ports/48352: JavaCC port updated for new distfiles.
Andy Gerweck
andy at tacnode.com
Tue Apr 29 17:53:18 UTC 2003
Were you planning on committing this change? Like I said, the port is
useless without the updated checksum. Any risk of trojan should be
obvious to the user who has to go and manually fetch the distribution
files from WebGain.
Thanks,
Andy Gerweck
Peter Pentchev wrote:
> Synopsis: JavaCC port updated for new distfiles.
>
> State-Changed-From-To: open->feedback
> State-Changed-By: roam
> State-Changed-When: Fri Feb 28 06:23:56 PST 2003
> State-Changed-Why:
> Do you know what exactly changed in the distfile? Would you happen to
> keep a copy of the old distfile, and if so, could you run a 'diff' or
> something to find out what exactly changed?
>
> The MD5 checksum mechanism is there for a reason: there have been many
> cases in the past years of intruders modifying distribution files to add
> Trojans; it would benicegood to know exactly what the changes are before
> bldndly updating the checksum :)
>
>
> Responsible-Changed-From-To: freebsd-ports-bugs->roam
> Responsible-Changed-By: roam
> Responsible-Changed-When: Fri Feb 28 06:23:56 PST 2003
> Responsible-Changed-Why:
> I'll take care of this one.
>
> http://www.freebsd.org/cgi/query-pr.cgi?pr=48352
More information about the freebsd-ports-bugs
mailing list