bdb5 is EOL, but still the default version?

From: Mel Pilgrim <>
Date: Mon, 12 Dec 2022 15:33:24 UTC
I get errors like this in audit logs:

db5-5.3.28_8: Tag: expiration_date Value: 2022-06-30
db5-5.3.28_8: Tag: deprecated Value: EOLd, potential security issues, 
maybe use db18 instead

But BDB_DEFAULT=5?  If db5 is EOL and vulnerable, why not bump the 
default version to 18?

FWIW, the only consumer of that port I have is devel/apr1, and it says