3 for FOSSology's HTTP client
requirements if version incompatibility exists.

Best regards,
Ahmed Gamal
FOSSology Debian Packaging Team

#1109365#32
Date:
2025-08-10 22:27:53 UTC
From:
To:
Dear William,

I need to reopen this ITP due to version requirements for FOSSology's
license compliance and external API integration.

VERSION REQUIREMENT:
FOSSology requires php-guzzlehttp-guzzle version 7.9.3 for its license
compliance system, which may differ from the current Debian version.

LICENSE COMPLIANCE DEPENDENCY:
FOSSology's core functionality relies on Guzzle for:
- HTTP requests to external license databases and APIs
- Integration with license compliance workflows
- PSR-7 HTTP message compatibility with FOSSology's HTTP stack
- Reliable communication with external license services

TECHNICAL INTEGRATION:
FOSSology's license compliance system expects:
- Specific Guzzle API methods from version 7.9.3
- Compatible PSR-7 HTTP message handling
- Integration with FOSSology's existing HTTP infrastructure
- Consistent behavior in external license data retrieval

CRITICAL FOR LICENSE ACCURACY:
FOSSology's license detection depends on:
- Reliable HTTP communication with license databases
- Stable API integration for compliance workflows
- Consistent external service communication
- Accurate license data retrieval from external sources

EVIDENCE FROM INTEGRATION:
FOSSology's dependencies specify Guzzle 7.9.3 to ensure reliable HTTP
communication for license compliance functionality.

PROPOSED SOLUTION:
Package as php-guzzlehttp-guzzle-7.9 if version differences exist, ensuring
FOSSology's license compliance accuracy.

JUSTIFICATION:
FOSSology's core mission - license compliance accuracy - depends on
reliable HTTP communication with external license databases.

REQUEST:
Please reopen to discuss providing Guzzle 7.9.3 for FOSSology's license
compliance requirements.

Best regards,
Ahmed Gamal
FOSSology Debian Packaging Team