aboutsummaryrefslogtreecommitdiff
path: root/security
Commit message (Collapse)AuthorAgeFilesLines
* */*: Remove expired erlang and elixir portsDave Cottlehuber2022-06-2826-607/+0
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | The rebar, rebar3 and mix tools are now more than a decade old, and are the preferred ways to fetch and install specific erlang and elixir modules, aside from core compilers, documentation, and custom build tools. See UPDATING and MOVED for details. https://www.freebsd.org/status/report-2021-07-2021-09/#_freebsd_erlang_ecosystem_ports_update archivers/erlang-snappy converters/erlang-base64url databases/elixir-calecto databases/elixir-db_connection databases/elixir-ecto databases/elixir-geo databases/elixir-mariaex databases/elixir-postgrex databases/elixir-timex_ecto databases/erlang-couchbeam databases/erlang-epgsql databases/erlang-eredis devel/elixir-apex devel/elixir-bson devel/elixir-cachex devel/elixir-calendar devel/elixir-combine devel/elixir-conform devel/elixir-connection devel/elixir-coverex devel/elixir-crontab devel/elixir-csv devel/elixir-decimal devel/elixir-deppie devel/elixir-dialyze devel/elixir-distillery devel/elixir-estree devel/elixir-eternal devel/elixir-exactor devel/elixir-excoveralls devel/elixir-exjsx devel/elixir-exprotobuf devel/elixir-gen_stage devel/elixir-gettext devel/elixir-inflex devel/elixir-libring devel/elixir-math devel/elixir-msgpax devel/elixir-nadia devel/elixir-nats devel/elixir-nimble_csv devel/elixir-paratize devel/elixir-plug devel/elixir-poison devel/elixir-quantum devel/elixir-smppex devel/elixir-timex devel/elixir-trailing_format_plug devel/elixir-tzdata devel/elixir-unsafe devel/erlang-bbmustache devel/erlang-certifi devel/erlang-cuttlefish devel/erlang-erlware_commons devel/erlang-gen_smtp devel/erlang-getopt devel/erlang-goldrush devel/erlang-hut devel/erlang-jobs devel/erlang-jsx devel/erlang-katana devel/erlang-lager devel/erlang-lager_syslog devel/erlang-meck devel/erlang-metrics devel/erlang-parse_trans devel/erlang-providers devel/erlang-ssl_verify_fun devel/erlang-unicode_util_compat dns/erlang-idna misc/elixir-mime misc/elixir-uuid misc/erlang-mimerl misc/erlang-mimetypes net/elixir-kafka_ex net/elixir-oauth2 net/erlang-ranch security/elixir-comeonin security/elixir-comeonin_i18n security/elixir-jose security/erlang-fast_tls security/erlang-jose textproc/elixir-earmark textproc/elixir-funnel textproc/elixir-sweet_xml textproc/erlang-edown textproc/erlang-fast_xml textproc/erlang-p1_utils textproc/erlang-yamerl www/elixir-html_entities www/elixir-html_sanitize_ex www/elixir-httpoison www/elixir-httpotion www/elixir-joken www/elixir-maru www/elixir-phoenix www/elixir-phoenix_ecto www/elixir-phoenix_html www/elixir-phoenix_pubsub www/elixir-webassembly www/erlang-cowboy www/erlang-cowlib www/erlang-hackney www/erlang-ibrowse www/erlang-mochiweb www/erlang-mochiweb-basho www/erlang-webmachine PR: 263694 Reviewed by: olgeni@FreeBSD.org Approved by: erlang (with hat) Sponsored by: SkunkWerks, GmbH
* security/fizz: Update 2022.06.20.00 -> 2022.06.27.00Yuri Victorovich2022-06-272-4/+4
|
* security/seclists: Remove workaroundLorenzo Salvadore2022-06-273-31/+2
| | | | | Remove workaround to deal with a filename which was too long. The workaround is obsolete now that pkg has been update to 1.18.3.
* cleanup: Remove expired ports:Rene Ladan2022-06-279-410/+0
| | | | | | | | | | | 2022-06-25 lang/cmucl: Not supported upstream since 2017 and broken since FreeBSD 12.1 2022-06-25 devel/qbs: Abandoned and not working with modern clang 2022-06-25 lang/cmucl-extra: lang/cmucl is not supported upstream since 2017 and broken since FreeBSD 12.1 2022-06-25 security/protonvpn-cli: This version is deprecated and unsupported upstream. The port needs an update, which would require a fair amount of effort. Use OpenVPN or Wireguard with configuration files provided by ProtonVPN instead. 2022-06-27 sysutils/firstboot-growfs: A better version is available on all FreeBSD version 2022-06-27 security/modsecurity3-apache: The project was not developed further 2022-06-29 net-mgmt/zabbix54-frontend: Unsupported by upstream 2022-06-29 net-mgmt/zabbix54-server: Unsupported by upstream
* security/boringssl: update to the recent commitSergey A. Osokin2022-06-272-5/+5
|
* security/vuxml: Document cURL vulnerabilitiesBernard Spil2022-06-271-0/+34
|
* security/py-ropgadget: Update to 6.8Emanuel Haupt2022-06-262-4/+4
|
* security/git-credential-gopass: Update to 1.14.3Emanuel Haupt2022-06-262-9/+8
|
* security/openssl-quictls: Security patch for CVE-2022-2068Bernard Spil2022-06-252-0/+24
| | | | | Security: 4eeb93bf-f204-11ec-8fbd-d4c9ef517024 MFH: 2022Q2
* security/openssl-devel: Security update to 3.0.4Bernard Spil2022-06-253-5/+97
| | | | | Security: 4eeb93bf-f204-11ec-8fbd-d4c9ef517024 MFH: 2022Q2
* security/nss: update to 3.80Jan Beich2022-06-252-4/+4
| | | | | | Changes: https://groups.google.com/a/mozilla.org/g/dev-tech-crypto/c/EvvZnF-wh14 Changes: https://hg.mozilla.org/projects/nss/shortlog/NSS_3_80_RTM Reported by: Repology
* deprecation: we are in 2022 not 2020Baptiste Daroussin2022-06-241-1/+1
| | | | Reported by: kai
* security/gnomeint: mark as deprecatedBaptiste Daroussin2022-06-241-1/+4
| | | | | | Abandonware, depending on gnome2 libraries Approved by: maintainer
* security/rubygem-rack-oauth2: update to 1.19.0Matthias Fechner2022-06-242-5/+4
| | | | Required for gitlab-ce 15.1
* security/rubygem-omniauth-dingtalk-oauth2: udpate to 1.0.1Matthias Fechner2022-06-242-5/+5
| | | | | | | | | | Required for gitlab-ce 15.1 Changelog: https://gitlab.com/gitlab-jh/jh-team/omniauth-dingtalk/-/tags v1.0.1 - Update Gemfile ('omniauth-oauth2', '~> 1.7') - Add GitLab CI
* security/clamav: fix build on big-endian architecturesPiotr Kubaj2022-06-247-0/+100
| | | | | | | Backport https://github.com/image-rs/image/commit/ed8337afc795571795482882236acf14196e10db to fix build. Approved by: Tier 2 blanket
* security/py-social-auth-core: Update to 4.3.0Kai Knoblich2022-06-232-4/+4
| | | | | | | | | Changelog: https://github.com/python-social-auth/social-core/releases/tag/4.3.0 PR: 264811 Approved by: ultima (maintainer)
* security/vuxml: Fix vuxml buildLi-Wen Hsu2022-06-231-2/+1
| | | | | | <cvename> tag needs a valid CVE name Fixes: 8f4091638ddd9e3c0484c5791359e58aa97b493a
* security/py-yubikey-manager: Add OTP HID support for FreeBSDMichael Gmelin2022-06-235-2/+401
| | | | | | | | | | | | | | | | | | | This makes yubikey-manager usable on FreeBSD again. FreeBSD support was broken since reliance on libusb and libykpersonalize was dropped upstream in 4.0.0. This supports the classic uhid(4) driver and the more modern hidraw(4) driver. See: https://github.com/Yubico/yubikey-manager/pull/504 As I had to redo the patch after the update to 4.0.9, I took the chance to add unit test support (`make test`). A future change could remove the dependency on ykpersonalize. PR: 263916 Approved by: egypcio (maintainer timeout, about 4 weeks)
* security/boringssl: update to the recent commitSergey A. Osokin2022-06-232-5/+5
|
* security/vuxml: Document Jenkins Security Advisory 2022-06-22Li-Wen Hsu2022-06-221-0/+41
| | | | Sponsored by: The FreeBSD Foundation
* security/1password-client2: update to 2.5.1Larry Rosenman2022-06-222-10/+10
| | | | | ChangeLog: https://app-updates.agilebits.com/product_history/CLI2#v2050101
* security/1password-client2: update to 2.5.0Larry Rosenman2022-06-222-10/+10
| | | | | ChangeLog: https://app-updates.agilebits.com/product_history/CLI2#v2050001
* KDE: Update KDE Frameworks to 5.94Tobias C. Berner2022-06-222-3/+5
| | | | | | | | | | | | | 12th June 2022. KDE today announces the release of KDE Frameworks 5.95.0. KDE Frameworks are 83 addon libraries to Qt which provide a wide variety of commonly needed functionality in mature, peer reviewed and well tested libraries with friendly licensing terms. For an introduction see https://kde.org/products/frameworks/ Exp-run by: antoine PR: 264651
* security/openssl: Security update to 1.1.1pBernard Spil2022-06-223-5/+100
| | | | Security: 4eeb93bf-f204-11ec-8fbd-d4c9ef517024
* security/vuxml: Document OpenSSL vulnerabilityBernard Spil2022-06-223-38/+38
| | | | | | | * Pet `make validate` * Fix spacing for 482456fb-e9af-11ec-93b6-318d1419ea39 * Add discovery date for 482456fb-e9af-11ec-93b6-318d1419ea39 using tor wiki page update date.
* security/vuxml: add www/chromium < 103.0.5060.53Rene Ladan2022-06-221-0/+46
|
* graphics/p5-Image-ExifTool: Add an vuxml entry for update 12.42Rafael Grether2022-06-211-0/+25
| | | | PR: 264618
* security/libgsasl: Update to 2.0.0Po-Chuan Hsieh2022-06-217-161/+54
| | | | | | - Bump PORTREVISION of dependent ports for shlib change Changes: https://gitlab.com/gsasl/gsasl/-/blob/master/NEWS
* security/gsasl: Update to 2.0.0Po-Chuan Hsieh2022-06-219-76/+73
| | | | Changes: https://gitlab.com/gsasl/gsasl/-/blob/master/NEWS
* security/wpa_supplicant-devel: Update to latest GH commitCy Schubert2022-06-212-6/+5
| | | | Update to the latest w1.fi commit, proxied through my GH account.
* security/sudo: Update to 1.9.11p3Renato Botelho2022-06-212-4/+4
| | | | Sponsored by: Rubicon Communications, LLC ("Netgate")
* security/py-josepy: Convert to USE_PYTHON=pytestPo-Chuan Hsieh2022-06-211-5/+1
|
* security/py-certbot: Convert to USE_PYTHON=pytestPo-Chuan Hsieh2022-06-211-5/+1
|
* security/py-acme: Convert to USE_PYTHON=pytestPo-Chuan Hsieh2022-06-211-5/+1
|
* */Makefile: Sort SUBDIRsPo-Chuan Hsieh2022-06-211-1/+1
|
* security/cyberchef: 9.39.1Dan Langille2022-06-212-4/+4
| | | | | | re: https://github.com/gchq/CyberChef/blob/master/CHANGELOG.md PR: 264756
* security/py-yubikey-manager: update 4.0.8 to 4.0.9Vinícius Zavam2022-06-212-4/+4
|
* security/fizz: Update 2022.06.13.00 -> 2022.06.20.00Yuri Victorovich2022-06-202-4/+4
|
* */*: Restore a missing wpa BSD driver patchCy Schubert2022-06-204-6/+128
| | | | | | | | | | These patches were removed to sync with base where in fact base was missing these patches and base should have been synced with the ports. PR: 264238 Fixes: b8477825c2dc42f6c595697a36f593c71f39fbad c86f32d652eb9dd023049122d8ca37cb13ed07b6 MFH: 2022Q2
* security/vuxml: Add CVE-2022-24766 for www/mitmproxyHung-Yi Chen2022-06-201-0/+39
| | | | PR: 264782
* security/wpa_supplicant29: fix PKGBASE collisionAntoine Brodin2022-06-201-0/+1
|
* */*: Bring back wpa_supplicant29 and hostapd29 as new portsCy Schubert2022-06-1919-0/+1074
| | | | | | | | | | | The current wpa_supplicant and hostapd have an issue with AR9285. For the time being bring back wpa_supplicant 2.9 as security/wpa_supplicant29 and hostpd 2.9 as net/hostapd29 for those cases that have an issue with wpa_supplicant/hostpad2.10 (in base and in ports) PR: 264238 MFH: 2022Q2
* security/apg: update 0.4.0 to 0.4.1Vinícius Zavam2022-06-192-5/+4
| | | | https://github.com/wneessen/apg-go/releases/tag/v0.4.1
* security/tailscale: Update to 1.26.1Ashish SHUKLA2022-06-182-7/+6
|
* security/py-python-jose: Update to 3.3.0Dan Langille2022-06-182-10/+12
| | | | re: https://github.com/mpdavis/python-jose/releases/tag/3.3.0
* security/rhash: update RHash to the latest version 1.4.3Alexey Dokuchaev2022-06-183-39/+4
| | | | | | | | | | After a long long time, the patch* yielding ~1.6x performance boost of RIPEMD-160 on some CPUs by interleaving the macro/function calls had been finally integrated upstream, remove it from the port. Reported by: portscout *) https://sourceforge.net/p/rhash/patches/5/
* security/tor: Update 0.4.7.7 -> 0.4.7.8Yuri Victorovich2022-06-172-4/+4
| | | | Reported by: Tor Project notification
* security/vuxml: Add vulnerability record for security/tor TROVE-2022-001[0]Yuri Victorovich2022-06-171-0/+26
|
* security/snort3: Update to 3.1.32.0Dan Langille2022-06-173-4/+5
| | | | | | re: https://github.com/snort3/snort3/releases/tag/3.1.32.0 Approved by: maintainer (via private email)