From owner-freebsd-ports-bugs@freebsd.org Thu Dec 24 12:12:58 2015 Return-Path: Delivered-To: freebsd-ports-bugs@mailman.ysv.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:1900:2254:206a::19:1]) by mailman.ysv.freebsd.org (Postfix) with ESMTP id 17BB7A50E70 for ; Thu, 24 Dec 2015 12:12:58 +0000 (UTC) (envelope-from bugzilla-noreply@freebsd.org) Received: from kenobi.freebsd.org (kenobi.freebsd.org [IPv6:2001:1900:2254:206a::16:76]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (Client did not present a certificate) by mx1.freebsd.org (Postfix) with ESMTPS id 087D11C3B for ; Thu, 24 Dec 2015 12:12:58 +0000 (UTC) (envelope-from bugzilla-noreply@freebsd.org) Received: from bugs.freebsd.org ([127.0.1.118]) by kenobi.freebsd.org (8.15.2/8.15.2) with ESMTP id tBOCCvtU043714 for ; Thu, 24 Dec 2015 12:12:57 GMT (envelope-from bugzilla-noreply@freebsd.org) From: bugzilla-noreply@freebsd.org To: freebsd-ports-bugs@FreeBSD.org Subject: [Bug 203227] vuln.xml incorrectly flagging ruby20 as insecure Date: Thu, 24 Dec 2015 12:12:57 +0000 X-Bugzilla-Reason: CC X-Bugzilla-Type: changed X-Bugzilla-Watch-Reason: None X-Bugzilla-Product: Ports & Packages X-Bugzilla-Component: Ports Framework X-Bugzilla-Version: Latest X-Bugzilla-Keywords: X-Bugzilla-Severity: Affects Some People X-Bugzilla-Who: m.panella@level28.org X-Bugzilla-Status: Closed X-Bugzilla-Priority: --- X-Bugzilla-Assigned-To: ports-secteam@FreeBSD.org X-Bugzilla-Target-Milestone: --- X-Bugzilla-Flags: X-Bugzilla-Changed-Fields: cc Message-ID: In-Reply-To: References: Content-Type: text/plain; charset="UTF-8" Content-Transfer-Encoding: 7bit X-Bugzilla-URL: https://bugs.freebsd.org/bugzilla/ Auto-Submitted: auto-generated MIME-Version: 1.0 X-BeenThere: freebsd-ports-bugs@freebsd.org X-Mailman-Version: 2.1.20 Precedence: list List-Id: Ports bug reports List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Thu, 24 Dec 2015 12:12:58 -0000 https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=203227 Matteo Panella changed: What |Removed |Added ---------------------------------------------------------------------------- CC| |m.panella@level28.org --- Comment #21 from Matteo Panella --- (In reply to Terry Kennedy from comment #20) > This has been broken again in the same manner by r404311. It needs the same fix > that was developed for this PR. Yup, just tested locally. Changing ruby 2.0.0.648,1 2.1.8,1 2.2.4,1 to ruby ruby20 2.0,12.0.0.648,1 ruby ruby21 2.1,12.1.8,1 ruby ruby22 2.2,12.2.4,1 clears the false positive (in my case, pkg audit reports ruby-2.1.8,1 as being affected by 3b50881d-1860-4721-aab1-503290e23f6c). -- You are receiving this mail because: You are on the CC list for the bug.