Commit Graph

41214 Commits

Author SHA1 Message Date
Sergey A. Osokin e023c9e3b9 security/boringssl: update to the recent snapshot 2024-11-08 14:20:39 -05:00
Dirk Meyer 0b6f281593 security/vuxml: add CVE-2018-10195, CVE-2020-29074 2024-11-08 18:49:55 +01:00
Älven 2f47d7ff7d security/vuxml: Document tnef vulnerabilities
PR:		282228
2024-11-08 11:04:20 -03:00
Hiroki Tagato 7ce45b8e01 security/vuxml: document electron32 multiple vulnerabilities
Obtained from:	https://github.com/electron/electron/releases/tag/v32.2.3
2024-11-08 20:24:02 +09:00
Muhammad Moinur Rahman e323ac9ae8 security/lasso: Runtime fix after xmlsec1 upgrade
- Fix build with upcoming libxml upgrade [1]

PR:		282243, 281592[1]
Reported by:	ray@bellis.me.uk, diizzy[1]
2024-11-08 09:32:25 +01:00
Mikael Urankar ca048c2884 lang/rust: Bump revisions after 1.82.0
PR:		282516
2024-11-08 09:24:20 +01:00
Jason E. Hale bbb9d90abc security/authenticator: Convert to USE_GSTREAMER=rust 2024-11-07 20:23:36 -05:00
Jason E. Hale 3d87c4ff59 security/vuxml: Document gstreamer1-rtsp-server
Only affected if assertions are enabled, which we don't do by default.
2024-11-07 20:22:51 -05:00
Hiroki Sato 8b41ea64ec security/xmlsec1: Update to 1.3.6 2024-11-08 08:12:45 +09:00
Larry Rosenman 5e21b76903 security/1password-client2: update to 2.30.3
ChangeLog:
This release includes security improvements, bug fixes for 1Password CLI commands, and introduces enhanced configuration options.

Improvements
The `OP_RUN_NO_MASKING` environment variable is now exposed to allow users to control the masking of the `op run` command output. {4089}
Fixed
For 1Password accounts that are managed by an MSP, 1Password CLI commands involving Service Accounts, Connect, or the Events API no longer occasionally return an error. {4033}
The `op read`, `op run` and `op inject` commands no longer query archived items. {3893}
Security
On Windows, the CLI now checks each signature of the 1Password desktop app before connecting to it. {4136}
2024-11-07 16:32:04 -06:00
Bernard Spil 6813c7fa10 security/nextcloud-passman: Update to 2.4.11 2024-11-07 20:29:07 +01:00
Ashish SHUKLA 3990d4e61d security/tailscale: Update to 1.76.6
MFH:		2024Q4
2024-11-07 18:01:00 +00:00
Markus Wipp 320891cd55 security/step-certificates: Update 0.27.2 → 0.27.5
Changelogs:
https://github.com/smallstep/certificates/releases/tag/v0.27.4
https://github.com/smallstep/certificates/releases/tag/v0.27.5

PR:	282211
2024-11-07 15:27:17 +03:00
Markus Wipp 0f427f3575 security/step-cli: Update 0.27.2 → 0.27.5
Changelogs:
https://github.com/smallstep/cli/releases/tag/v0.27.4
https://github.com/smallstep/cli/releases/tag/v0.27.5

PR:	282211
2024-11-07 15:27:17 +03:00
Dima Panov aa66784cf0 security/botan3: update to 3.6.1 release (+)
Changelog:	https://botan.randombit.net/news.html#version-3-6-1-2024-10-26
		https://botan.randombit.net/news.html#version-3-6-0-2024-10-21
2024-11-06 18:51:52 +03:00
Robert Clausecker 6e2da9672f filesystems: add new category for file systems and related utilities
The filesystems category houses file systems and file system utilities.
It is added mainly to turn the sysutils/fusefs-* pseudo-category into
a proper one, but is also useful for the sundry of other file systems
related ports found in the tree.

Ports that seem like they belong there are moved to the new category.
Two ports, sysutils/fusefs-funionfs and sysutils/fusefs-fusepak are
not moved as they currently don't fetch and don't have TIMESTAMP set
in their distinfo, but that is required to be able to push a rename
of the port by the pre-receive hook.

Approved by:	portmgr (rene)
Reviewed by:	mat
Pull Request:	https://github.com/freebsd/freebsd-ports/pull/302
PR:		281988
2024-11-06 16:17:35 +01:00
Robert Nagy 92e1c36a51 security/vuxml: add www/*chromium < 130.0.6723.116
Obtained from:	https://chromereleases.googleblog.com/2024/11/stable-channel-update-for-desktop.html
2024-11-06 13:03:21 +01:00
Yuri Victorovich 94fb2b7ebe security/fizz: update 2024.10.28.00 → 2024.11.04.00 2024-11-04 23:25:45 -08:00
Yuri Victorovich 447593850b security/flawz: update 0.2.2 → 0.3.0 2024-11-04 17:26:40 -08:00
Älven 1bdede316d security/vuxml: Add record for devel/libqb < 2.0.8 CVE-2023-39976
log_blackbox.c in libqb before 2.0.8 allows a buffer overflow via long
log messages because the header size is not considered.
https://nvd.nist.gov/vuln/detail/CVE-2023-39976

PR:	282536
2024-11-04 22:01:32 +03:00
Gleb Popov 791bbaf6c8 security/gcr: Update to 4.3.0
Move the previous version to security/gcr3 and switch consumer ports to it

PR:		282046
Approved by:	vishwin
Sponsored by:	Future Crew, LLC
2024-11-04 19:50:19 +03:00
Emanuel Haupt 148aa6b71e security/rage-encryption: Update to 0.11.0 2024-11-04 15:44:49 +01:00
Emanuel Haupt 23475abd53 security/git-credential-oauth: Update to 0.13.4 2024-11-04 15:44:49 +01:00
Dan Langille aa1aa0720a security/py-first-server: Mark as deprecated, add expiry date
Upstream code has been archived - project closed.

Whle here, portlint and portfmt. Who wrote this port?
2024-11-04 14:16:05 +00:00
Po-Chuan Hsieh 987180f3d4 security/rubygem-doorkeeper-openid_connect: Change RUN_DEPENDS from rubygem-doorkeeper-rails70 to rubygem-doorkeeper57-rails70
- Bump PORTREVISION for dependency change
2024-11-03 21:24:02 +08:00
Po-Chuan Hsieh 08a03bda54 security/rubygem-doorkeeper-rails70: Update to 5.8.0
Changes:	https://github.com/doorkeeper-gem/doorkeeper/releases
2024-11-03 21:23:57 +08:00
Po-Chuan Hsieh e7e2763a6d security/rubygem-doorkeeper-rails50: Update to 5.8.0
Changes:	https://github.com/doorkeeper-gem/doorkeeper/releases
2024-11-03 21:23:53 +08:00
Po-Chuan Hsieh 0352aaa4d4 security/rubygem-doorkeeper-rails5: Update to 5.8.0
Changes:	https://github.com/doorkeeper-gem/doorkeeper/releases
2024-11-03 21:23:49 +08:00
Po-Chuan Hsieh 538fb0a9c1 security/rubygem-doorkeeper: Update to 5.8.0
Changes:	https://github.com/doorkeeper-gem/doorkeeper/releases
2024-11-03 21:23:46 +08:00
Po-Chuan Hsieh f6fb39e318 security/p5-Authen-Radius: Update to 0.33
Changes:	https://metacpan.org/dist/Authen-Radius/changes
2024-11-03 21:23:33 +08:00
Po-Chuan Hsieh 0b8ec2a308 security/rubygem-doorkeeper57-rails70: Add rubygem-doorkeeper57-rails70 5.7.1 (copied from rubygem-doorkeeper-rails70)
- Add PORTSCOUT
2024-11-03 21:20:52 +08:00
Craig Leres a8b1ce8bbb security/py-pysrp: Fix github config
GH_TAG should have been GH_TAGNAME which defaults to DISTVERSIONFULL
and isn't needed. And GH_ACCOUNT defaults to PORTNAME and isn't
needed.
2024-11-02 10:58:04 -07:00
Craig Leres f754c341f2 security/py-pysrp: Update to 1.0.22
Changes since 1.0.21:

 - Keep leading zero bytes in salt.
2024-11-02 10:26:17 -07:00
Robert Nagy 508fcad02f security/vuxml: add www/*chromium < 130.0.6723.91
Obtained from:	https://chromereleases.googleblog.com/2024/10/stable-channel-update-for-desktop_29.html
2024-11-02 09:14:11 +01:00
Matthias Fechner 73948f2c2e security/trivy: update to 0.57.0
Changes:	https://github.com/aquasecurity/trivy/releases/tag/v0.57.0
2024-11-02 09:06:37 +02:00
Santhosh Raju 5d788b4067 security/wolfssl: Enable additional build options.
Enable option for storing user-defined data in TLS API

PR:             282430
Reported by:    Matthias Andree <mandree@FreeBSD.org>
2024-11-02 04:10:37 +01:00
Nuno Teixeira e648504926 security/s2n-tls: Update to 1.5.7
ChangeLog: https://github.com/aws/s2n-tls/releases/tag/v1.5.7
2024-11-01 18:09:12 +00:00
Kai Knoblich 697cec7f05 security/py-netbox-secrets: Update to 2.1.0
Changelog:

https://github.com/Onemind-Services-LLC/netbox-secrets/releases/tag/v2.1.0

MFH:		No (not compatible with NetBox 4.0)
2024-11-01 16:21:19 +01:00
Ricardo Branco c2a8a5e07e security/xhash: Update to v3.5.3
While here,

- Sync MAINTAINER to maintainer's Bugzilla email

PR:		282225
2024-11-01 10:40:07 +09:00
Jason E. Hale 6892e780d7 security/vuxml: Add www/qt5-webengine < 5.15.18p2
Fix indentation issues caught by `make validate` for previous entry.
2024-10-31 20:41:09 -04:00
Carlo Strub 05b782b2c5 security/arti: Update to 1.3.0 2024-10-31 21:49:20 +01:00
Po-Chuan Hsieh e121d7c85d security/libssh: Update WWW 2024-11-01 04:40:21 +08:00
Po-Chuan Hsieh a32355427e security/libaegis: Update to 0.1.24
Changes:	https://github.com/aegis-aead/libaegis/releases
2024-11-01 04:40:18 +08:00
Daniel Engberg 3fd98fa0c1 security/libssh2: Backport upstream commits
Backport upstream commit 5d03b4f94ac6740e0085a6acda6fc417ca6ecc83 and
d4e43c7b69d10b6cfaaa53787addfd4beac7a3ce

References:
https://github.com/libssh2/libssh2/commit/5d03b4f94ac6740e0085a6acda6fc417ca6ecc83
https://github.com/libssh2/libssh2/commit/d4e43c7b69d10b6cfaaa53787addfd4beac7a3ce

Approved by:	portmgr (blanket, build fix)
2024-10-31 20:56:19 +01:00
Dmitry Marakasov c818497c04 */*: fix handling of # character in COMMENT
Approved by:	portmgr blanket
2024-10-31 20:44:13 +03:00
Palle Girgensohn 319b9c0cd3 security/shibboleth-sp: Fix build with clang19
There was probably a name space clash between std and xmltooling for
the `char_traits' method.

See also:	https://shibboleth.atlassian.net/browse/SSPCPP-998
2024-10-31 13:58:56 +01:00
Matthias Wolf 331f33b5fe security/vuxml: Add record for net/keycloak < 26.0.4 CVE-2021-44549
PR:	282419
2024-10-31 13:50:31 +03:00
Emanuel Haupt 11f6e63047 security/git-credential-oauth: Update to 0.13.3 2024-10-31 10:17:08 +01:00
Yuri Victorovich 43da3e3baa security/openfhe: update 1.2.2 → 1.2.3
Reported by:	portscout
2024-10-31 01:28:17 -07:00
Dima Panov cf8cecd821 security/linux-rl9-nss: update to 3.101.0
Sponsored by:	Future Crew, LLC
2024-10-31 10:54:13 +03:00