Re:_git:_72dd8d2ee676_-_main_-_mail/dovecot:_upd ate_2.3.21_→_2.3.21.1_(fixes_2_CVEs)

From: Alexander Leidinger <Alexander_at_Leidinger.net>
Date: Sat, 17 Aug 2024 07:50:11 UTC
Am 2024-08-17 09:26, schrieb Mathieu Arnold:
> On Sat, Aug 17, 2024 at 12:15:54AM GMT, Kevin Bowling wrote:

>> I'm not really sure why this is turning into a discussion.  The
>> request is standard practice for handling CVEs in the repo and a
>> courtesy to other committers and even more for users who rely on tools
>> like pkg audit and do not watch commit logs.
> 
> Technically, it does not need to be a discussion. Maintaining the VuXML
> database is ports-secteam's job, it's in their charter.
> 
> Now, ports-secteam has no members, so nobody is maintaining the VuXML
> database.
> 
> Ports committers can update it, but they have absolutely no obligation
> to, it's on a best effort basis.

An entry for dovecot is committed to vuxml.

Bye,
Alexander.

-- 
http://www.Leidinger.net Alexander@Leidinger.net: PGP 0x8F31830F9F2772BF
http://www.FreeBSD.org    netchild@FreeBSD.org  : PGP 0x8F31830F9F2772BF