Repository navigation
Update FrankenPHP to version 1.13 and adjust Mercure settings for com… - #715
Merged
jaydrogers merged 1 commit intoOct 6, 2026
Conversation
jaydrogers
marked this pull request as ready for review
October 6, 2026 20:18
Contributor
Images for PR #715
Try it: docker run --rm -v "$PWD:/var/www/html" -p 8080:8080 serversideup/php-dev:715-8.5-fpm-nginxEvery image is on Docker Hub as All images with sizesSizes are compressed, per architecture.
Updated on every push to this PR. |
jaydrogers
merged commit Oct 6, 2026
c02169d
into
release/webserver-improvements-and-fixes
132 checks passed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Upgrades the FrankenPHP variation to v1.13.0 and builds it the way the official
dunglas/frankenphpimage does, withgo installfrom FrankenPHP's owngo.modinstead of xcaddy. Follow-up to #713 for #712.Why
#713 pinned Caddy to 2.11.4 because
xcaddy buildresolved the latest Caddy at build time, which is how the 2.11.6 HTTP/2 crash reached beta3. FrankenPHP 1.13.0 ships Caddy 2.11.7, which fixes that panic (caddy#8101, fixed in caddy#8107). It also fixes five security advisories. Three of them affect our Linux images: header spoofing through dot-form header names, a CGI path split that ranuploads/a.phpfor/uploads/a.php.txt/b.php, andputenv()leaking between worker requests.Upstream hit the same xcaddy problem in php/frankenphp#2685: their xcaddy-built 1.12.7 binaries picked up Mercure 1.0 overnight with no new release. Building with
go installtakes every module version fromcaddy/go.sum, so the binary only changes whenFRANKENPHP_VERSIONdoes.We switched to xcaddy in September 2025 after #563, which proposed a builder image for people adding their own Caddy modules (#568). That image was never built, and it doesn't depend on how our binary is built: people adding modules run xcaddy in their own builder stage, which is also how upstream splits it.
Changes
FRANKENPHP_VERSIONis1.13.0andGOLANG_VERSIONis1.27, which FrankenPHP'sgo.modnow requires.CADDY_VERSIONand the hand-pinned Mercure, Vulcain, and cbrotli versions are gone.go.sh installfromcaddy/frankenphpwith upstream's-ldflagsand cgo flags, thensetcap. That adds the things xcaddy skipped: the PGO profile, PHP's hardening flags ($PHP_CFLAGS,$PHP_CPPFLAGS,$PHP_LDFLAGS), thedeprecated_topic,deprecated_claimtags for Mercure's compatibility mode, and the full version string.frankenphp versionnow printsFrankenPHP v1.13.0 PHP 8.4.26 Caddy v2.11.7instead of a bare Caddy line.What users will notice
publisher_jwtorsubscriber_jwt, including through themercurearray inconfig/octane.php, now stops FrankenPHP from starting. Moving the keys into anissuerblock or addingprotocol_version_compatibility 8fixes it.431. 1.12.7 accepted at least 64 KB. Headers with a.in their name are dropped.num_threads: it no longer includes worker threads, so setting it alongside workers starts more threads, or fails ifmax_threadsis lower than the total.