aboutsummaryrefslogtreecommitdiff
path: root/security
Commit message (Collapse)AuthorAgeFilesLines
* - Update to 2.35.0Dmitry Marakasov2021-01-182-8/+5
| | | | Notes: svn path=/head/; revision=561953
* Revert 561829, this is not a correct solutionDmitry Marakasov2021-01-182-15/+3
| | | | | | | PR: 252159 Notes: svn path=/head/; revision=561921
* Update KDE Frameworks to 5.78.0Tobias C. Berner2021-01-181-3/+3
| | | | | | | | | | | | | | | | | | | | | January 09, 2021. KDE today announces the release of KDE Frameworks 5.78.0. KDE Frameworks are 83 addon libraries to Qt which provide a wide variety of commonly needed functionality in mature, peer reviewed and well tested libraries with friendly licensing terms. For an introduction see the KDE Frameworks release announcement. This release is part of a series of planned monthly releases making improvements available to developers in a quick and pred Full Changelog: https://kde.org/announcements/kde-frameworks-5.78.0 PR: 252591 Exp-run by: antoine Notes: svn path=/head/; revision=561913
* Document CVE-2020-25074 and CVE-2020-15275 for www/moinmoinLi-Wen Hsu2021-01-181-0/+30
| | | | Notes: svn path=/head/; revision=561901
* pi@ prefers it to be foolproof, so be itBaptiste Daroussin2021-01-181-1/+1
| | | | | | | Reported by: pi Notes: svn path=/head/; revision=561899
* Document ghostscript9-agpl-base vulnerability committed in r544907Mateusz Piotrowski2021-01-171-0/+31
| | | | | | | | | | | PR: 248580 Requested by: joneum (ports-secteam) Reported by: VVD <vvd@unislabs.com> MFH: 2021Q1 Security: CVE-2020-15900 Notes: svn path=/head/; revision=561880
* security/logcheck: Fix runtime error with bsdgrepSteve Wills2021-01-177-1/+65
| | | | | | | | PR: 251778 Submitted by: Yasuhiro Kimura <yasu@utahime.org> (maintainer) Notes: svn path=/head/; revision=561861
* security/i2pd: make the port compatible with sysloggingEugene Grosbein2021-01-172-2/+15
| | | | | | | | | | | | | | | | | | | | | | | i2pd supports logging via syslog. This may be enabled with its configuration file, but port's startup script forces logging to a file using command line switches that override configuration file. This change adds syslogging support with following rc.conf setting: i2pd_logfile="syslog" # translates to: --log syslog or i2pd_logfile="syslog:warn" # translates to: --log syslog --loglevel warn The change is backward compatible with previous settings. PR: 252159 Approved by: amdmi3 (maintainer timeout over 3 weeks) Notes: svn path=/head/; revision=561829
* security/age: Update to v1.0.0-beta6Dmitri Goutnik2021-01-172-9/+14
| | | | | | | Changes: https://github.com/FiloSottile/age/releases/tag/v1.0.0-beta6 Notes: svn path=/head/; revision=561815
* Remove expired ports:Rene Ladan2021-01-174-39/+0
| | | | | | | | | 2021-01-14 net-im/telegram: Upstream unmaintained; please migrate to net-im/telegram-cli 2021-01-14 science/dlpoly-classic: MASTERSITE gone; possibly replaced by https://gitlab.com/DL_POLY_Classic/dl_poly? 2021-01-15 security/py-gtts-token: Obsolete, please use audio/py-gtts instead Notes: svn path=/head/; revision=561814
* LibreTLS is a port of libtls from LibreSSL to OpenSSL. libtls is "a new TLSBaptiste Daroussin2021-01-175-0/+125
| | | | | | | | | | | | | library, designed to make it easier to write foolproof applications". libtls provides an excellent new API, but LibreSSL can be difficult to install on systems which already use OpenSSL. LibreTLS aims to make the libtls API more easily and widely available. WWW: https://git.causal.agency/libretls/about/ Notes: svn path=/head/; revision=561811
* security/2fa: Update to 1.2.0Dmitri Goutnik2021-01-172-10/+5
| | | | | | | - Remove custom do-test target Notes: svn path=/head/; revision=561810
* Update the Angr framework to 9.0.5405Mateusz Piotrowski2021-01-165-20/+18
| | | | | | | | | | | | | | - Angr binaries are now tagged as well. We may consider removing ANGR_BINARIES_TAGNAME in the future. - Remove restrictions on the unicorn version for now. This should prevent the port from breaking again in the foreseeable future. PR: 252042 Reported by: nc Event: January 2021 Bugathon Notes: svn path=/head/; revision=561764
* security/xray-core: Update to 1.2.2Neel Chauhan2021-01-162-4/+4
| | | | | | | Approved by: 0mp (mentor, implicit) Notes: svn path=/head/; revision=561742
* security/py-bcrypt: Update to 3.2.0Danilo G. Baio2021-01-162-5/+4
| | | | Notes: svn path=/head/; revision=561721
* Fix buildAntoine Brodin2021-01-161-0/+11
| | | | | | | | Reported by: pkg-fallout MFH: 2021Q1 Notes: svn path=/head/; revision=561718
* security/libscep: Remove Python 2.7 support and PY_SPHINXDanilo G. Baio2021-01-151-2/+2
| | | | | | | Approved by: portmgr blanket Notes: svn path=/head/; revision=561639
* security/py-ospd: Transfer maintainership to acm@ on his request.Yuri Victorovich2021-01-141-1/+1
| | | | | | | Requested by: acm (via e-mail) Notes: svn path=/head/; revision=561608
* security/vuxml: document Node.js January 2021 Security ReleasesBradley T. Hughes2021-01-141-0/+46
| | | | | | | | | https://nodejs.org/en/blog/vulnerability/january-2021-security-releases/ Sponsored by: Miles AS Notes: svn path=/head/; revision=561590
* Remove PY_SPHINX from ports using Python 3Danilo G. Baio2021-01-141-1/+1
| | | | | | | | Approved by: portmgr blanket Differential Revision: https://reviews.freebsd.org/D28093 Notes: svn path=/head/; revision=561562
* Document gitlab vulnerability.Matthias Fechner2021-01-141-0/+27
| | | | Notes: svn path=/head/; revision=561551
* security/gcr: update to 3.38.1Tobias C. Berner2021-01-142-4/+4
| | | | Notes: svn path=/head/; revision=561550
* Document integer overflow in wavpack (CVE-2020-35738).Thomas Zander2021-01-141-0/+28
| | | | Notes: svn path=/head/; revision=561541
* Return to pool as per maintainer's requestKoichiro Iwao2021-01-142-2/+2
| | | | | | | | | | and I take security/dehydrated. PR: 252650 Submitted by: Sascha Holzleiter <sascha@root-login.org> Notes: svn path=/head/; revision=561540
* security/please: take maintainershipSteve Wills2021-01-141-1/+1
| | | | Notes: svn path=/head/; revision=561534
* security/lynis: Update to 3.0.3Lars Engels2021-01-132-4/+4
| | | | | | | MFH: 20201Q1 Notes: svn path=/head/; revision=561506
* Document Jenkins Security Advisory 2021-01-13Li-Wen Hsu2021-01-131-0/+49
| | | | | | | Sponsored by: The FreeBSD Foundation Notes: svn path=/head/; revision=561491
* Update databases/redis to the recent stable version 6.0.10.Sergey A. Osokin2021-01-133-2/+3
| | | | | | | | | | | | | | | Update CONFLICTS for: o) databases/redis4 o) databases/redis5 o) databases/redis o) databases/redis-devel Connect databases/redis5 to the build. Bump PORTREVISIONs for dependant ports. Notes: svn path=/head/; revision=561486
* Fix key management in security/kleopatraAdriaan de Groot2021-01-134-47/+100
| | | | | | | | | | | | | | | This was reported upstream also as https://bugs.kde.org/show_bug.cgi?id=415168 there has been a patch languishing there for a long time, which I've now (re)submitted upstream. It fixes all of the reported problem: a previous patch by me in FreeBSD ports only dealt with half of them. PR: 242670 Submitted by: Andre Heinecke Reported by: Gerhard Seibert Notes: svn path=/head/; revision=561468
* Simplify some ports using PYTHON_MAJOR_VER and Python 3.6+Rene Ladan2021-01-121-6/+2
| | | | Notes: svn path=/head/; revision=561385
* Document phpmyfaq vulnerabilityFlorian Smeets2021-01-121-0/+26
| | | | Notes: svn path=/head/; revision=561382
* security/tor-devel: Update 0.4.5.2-alpha -> 0.4.5.3-rcYuri Victorovich2021-01-122-4/+4
| | | | | | | Reported by: upstream notification Notes: svn path=/head/; revision=561374
* security/sudo: Update to 1.9.5p1Renato Botelho2021-01-122-4/+4
| | | | | | | | | | | | | | This version fixes a regression introduced by 1.9.5 Changelog: https://www.sudo.ws/stable.html#1.9.5p1 PR: 252598 Submitted by: cy MFH: 2021Q1 Sponsored by: Rubicon Communications, LLC (Netgate) Notes: svn path=/head/; revision=561323
* security/gnupg: Update to 2.2.27Adam Weinberger2021-01-122-4/+4
| | | | | | | | | | | | | | | | | * gpg: Fix regression in 2.2.24 for gnupg_remove function under Windows. [#5230] * gpgconf: Fix case with neither local nor global gpg.conf. [9f37d3e6f3] * gpgconf: Fix description of two new options. [#5221] * Build Windows installer without timestamps. Note that the Authenticode signatures still carry a timestamp. Release-info: https://dev.gnupg.org/T5234 Notes: svn path=/head/; revision=561299
* Document sudo CVE-2021-23239.Cy Schubert2021-01-121-0/+37
| | | | Notes: svn path=/head/; revision=561298
* Fix build on llvm10 and gcc.Cy Schubert2021-01-121-2/+4
| | | | | | | | | PR: 252577 Reported by: David Sieborger <drs-freebsd _ sieborger.nom.za> MFH: 2021Q1 Notes: svn path=/head/; revision=561297
* security/fizz: Update 2021.01.04.00 -> 2021.01.11.00Yuri Victorovich2021-01-112-4/+4
| | | | Notes: svn path=/head/; revision=561264
* Update 1.9.4p2 --> 1.9.5Cy Schubert2021-01-112-4/+4
| | | | | | | | | | | | PR: 252583 Submitted by: cy Reported by: cy Approved by: garga (maintainer) MFH: 2021Q1 Security: CVE-2021-23239 Notes: svn path=/head/; revision=561259
* Remove logic for Python < 3.6 for ports using Python 3.6+Rene Ladan2021-01-113-21/+3
| | | | Notes: svn path=/head/; revision=561252
* security/xray-core: Update to 1.2.1Neel Chauhan2021-01-112-4/+4
| | | | | | | | | Reviewed by: 0mp (mentor) Approved by: 0mp (mentor) Differential Revision: https://reviews.freebsd.org/D28094 Notes: svn path=/head/; revision=561243
* security/libtasn1: add a workaround for clang 10+Roman Bogorodskiy2021-01-111-2/+10
| | | | | | | | | | | | | | | When compiled with clang 10+ and -O[2-9], the resulting package fails to parse certificates. As a workaround, downgrade optimization to -O1. Upstream issue: https://gitlab.com/gnutls/libtasn1/-/issues/30 PR: 252548 Reported by: rozhuk.im@gmail.com Notes: svn path=/head/; revision=561219
* Update version requirement of RUN_DEPENDSSunpoet Po-Chuan Hsieh2021-01-101-1/+1
| | | | Notes: svn path=/head/; revision=561153
* Update version requirement of RUN_DEPENDSSunpoet Po-Chuan Hsieh2021-01-101-1/+1
| | | | Notes: svn path=/head/; revision=561152
* Remove empty PY_IPADDRESS from ports using Python 3.6+Rene Ladan2021-01-103-3/+0
| | | | | | | Also remove one manual declaration (net-mgmt/py-aggregate6) Notes: svn path=/head/; revision=561083
* Remove empty PY_ENUM34 from ports using Python 3.6+Rene Ladan2021-01-105-7/+2
| | | | Notes: svn path=/head/; revision=561070
* security/go-cve-dictionary: Update to 0.5.5Dmitri Goutnik2021-01-102-101/+114
| | | | | | | | | | | - Pet portclippy while here Changes: https://github.com/kotakanbe/go-cve-dictionary/releases/tag/v0.5.5 PR: 251653 Submitted by: Alexandru Ciobanu <iscandr@gmail.com> (maintainer) Notes: svn path=/head/; revision=561062
* Document cairosvg vulnerabilitySunpoet Po-Chuan Hsieh2021-01-101-0/+32
| | | | Notes: svn path=/head/; revision=561020
* Clean up RUN_DEPENDS after r542200 (USES=python:3.6+)Sunpoet Po-Chuan Hsieh2021-01-101-1/+0
| | | | Notes: svn path=/head/; revision=560969
* Remove PYTHON_REL checkSunpoet Po-Chuan Hsieh2021-01-101-8/+2
| | | | Notes: svn path=/head/; revision=560968
* Clean up RUN_DEPENDS after r559531 (USES=python:3.6+)Sunpoet Po-Chuan Hsieh2021-01-101-2/+1
| | | | Notes: svn path=/head/; revision=560967