From nobody Thu Jul 6 06:24:43 2023 X-Original-To: dev-commits-ports-branches@mlmmj.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mlmmj.nyi.freebsd.org (Postfix) with ESMTP id 4QxRMb3GGFz4lqSF; Thu, 6 Jul 2023 06:24:43 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from mxrelay.nyi.freebsd.org (mxrelay.nyi.freebsd.org [IPv6:2610:1c1:1:606c::19:3]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "mxrelay.nyi.freebsd.org", Issuer "R3" (verified OK)) by mx1.freebsd.org (Postfix) with ESMTPS id 4QxRMb2FYfz4D9y; Thu, 6 Jul 2023 06:24:43 +0000 (UTC) (envelope-from git@FreeBSD.org) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1688624683; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=zbCf4bcKrpBZe6HskC2/ZVRPJ9VOZJCtOMipyGdvtTA=; b=pMC5NKAR9Yw7bzSgDdu1l5FEeyggHpcmL6YxRfMrTHqGp97G9r7RrkHde8Wh/uWie/SezX 5dHFhiJG0adaP/gyl5RkjGn0Wvn9W/A6iSUy30ZEKr4AKGwR02baXxRzstpRjoQuklRzV7 +1a6bUs6KWi96icuhqZkrnK7PRzK+I5aisDL2cnA13Wo4OcJhVr/481llFBGBsIdH5GKHo BY+sYnRS8z8q6y7DCjO85tqpuKU6twgbGDKc18AfgDnGNE6mq6gzXc+8JXnE5HA9U69t95 UpXy3IrVFrfuJgAi0cSUaODv0gxciS/9Ay1vYie+szaSK/h7jdCmhyYtSUFu1Q== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1688624683; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=zbCf4bcKrpBZe6HskC2/ZVRPJ9VOZJCtOMipyGdvtTA=; b=A8HPnUuk45do+a2m0wspWhG7PElVmEcB+EA/JYdPEvGvsdniuvOLrH2ZtFTPvqW2Ijob3I KEWYT1ojxYHhi3kJc2D2mtq/jt/03AjM25qYgNmUh2iaOG0ikVvPGo3hIozC1KXmLs6tA8 haz+pu+OpW7S1+qebQR/yiLcNuY+B9ZlWqh6uo58tYh10omKd3Aq2qHqkI33K+izVijf6I HhP9QlBEZNmGIvL+fQXc+6j3SdL3xsRLXWhQIpTth7oSUiJlDrCPZigvi3OkXDVXCooWZx Hp7Ilcuh+SeMTImargUdfLV/Xv521MyuYb6aYTLnXLLR9+poJ4SrVhoOcZIRVA== ARC-Authentication-Results: i=1; mx1.freebsd.org; none ARC-Seal: i=1; s=dkim; d=freebsd.org; t=1688624683; a=rsa-sha256; cv=none; b=VNc0TSKXkwT47ITPagdUqRUg7MYeVpi2V+xJ3DmSka2cvE1s4T7EJu2xIs48EePVwF8vLl Y8ga7IDpHJhpCq/2EPM3OaMHzoNzyD7arrXw8sHWYWTjHqI+508A5M9KAgGp9LBjsJWqxx h4VIAC48g3ZPmEzMvAXf2NBwTcgVDj44FZqzpmW45mTEri5Uq88wOurigX6WYwoXZvPiZh IWmOulD9dgWzvcu/BGDZ41/rR9ozvbI72cvob3zISAd8xXbgVjgeAfqoqGb8RpwcSJGslH mSw8io8sCq+ZkfNq9i952E1txlDnjg7p7mFQzxHZ9Yy2y1Zl7ZLNv5NKaZH+hQ== Received: from gitrepo.freebsd.org (gitrepo.freebsd.org [IPv6:2610:1c1:1:6068::e6a:5]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (Client did not present a certificate) by mxrelay.nyi.freebsd.org (Postfix) with ESMTPS id 4QxRMb1KCfzlqJ; Thu, 6 Jul 2023 06:24:43 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from gitrepo.freebsd.org ([127.0.1.44]) by gitrepo.freebsd.org (8.17.1/8.17.1) with ESMTP id 3666OhJH089868; Thu, 6 Jul 2023 06:24:43 GMT (envelope-from git@gitrepo.freebsd.org) Received: (from git@localhost) by gitrepo.freebsd.org (8.17.1/8.17.1/Submit) id 3666OhM9089867; Thu, 6 Jul 2023 06:24:43 GMT (envelope-from git) Date: Thu, 6 Jul 2023 06:24:43 GMT Message-Id: <202307060624.3666OhM9089867@gitrepo.freebsd.org> To: ports-committers@FreeBSD.org, dev-commits-ports-all@FreeBSD.org, dev-commits-ports-branches@FreeBSD.org From: =?utf-8?Q?Fernando=20Apestegu=C3=ADa?= Subject: git: b72fcf2103b7 - 2023Q3 - www/gitea: Update to 1.19.4 (fixes security vulnerabilities) List-Id: Commits to the quarterly branches of the FreeBSD ports repository List-Archive: https://lists.freebsd.org/archives/dev-commits-ports-branches List-Help: List-Post: List-Subscribe: List-Unsubscribe: Sender: owner-dev-commits-ports-branches@freebsd.org X-BeenThere: dev-commits-ports-branches@freebsd.org MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: 8bit X-Git-Committer: fernape X-Git-Repository: ports X-Git-Refname: refs/heads/2023Q3 X-Git-Reftype: branch X-Git-Commit: b72fcf2103b73946265f42d1a03d0df5ff056686 Auto-Submitted: auto-generated X-ThisMailContainsUnwantedMimeParts: N The branch 2023Q3 has been updated by fernape: URL: https://cgit.FreeBSD.org/ports/commit/?id=b72fcf2103b73946265f42d1a03d0df5ff056686 commit b72fcf2103b73946265f42d1a03d0df5ff056686 Author: Stefan Bethke AuthorDate: 2023-07-05 11:36:51 +0000 Commit: Fernando ApesteguĂ­a CommitDate: 2023-07-06 06:24:34 +0000 www/gitea: Update to 1.19.4 (fixes security vulnerabilities) ChangeLog: https://github.com/go-gitea/gitea/releases/tag/v1.19.4 SECURITY * Fix open redirect check for more cases API * Return 404 in the API if the requested webhooks were not found * Fix organization field being null in GET /api/v1/teams/{id} ENHANCEMENTS * Set --font-weight-bold to 600 * Make mailer SMTP check have timed context * Do not select line numbers when selecting text from the action run logs BUGFIXES * Fix bug when change user name * Fix task list checkbox toggle to work with YAML front matter * Hide limited users if viewed by anonymous ghost * Add WithPullRequest for actionsNotifier * Fix parallelly generating index failure with Mysql * GitLab migration: Sanitize response for reaction list * Fix users cannot visit issue attachment bug * Fix missing reference prefix of commits when sync mirror repository * Only validate changed columns when update user * Make DeleteIssue use correct context * Fix topics deleted via API not being deleted in org page * Fix Actions being enabled accidentally * Fix missed table name on iterate lfs meta objects * Fix safari cookie session bug * Respect original content when creating secrets * Fix Pull Mirror out-of-sync bugs * Fix run list broken when trigger user deleted * Fix issues list page multiple selection update milestones * Fix: release page for empty or non-existing target * Fix close org projects * Refresh the refernce of the closed PR when reopening * Fix the permission of team's Actions unit issue * Bump go.etcd.io/bbolt and blevesearch deps * Fix new wiki page mirror * Match unqualified references when syncing pulls as well DOCS * Change branch name from master to main in some documents' links * Remove unnecessary content on docs * Unify doc links to use paths relative to doc folder * Fix docs documenting invalid @every for OLDER_THAN cron settings MISC * Merge different languages for language stats * Hiding Secrets options when Actions feature is disabled * Improve decryption failure message * Makefile: Use portable !, not GNUish -not, with find(1). PR: 272380 Reported by: stb@lassitu.de MFH: 2023Q3 (security fix) (cherry picked from commit 0609a03e4b94368b5410503906f05eaec542e2c7) --- www/gitea/Makefile | 2 +- www/gitea/distinfo | 6 +++--- 2 files changed, 4 insertions(+), 4 deletions(-) diff --git a/www/gitea/Makefile b/www/gitea/Makefile index 782053b4a3e0..7b07a52bde93 100644 --- a/www/gitea/Makefile +++ b/www/gitea/Makefile @@ -1,6 +1,6 @@ PORTNAME= gitea DISTVERSIONPREFIX= v -DISTVERSION= 1.19.3 +DISTVERSION= 1.19.4 CATEGORIES= www MASTER_SITES= https://github.com/go-gitea/gitea/releases/download/${DISTVERSIONPREFIX}${DISTVERSION}/ \ https://dl.gitea.io/gitea/${DISTVERSION}/ diff --git a/www/gitea/distinfo b/www/gitea/distinfo index d6d143aa1049..ec1c92eb90df 100644 --- a/www/gitea/distinfo +++ b/www/gitea/distinfo @@ -1,3 +1,3 @@ -TIMESTAMP = 1685483917 -SHA256 (gitea-src-1.19.3.tar.gz) = ad2bc17929c9df9e986daeed6578344b5d59473626177c673a5e19509f17418c -SIZE (gitea-src-1.19.3.tar.gz) = 55634848 +TIMESTAMP = 1688548753 +SHA256 (gitea-src-1.19.4.tar.gz) = bcd30d10a32952854b506c0f3d584b29f1251668c25a06476398b596236cfb19 +SIZE (gitea-src-1.19.4.tar.gz) = 55781048