git: 0605ef1bd0c2 - main - graphics/ImageMagick6: upgrade to 6.9.12-12

Dan Langille dan at langille.org
Fri Jun 11 17:56:01 UTC 2021


> On Jun 11, 2021, at 1:26 PM, Thierry Thomas <thierry at freebsd.org> wrote:
> 
> Le ven. 11 juin 21 à 18:48:18 +0200, Dan Langille <dan at langille.org>
> écrivait :
> 
>>>   Note: this might fix some vulnerabilities, e.g. CVE-2021-20244,
>>>   CVE-2021-20243, CVE-2021-20176 or CVE-2020-27829, but this is not clear
>>>   for me.
>>> 
>>>   PR:             255818
>>>   Approved by:    maintainer’s time-out
>> 
>> This was a vuln fix and not backported to 2021Q2?
>> 
>> Is there any reason I should not do that backport now?
> 
> Yes, please! I sent a mail to ports-secteam@ and to the maintainer, but
> did not get any answer, and then I forgot about it…

I understand that we no longer need secteam permission for backports of security items.

— 
Dan Langille
http://langille <http://langille/>.org/








More information about the dev-commits-ports-main mailing list