portsdb output and portaudit question

Svein Halvor Halvorsen svein.h at lvor.halvorsen.cc
Mon Jul 31 18:10:31 UTC 2006


jan gestre wrote:
> i was trying to portupgrade ruby coz portaudit is complaining of
> vulnerabilities, i did run cvsup and portsdb -Uu before portupgrade, at
> first i couldn't upgrade ruby coz portupgrade is complaining maybe coz
> portaudit but someone in the list suggested this:
> 
> # portupgrade -Rr -m DISABLE_VULNERABILITIES="yes" ruby
> 
> whoala it installed the ruby package but still portaudit complains even
> though the installed version is current which has no vulnerability. is this
> normal? any way to fix these?


This is expected behavior. The ports system will let you upgrade a
vulnerable port without complaint. It will however complain if you try
to install (or upgrade to) a version that has vulnerabilities. Since
portupgrade complained, it's no surprise that portaudit also complains
after the forced upgrade.

This means that either the version in ports aren't fixed yet (the
existence of a vulnerability of a prior version does not imply that said
vulnerability is fixed in the current version), or that your ports tree
 is out of date. Seeing that the latter is not true, I would say you
just have to wait for an updated version to appear in ports.

You can create an account at freshports and ad ruby to your "watch
list". That means you'll get notified when new versions arrive.


	Svein Halvor

-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 247 bytes
Desc: OpenPGP digital signature
Url : http://lists.freebsd.org/pipermail/freebsd-questions/attachments/20060731/083bc1b9/signature.pgp


More information about the freebsd-questions mailing list