[Bug 288859] devel/dbus: default MANPAGES pulls vulnerable textproc/libxslt and blocks builds
Date: Thu, 14 Aug 2025 14:59:08 UTC
https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=288859
Gleb Popov <arrowd@FreeBSD.org> changed:
What |Removed |Added
----------------------------------------------------------------------------
Flags|maintainer-feedback?(deskto |maintainer-feedback+
|p@FreeBSD.org) |
CC| |arrowd@FreeBSD.org
--- Comment #1 from Gleb Popov <arrowd@FreeBSD.org> ---
(In reply to Generic Rikka from comment #0)
> the build halts on the vulnerability check and dbus cannot be built.
You can disable this check.
> Expected result:
devel/dbus builds successfully with default options (or avoids vulnerable
dependencies by default).
It builds fine in Poudriere, which is the only supported way to build ports.
I see no reason to change the option's default, because the vulnerable
dependency is a build dependency and won't end up on client machine (unless of
course you're building on host with portmaster/make).
Again, building on host is not a supported way to consume Ports tree and it is
expected that you can deal with problems arising from such usage yourself.
Meanwhile, the default ports options are arranged for Poudriere builders and
binary package users, which should not suffer from a vulnerable build-time
dependency they don't care about.
--
You are receiving this mail because:
You are the assignee for the bug.