From nobody Tue Nov 19 16:30:03 2024 X-Original-To: dev-commits-ports-main@mlmmj.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mlmmj.nyi.freebsd.org (Postfix) with ESMTP id 4Xt92M758pz5fBRr; Tue, 19 Nov 2024 16:30:03 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from mxrelay.nyi.freebsd.org (mxrelay.nyi.freebsd.org [IPv6:2610:1c1:1:606c::19:3]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "mxrelay.nyi.freebsd.org", Issuer "R10" (verified OK)) by mx1.freebsd.org (Postfix) with ESMTPS id 4Xt92M6Z7lz4LNk; Tue, 19 Nov 2024 16:30:03 +0000 (UTC) (envelope-from git@FreeBSD.org) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1732033803; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=qdzBLrgZxx/4xF7QJaXrZZvAkZfHRgaCzfSjRdwrOQU=; b=H3Yw+6KAl60ZD0r5VxAJbaUr7uCcwH7r/bkuzuRnfCzcSNeTWY0pp7favcFo199o9u+ZTy OjQj8BRx6hy/yFJ0zm77vUj0Hzw0aBClQqvGUTGIJCqUuQynDJXp23gTvNx1AIyvLnFIHl 0ft+nlqLggEAND2GS/sMnWAE64rzWF/DdpDP4IYSVu/unfPA/nDL2Pylji4DzsIe11rgEh co1fjWGXsE4rUkYjW3FEm0WF98d5tiw7N5ROSnFF6oSSJZUk/wvan/i0nD5TldWIfw/8ZO 7Zw+xTbiw2s+kiK4nGQ6cIlRi+ST3iOb0iZXG9mOTcFnjM36J8aQ1jGRcfNc4w== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1732033803; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=qdzBLrgZxx/4xF7QJaXrZZvAkZfHRgaCzfSjRdwrOQU=; b=fJCq17nrXezG0huSr7YKDuZOWGZWw2wB4Z2Xuc3OyFK/PaMkZDlRhdrgZdqm2hUunLQKw8 X1VxNuRPal/fMcAKcZERbT5Di3lZDegbiZnezazKEJWn5+GwMNQ6TTfNBpZIoTnJLuiipB y8M2DZG34hjKU2DCzVLL5n2gk75zOrsUQZC0VU+0I+a0krvXc9Bu0H/iWCJKqAE0lJPVAY 6NAAP1pgEj6js+S3Kz3t/mwbwm5hEunCnVhmU3ofqPiPsVh99U32E0t+olAJlTQixPWOsE bha34lR8nEJcTtkCzgvQuiGVEcr16HvlM2+bhfPqlU7iJ3enXcUKhBK4ghiGiA== ARC-Authentication-Results: i=1; mx1.freebsd.org; none ARC-Seal: i=1; s=dkim; d=freebsd.org; t=1732033803; a=rsa-sha256; cv=none; b=D64O+oon3HAimbwAALAPODaMz0KBbXWr6yQKUThblTowmm8f1lzaiuO8CTN8cbmd//D9UG ypG69HUe1qiyH9AYnRcOAlDeSyjjEiw3MkMYz/wd8TSgzGNKAIztyfiRdRfdYx1k++Aka4 Et8aME0c4400bAMDFYFW3YaX4/CtU8G9dvrj+6JI3QN1alrHQVsm4ZtVsXFXbARQdHmc4p tacMUxsS9Zrxe5cvkySZnCUCH2+b1r04f3t/j/RdZstojOlTlyVkju4NN/kswDVP8bK7dn Kc7F/M86r3PwnwZmpB7l7VHuAUJY4lrXhSK7MwQjCM8XxHvceU0mZzZo81S73A== Received: from gitrepo.freebsd.org (gitrepo.freebsd.org [IPv6:2610:1c1:1:6068::e6a:5]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (Client did not present a certificate) by mxrelay.nyi.freebsd.org (Postfix) with ESMTPS id 4Xt92M63G0zHG8; Tue, 19 Nov 2024 16:30:03 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from gitrepo.freebsd.org ([127.0.1.44]) by gitrepo.freebsd.org (8.18.1/8.18.1) with ESMTP id 4AJGU3xN056420; Tue, 19 Nov 2024 16:30:03 GMT (envelope-from git@gitrepo.freebsd.org) Received: (from git@localhost) by gitrepo.freebsd.org (8.18.1/8.18.1/Submit) id 4AJGU3Ax056415; Tue, 19 Nov 2024 16:30:03 GMT (envelope-from git) Date: Tue, 19 Nov 2024 16:30:03 GMT Message-Id: <202411191630.4AJGU3Ax056415@gitrepo.freebsd.org> To: ports-committers@FreeBSD.org, dev-commits-ports-all@FreeBSD.org, dev-commits-ports-main@FreeBSD.org From: Michael Reifenberger Subject: git: 63974c070ff0 - main - security/vaultwarden: Security update to 1.32.5 List-Id: Commits to the main branch of the FreeBSD ports repository List-Archive: https://lists.freebsd.org/archives/dev-commits-ports-main List-Help: List-Post: List-Subscribe: List-Unsubscribe: X-BeenThere: dev-commits-ports-main@freebsd.org Sender: owner-dev-commits-ports-main@FreeBSD.org MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: 8bit X-Git-Committer: mr X-Git-Repository: ports X-Git-Refname: refs/heads/main X-Git-Reftype: branch X-Git-Commit: 63974c070ff072210b7991216bd8779e4302e4e3 Auto-Submitted: auto-generated The branch main has been updated by mr: URL: https://cgit.FreeBSD.org/ports/commit/?id=63974c070ff072210b7991216bd8779e4302e4e3 commit 63974c070ff072210b7991216bd8779e4302e4e3 Author: Michael Reifenberger AuthorDate: 2024-11-19 16:25:01 +0000 Commit: Michael Reifenberger CommitDate: 2024-11-19 16:25:01 +0000 security/vaultwarden: Security update to 1.32.5 This release further fixed some CVE Reports reported by a third party security auditor and we recommend everybody to update to the latest version as soon as possible. The contents of these reports will be disclosed publicly in the future. PR: 282795 Reported by: Bernard Spil --- security/vaultwarden/Makefile | 2 +- security/vaultwarden/Makefile.crates | 4 ++++ security/vaultwarden/distinfo | 14 +++++++++++--- security/vaultwarden/pkg-plist | 1 - 4 files changed, 16 insertions(+), 5 deletions(-) diff --git a/security/vaultwarden/Makefile b/security/vaultwarden/Makefile index acb0d7596edf..350470bb7689 100644 --- a/security/vaultwarden/Makefile +++ b/security/vaultwarden/Makefile @@ -1,5 +1,5 @@ PORTNAME= vaultwarden -DISTVERSION= 1.32.4 +DISTVERSION= 1.32.5 CATEGORIES= security MAINTAINER= mr@FreeBSD.org diff --git a/security/vaultwarden/Makefile.crates b/security/vaultwarden/Makefile.crates index 819fa464cc58..89dc1925f265 100644 --- a/security/vaultwarden/Makefile.crates +++ b/security/vaultwarden/Makefile.crates @@ -53,6 +53,7 @@ CARGO_CRATES= addr2line-0.24.2 \ chrono-tz-0.10.0 \ chrono-tz-build-0.4.0 \ chumsky-0.9.3 \ + codemap-0.1.3 \ concurrent-queue-2.5.0 \ cookie-0.18.1 \ cookie_store-0.21.1 \ @@ -120,6 +121,7 @@ CARGO_CRATES= addr2line-0.24.2 \ glob-0.3.1 \ gloo-timers-0.3.0 \ governor-0.7.0 \ + grass_compiler-0.13.4 \ h2-0.3.26 \ h2-0.4.6 \ half-1.8.3 \ @@ -177,6 +179,7 @@ CARGO_CRATES= addr2line-0.24.2 \ js-sys-0.3.72 \ jsonwebtoken-9.3.0 \ kv-log-macro-1.0.7 \ + lasso-0.7.3 \ lazy_static-1.5.0 \ lettre-0.11.10 \ libc-0.2.162 \ @@ -242,6 +245,7 @@ CARGO_CRATES= addr2line-0.24.2 \ phf-0.11.2 \ phf_codegen-0.11.2 \ phf_generator-0.11.2 \ + phf_macros-0.11.2 \ phf_shared-0.11.2 \ pico-args-0.5.0 \ pin-project-lite-0.2.15 \ diff --git a/security/vaultwarden/distinfo b/security/vaultwarden/distinfo index 940a5430f80f..e9466fe537b8 100644 --- a/security/vaultwarden/distinfo +++ b/security/vaultwarden/distinfo @@ -1,4 +1,4 @@ -TIMESTAMP = 1731311981 +TIMESTAMP = 1731934491 SHA256 (rust/crates/addr2line-0.24.2.crate) = dfbe277e56a376000877090da837660b4427aad530e3028d44e0bffe4f89a1c1 SIZE (rust/crates/addr2line-0.24.2.crate) = 39015 SHA256 (rust/crates/adler2-2.0.0.crate) = 512761e0bb2578dd7380c6baaa0f4ce03e84f95e960231d1dec8bf4d7d6e2627 @@ -109,6 +109,8 @@ SHA256 (rust/crates/chrono-tz-build-0.4.0.crate) = e94fea34d77a245229e7746bd2beb SIZE (rust/crates/chrono-tz-build-0.4.0.crate) = 10660 SHA256 (rust/crates/chumsky-0.9.3.crate) = 8eebd66744a15ded14960ab4ccdbfb51ad3b81f51f3f04a80adac98c985396c9 SIZE (rust/crates/chumsky-0.9.3.crate) = 75112 +SHA256 (rust/crates/codemap-0.1.3.crate) = b9e769b5c8c8283982a987c6e948e540254f1058d5a74b8794914d4ef5fc2a24 +SIZE (rust/crates/codemap-0.1.3.crate) = 9483 SHA256 (rust/crates/concurrent-queue-2.5.0.crate) = 4ca0197aee26d1ae37445ee532fefce43251d24cc7c166799f4d46817f1d3973 SIZE (rust/crates/concurrent-queue-2.5.0.crate) = 22654 SHA256 (rust/crates/cookie-0.18.1.crate) = 4ddef33a339a91ea89fb53151bd0a4689cfce27055c291dfa69945475d22c747 @@ -243,6 +245,8 @@ SHA256 (rust/crates/gloo-timers-0.3.0.crate) = bbb143cf96099802033e0d4f4963b19fd SIZE (rust/crates/gloo-timers-0.3.0.crate) = 5530 SHA256 (rust/crates/governor-0.7.0.crate) = 0746aa765db78b521451ef74221663b57ba595bf83f75d0ce23cc09447c8139f SIZE (rust/crates/governor-0.7.0.crate) = 131769 +SHA256 (rust/crates/grass_compiler-0.13.4.crate) = 2d9e3df7f0222ce5184154973d247c591d9aadc28ce7a73c6cd31100c9facff6 +SIZE (rust/crates/grass_compiler-0.13.4.crate) = 166416 SHA256 (rust/crates/h2-0.3.26.crate) = 81fe527a889e1532da5c525686d96d4c2e74cdd345badf8dfef9f6b39dd5f5e8 SIZE (rust/crates/h2-0.3.26.crate) = 168315 SHA256 (rust/crates/h2-0.4.6.crate) = 524e8ac6999421f49a846c2d4411f337e53497d8ec55d67753beffa43c5d9205 @@ -357,6 +361,8 @@ SHA256 (rust/crates/jsonwebtoken-9.3.0.crate) = b9ae10193d25051e74945f1ea2d0b42e SIZE (rust/crates/jsonwebtoken-9.3.0.crate) = 48987 SHA256 (rust/crates/kv-log-macro-1.0.7.crate) = 0de8b303297635ad57c9f5059fd9cee7a47f8e8daa09df0fcd07dd39fb22977f SIZE (rust/crates/kv-log-macro-1.0.7.crate) = 16842 +SHA256 (rust/crates/lasso-0.7.3.crate) = 6e14eda50a3494b3bf7b9ce51c52434a761e383d7238ce1dd5dcec2fbc13e9fb +SIZE (rust/crates/lasso-0.7.3.crate) = 78870 SHA256 (rust/crates/lazy_static-1.5.0.crate) = bbd2bcb4c963f2ddae06a2efc7e9f3591312473c50c6685e1f298068316e66fe SIZE (rust/crates/lazy_static-1.5.0.crate) = 14025 SHA256 (rust/crates/lettre-0.11.10.crate) = 0161e452348e399deb685ba05e55ee116cae9410f4f51fe42d597361444521d9 @@ -487,6 +493,8 @@ SHA256 (rust/crates/phf_codegen-0.11.2.crate) = e8d39688d359e6b34654d328e2622346 SIZE (rust/crates/phf_codegen-0.11.2.crate) = 12977 SHA256 (rust/crates/phf_generator-0.11.2.crate) = 48e4cc64c2ad9ebe670cb8fd69dd50ae301650392e81c05f9bfcb2d5bdbc24b0 SIZE (rust/crates/phf_generator-0.11.2.crate) = 14190 +SHA256 (rust/crates/phf_macros-0.11.2.crate) = 3444646e286606587e49f3bcf1679b8cef1dc2c5ecc29ddacaffc305180d464b +SIZE (rust/crates/phf_macros-0.11.2.crate) = 4748 SHA256 (rust/crates/phf_shared-0.11.2.crate) = 90fcb95eef784c2ac79119d1dd819e162b5da872ce6f3c3abe1e8ca1c082f72b SIZE (rust/crates/phf_shared-0.11.2.crate) = 14284 SHA256 (rust/crates/pico-args-0.5.0.crate) = 5be167a7af36ee22fe3115051bc51f6e6c7054c9348e28deb4f49bd6f705a315 @@ -909,5 +917,5 @@ SHA256 (rust/crates/zerovec-0.10.4.crate) = aa2b893d79df23bfb12d5461018d408ea19d SIZE (rust/crates/zerovec-0.10.4.crate) = 126398 SHA256 (rust/crates/zerovec-derive-0.10.3.crate) = 6eafa6dfb17584ea3e2bd6e76e0cc15ad7af12b09abdd1ca55961bed9b1063c6 SIZE (rust/crates/zerovec-derive-0.10.3.crate) = 19438 -SHA256 (dani-garcia-vaultwarden-1.32.4_GH0.tar.gz) = 7cf9a5c7356df42b0da318a446bf576c2aa340581ec4c729f1cb616754cf66ad -SIZE (dani-garcia-vaultwarden-1.32.4_GH0.tar.gz) = 619528 +SHA256 (dani-garcia-vaultwarden-1.32.5_GH0.tar.gz) = 305b195e464cd831abc31112aec9dad634b44323069cfe3dc675ede41a3a42d9 +SIZE (dani-garcia-vaultwarden-1.32.5_GH0.tar.gz) = 623393 diff --git a/security/vaultwarden/pkg-plist b/security/vaultwarden/pkg-plist index 7255bbe8daa1..6136a66ce9ec 100644 --- a/security/vaultwarden/pkg-plist +++ b/security/vaultwarden/pkg-plist @@ -1,5 +1,4 @@ bin/vaultwarden etc/rc.conf.d/vaultwarden.sample -etc/rc.d/vaultwarden @dir %%ETCDIR%%/rc.conf.d @dir(www,www,755) %%WWWDIR%%/data