From nobody Sun Sep 17 18:33:50 2023 X-Original-To: dev-commits-ports-all@mlmmj.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mlmmj.nyi.freebsd.org (Postfix) with ESMTP id 4Rpc5B3VB6z4tb0p; Sun, 17 Sep 2023 18:33:50 +0000 (UTC) (envelope-from danfe@freebsd.org) Received: from freefall.freebsd.org (freefall.freebsd.org [96.47.72.132]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "freefall.freebsd.org", Issuer "R3" (verified OK)) by mx1.freebsd.org (Postfix) with ESMTPS id 4Rpc5B32wwz4q12; Sun, 17 Sep 2023 18:33:50 +0000 (UTC) (envelope-from danfe@freebsd.org) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1694975630; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: in-reply-to:in-reply-to:references:references; bh=DsZ3DKWZNER7O/haVxunOi7+5ErQPUtV/yq1P5GhoVw=; b=jVJsaZH35HhbU9LApewEProxh6iKle9kugn4tCqUKJzXDxHyJzqJ/HpCquJUvMPuvT8Asc JsxQ7coTDlJH8X+ru8R9fxfBZZq4jRSZxFze/yb0ngo2GFg5QPUpx1ddiyRUpxsZNXHjBJ MEhDg+UgMOPp++7Gx1PtVT6Bdwkatfy5wrBu4ebkFF6VwOyRgVrh3tPO9O11D1AciJ6hag 4QGW/rV2rUncJQw0+nc5zd7ld8unxAhvAa3KyMUdfQQU1rtiaKTrOGXk+Z0O0rc+EOmz7t 1JqtLfrIbe15Jg/ok113N1AqvaI48Sz1aYrfYcBupiigJMzneFP1muiq9ICeFg== ARC-Seal: i=1; s=dkim; d=freebsd.org; t=1694975630; a=rsa-sha256; cv=none; b=xoagPsFohQi1XKx1ZELJahEwvxpA2C1q468nEcv6RIMsC+YuoVfVX6CuL+b96kFiZLXrMJ d30EZlAo+lZqQyZeFy+M4vieRjFPbOZ5HAx+cT8e5Wk8jeHFxl+BOyBitvcJ/EmyL+CHYn pe+RbmySUJ7fiac2jpWoPFyjeQ+QSFSyEuTsPvw/pXGLOMX43qNvGf914+lKPaouqCeiji 9dVheykg6bp1EhvYQSmyWgfYnlcK9+4+wnavOMMaxE2SMfVsBuAtBtiDOKkkUYGDgcDwZ7 9aJKCKHQBkKHnj0QSl9NNCq7zjUP9I3xpLfpmL0AK2BsEKfvtRwrUNiSwIepSQ== ARC-Authentication-Results: i=1; mx1.freebsd.org; none ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1694975630; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: in-reply-to:in-reply-to:references:references; bh=DsZ3DKWZNER7O/haVxunOi7+5ErQPUtV/yq1P5GhoVw=; b=RyGOTf9PwBaJjiawY3x47Qh56vQ85Gqu6dkw+Ai5bvrmMfU7XKYUY2Cb1Bs0Enk//jQYFt O2/XvytFXq+pf/uJkCjyT/2K3+PbAl0pwURvLgAhz6oeowx3ScfuXjTMQmiw1V6qGNf8pE OTvHN/rlOH9/T8KFtJTKkocp+GBEYUao/lzjohSM4KFkyhUEuUy2QvEUga5Fb+sb7QSMlp SzwweQVMxEGAe+0syWTpDBxKOTqt/JR0iRQP+fIhOIkMJjzjVInYMPK1uHuEcXPDDPEEHs 4f3Ea2qpIxNTCEVZj4NIZRNkkxcq631UaecAIrYPu3tZZt83j21y7volnTvCzw== Received: by freefall.freebsd.org (Postfix, from userid 1033) id 39AFD15F4B; Sun, 17 Sep 2023 18:33:50 +0000 (UTC) Date: Sun, 17 Sep 2023 18:33:50 +0000 From: Alexey Dokuchaev To: "Jason E. Hale" Cc: Bernard Spil , ports-committers@freebsd.org, dev-commits-ports-all@freebsd.org, dev-commits-ports-main@freebsd.org Subject: Re: git: a3dec5316c3e - main - security/vuxml: Document cURL vulnerability Message-ID: References: <202309161328.38GDSngf016525@gitrepo.freebsd.org> List-Id: Commit messages for all branches of the ports repository List-Archive: https://lists.freebsd.org/archives/dev-commits-ports-all List-Help: List-Post: List-Subscribe: List-Unsubscribe: Sender: owner-dev-commits-ports-all@freebsd.org X-BeenThere: dev-commits-ports-all@freebsd.org MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: On Sun, Sep 17, 2023 at 02:23:22PM -0400, Jason E. Hale wrote: > > commit a3dec5316c3e45a676eef22de283ad57ea6a3111 > > > > security/vuxml: Document cURL vulnerability > > > > PR: 273764 > > Reported by: yasu > > [...] > > + > > + Roundcube -- XSS vulnerability > > + > > +-- > > +2.42.0 > > + > > You probably didn't mean to add this file. Could you remove it please? Could it be the reason why any "make" command in any port now complains that it has known vulnerabilities? Preceding lines are: pkg-static: Invalid end of XML pkg-static: cannot process vulnxml ./danfe