From owner-freebsd-ports@FreeBSD.ORG Tue Sep 1 13:14:02 2009 Return-Path: Delivered-To: freebsd-ports@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id E57371065670 for ; Tue, 1 Sep 2009 13:14:02 +0000 (UTC) (envelope-from thomas@goodking.ca) Received: from mail-pz0-f190.google.com (mail-pz0-f190.google.com [209.85.222.190]) by mx1.freebsd.org (Postfix) with ESMTP id 813538FC13 for ; Tue, 1 Sep 2009 13:14:02 +0000 (UTC) Received: by pzk28 with SMTP id 28so3875254pzk.27 for ; Tue, 01 Sep 2009 06:14:00 -0700 (PDT) Received: by 10.114.69.19 with SMTP id r19mr4480732waa.117.1251810830671; Tue, 01 Sep 2009 06:13:50 -0700 (PDT) Received: from goodking.goodking.ca (dynamic-216-211-42-235.tbaytel.net [216.211.42.235]) by mx.google.com with ESMTPS id l30sm734821waf.0.2009.09.01.06.13.48 (version=TLSv1/SSLv3 cipher=RC4-MD5); Tue, 01 Sep 2009 06:13:49 -0700 (PDT) Sender: Thomas Abthorpe From: Thomas Abthorpe Organization: FreeBSD.GoodKing.Ca To: freebsd-ports@freebsd.org Date: Tue, 1 Sep 2009 09:13:44 -0400 User-Agent: KMail/1.9.10 References: <57200BF94E69E54880C9BB1AF714BBCBA56E9A@w2003s01.double-l.local> In-Reply-To: <57200BF94E69E54880C9BB1AF714BBCBA56E9A@w2003s01.double-l.local> X-Face: /|[9,PbEOB6g>?2^*Sc|"~6:Ro"O>Nv\Rfkv\42g)=?utf-8?q?TuAYG=26+bD=5CpCJTX31s=5Fp=7Bc7=5D5a=2ED=2E=0A=09Y?=@QddKu_I[XB8; euK=^[=L1I#]rgi[0jgz^4qCTwlj]3kJ)]vc}O"HrA14hN)=?utf-8?q?aXewJPTi=7C=0A=09Pt=7BS3=23Vw4x-?="/:& Cc: Johan Hendriks Subject: Re: squirrelmail port X-BeenThere: freebsd-ports@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: Porting software to FreeBSD List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Tue, 01 Sep 2009 13:14:03 -0000 -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 On September 1, 2009 07:36:56 am Johan Hendriks wrote: > Since when are we using release candidate's of squirrelmail in the ports > tree. > I think we need an devel port for that so that we can use the stable > squirrelmail port as stable, and use the devel port if we want to use > beta's and release candidates. > > > > Regards, > Johan > Hey Johan Once the XSS vulnerability was brought to my attention, http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2964 (plus related links) I decided to err on the side of caution, and upgrade to a more stable version, albeit an RC. Yes I know I could have patched it, but chose not to. I am hoping that the release branch will be out sooner than later. Thomas - -- Thomas Abthorpe | FreeBSD Committer tabthorpe@FreeBSD.org | http://people.freebsd.org/~tabthorpe -----BEGIN PGP SIGNATURE----- Version: GnuPG v2.0.12 (FreeBSD) iEYEARECAAYFAkqdHgkACgkQ5Gm/jNBp8qAeRwCeInu4BpN9IWQMa+0glxhFJz0B exIAnRChCLMGSRWHPvOT86aMIHsfUI8l =YoJH -----END PGP SIGNATURE-----