Skip site navigation (1)Skip section navigation (2)
Date:      Tue, 24 Apr 2001 12:07:56 -0700
From:      bmah@FreeBSD.ORG (Bruce A. Mah)
To:        Kris Kennaway <kris@obsecurity.org>
Cc:        Sean Chittenden <sean@chittenden.org>, Calvin NG <calvinng@brel.com>, Sean Chittenden <sean-freebsd-stable@chittenden.org>, Jeff Kletsky <Jeff+freebsd@wagsky.com>, freebsd-stable@FreeBSD.ORG, bmah@FreeBSD.ORG
Subject:   Re: pkg_version perl hacker project 
Message-ID:  <200104241907.f3OJ7u103414@bmah-freebsd-0.cisco.com>
In-Reply-To: <20010424120052.H89156@xor.obsecurity.org> 
References:  <Pine.BSF.4.21.0104230806060.27435-100000@wildside.wagsky.com> <20010423231827.A19530@rand.tgd.net> <20010424142340.E5216@brel.com> <20010424014833.B19530@rand.tgd.net> <20010424120052.H89156@xor.obsecurity.org>

next in thread | previous in thread | raw e-mail | index | archive | help
--==_Exmh_-753634348P
Content-Type: text/plain; charset=us-ascii

If memory serves me right, Kris Kennaway wrote:

Couple o' random thoughts, don't have time to look into this myself...

> This could be done as an extension to pkg_version, since much of the
> code you will need to manage versions is already there, and it's a
> logical extension of that program's function.

Or you can use pkg_version's -t flag to help with the comparisons if 
you think running as a separate script is better.

> NetBSD have a port called audit-packages which does something similar,
> but not quite the same as the above (last I checked) -- it might still
> be useful as a starting point.

Think about where to put the parsed set of vulnerable packages.  It 
might live under /usr/ports or reside somewhere on the network.  Use 
fetch(1) to grab it from there, like pkg_version does for the INDEX 
file.

Bruce.

PS.  Jeff Kletsky, sorry I haven't looked at your dependency graphing 
tool...I'm mildly thrashing right now.  Sounds pretty neat though!



--==_Exmh_-753634348P
Content-Type: application/pgp-signature

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.0.4 (FreeBSD)
Comment: Exmh version 2.2 06/23/2000

iD8DBQE65c8M2MoxcVugUsMRAkbnAJ9JTeUOiZNkhcUtagiouDJNMatd3QCg8ZQT
oVZy3+zh045FL+GEZDsUL54=
=o/j+
-----END PGP SIGNATURE-----

--==_Exmh_-753634348P--

To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-stable" in the body of the message




Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?200104241907.f3OJ7u103414>