Re: git: db727c902a8f - main - security/vuxml: Add devel/git-lfs entry
- Go to: [ bottom of page ] [ top of archives ] [ this month ]
Date: Mon, 14 Sep 2026 19:44:40 UTC
El lun, 14 sept 2026, 20:21, Ivo Marino <ivo.marino+freebsd@gmail.com> escribió: > On Mon, Sep 14, 2026, at 12:52 PM, Fernando Apesteguía wrote: > > + <range><lt>0.5.2, &lt; 3.7.1</lt></range> > > > I'm no vuxml expert. Does the above need to be two separate entries? > > Good catch, Dan - thanks for flagging it. No, it doesn't need to be > split into two entries: a single <range> can carry more than one > bound. Two patterns are already used elsewhere in this same file - > a bare upper bound, like the Forgejo entry right above this one: > > <range><lt>3.7.1</lt></range> > > or a paired lower/upper bound when there's a real starting version, > like the c-ares entry a bit further down: > > <range><ge>0.5.2</ge><lt>3.7.1</lt></range> > > What actually landed has both numbers concatenated into a single > <lt> tag along with a stray escaped "<", which isn't a valid > version string in either position - so pkg audit won't be able to > match against it as-is. > > Since the git-lfs port has never carried anything close to 0.5.2, > I'd go with the simple upper-bound-only form. Fernando, happy to > send a follow-up patch to fix this if that's useful - just let me > know. > Hi Ivo, I did it in https://cgit.freebsd.org/ports/commit/?id=96ad848daae8832a2842a5bc4f6bb4761acf58ee Thanks! > Ivo >