Skip site navigation (1)Skip section navigation (2)
Date:      Wed, 16 Nov 2022 00:51:22 +0000
From:      Amar Takhar <verm@darkbeer.org>
To:        freebsd-ports@freebsd.org
Subject:   Re: Some ports uses git while make configure to load deps
Message-ID:  <20221116005122.GA69273@darkbeer.org>
In-Reply-To: <20221116021440.4da2a3e5@rimwks.local>
References:  <20221116021440.4da2a3e5@rimwks.local>

next in thread | previous in thread | raw e-mail | index | archive | help
On 2022-11-16 02:14 +0200, Rozhuk Ivan wrote:
> Hi!
> 
> 
> I see this many times with different ports, for example: graphics/evince.
> Probably this is new meson behaviour.
<snip> 
> 
> Does it violates some ports requirements to not load anything that not covered by "make makesum"?

I would think if the port had a commit hash pinned it would be fine but.

I took a look at graphics/evince and it seems to just pull down the main branch?  
That's kind disturbing as it would not always match what the port creator tested 
when making the port.  It also makes any kind of auditing useless.


Amar.



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?20221116005122.GA69273>