From owner-svn-ports-all@FreeBSD.ORG Thu Apr 24 16:20:33 2014 Return-Path: Delivered-To: svn-ports-all@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:1900:2254:206a::19:1]) (using TLSv1 with cipher ADH-AES256-SHA (256/256 bits)) (No client certificate requested) by hub.freebsd.org (Postfix) with ESMTPS id 50CFEAC8; Thu, 24 Apr 2014 16:20:33 +0000 (UTC) Received: from svn.freebsd.org (svn.freebsd.org [IPv6:2001:1900:2254:2068::e6a:0]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (Client did not present a certificate) by mx1.freebsd.org (Postfix) with ESMTPS id 318561E5E; Thu, 24 Apr 2014 16:20:33 +0000 (UTC) Received: from svn.freebsd.org ([127.0.1.70]) by svn.freebsd.org (8.14.8/8.14.8) with ESMTP id s3OGKX6r016335; Thu, 24 Apr 2014 16:20:33 GMT (envelope-from lwhsu@svn.freebsd.org) Received: (from lwhsu@localhost) by svn.freebsd.org (8.14.8/8.14.8/Submit) id s3OGKVux016139; Thu, 24 Apr 2014 16:20:31 GMT (envelope-from lwhsu@svn.freebsd.org) Message-Id: <201404241620.s3OGKVux016139@svn.freebsd.org> From: Li-Wen Hsu Date: Thu, 24 Apr 2014 16:20:31 +0000 (UTC) To: ports-committers@freebsd.org, svn-ports-all@freebsd.org, svn-ports-branches@freebsd.org Subject: svn commit: r352014 - in branches/2014Q2: security/vuxml www/py-django www/py-django-devel www/py-django14 www/py-django15 X-SVN-Group: ports-branches MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit X-BeenThere: svn-ports-all@freebsd.org X-Mailman-Version: 2.1.17 Precedence: list List-Id: SVN commit messages for the ports tree List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Thu, 24 Apr 2014 16:20:33 -0000 Author: lwhsu Date: Thu Apr 24 16:20:30 2014 New Revision: 352014 URL: http://svnweb.freebsd.org/changeset/ports/352014 QAT: https://qat.redports.org/buildarchive/r352014/ Log: MFH: r351931 Document Django 2014-04-21 vulnerabilty MFH: r351932 - Update to 1.6.3 Security: 59e72db2-cae6-11e3-8420-00e0814cab4e MFH: r351933 - Update to 1.5.6 Security: 59e72db2-cae6-11e3-8420-00e0814cab4e MFH: r351934 - Update to 1.4.11 Security: 59e72db2-cae6-11e3-8420-00e0814cab4e MFH: r351935 - Update to 20140423 snapshot Security: 59e72db2-cae6-11e3-8420-00e0814cab4e MFH: r351938 Fix Django package names Submitted by: mat MFH: r351944 - Add missing distinfo [1] - Trim unneeded PYDISTUTILS_PKGNAME Notified by: swills [1] MFH: r352013 Add back pakcage ranges for people have ancient packages Notified by: mat Approved by: portmgr (mat) Deleted: branches/2014Q2/www/py-django-devel/pkg-plist branches/2014Q2/www/py-django14/pkg-plist branches/2014Q2/www/py-django15/pkg-plist Modified: branches/2014Q2/security/vuxml/vuln.xml branches/2014Q2/www/py-django-devel/Makefile branches/2014Q2/www/py-django-devel/distinfo branches/2014Q2/www/py-django/Makefile branches/2014Q2/www/py-django/distinfo branches/2014Q2/www/py-django14/Makefile branches/2014Q2/www/py-django14/distinfo branches/2014Q2/www/py-django15/Makefile branches/2014Q2/www/py-django15/distinfo Directory Properties: branches/2014Q2/ (props changed) Modified: branches/2014Q2/security/vuxml/vuln.xml ============================================================================== --- branches/2014Q2/security/vuxml/vuln.xml Thu Apr 24 15:54:50 2014 (r352013) +++ branches/2014Q2/security/vuxml/vuln.xml Thu Apr 24 16:20:30 2014 (r352014) @@ -51,6 +51,86 @@ Note: Please add new entries to the beg --> + + django -- multiple vulnerabilities + + + py26-django + py27-django + py31-django + py32-django + py33-django + py34-django + 1.61.6.3 + 1.51.5.6 + 1.41.4.11 + + + py26-django15 + py27-django15 + py31-django15 + py32-django15 + py33-django15 + py34-django15 + 1.51.5.6 + + + py26-django14 + py27-django14 + py31-django14 + py32-django14 + py33-django14 + py34-django14 + 1.41.4.11 + + + py26-django15 + py27-django15 + py31-django15 + py32-django15 + py33-django15 + py34-django15 + 1.51.5.6 + + + py26-django14 + py27-django14 + py31-django14 + py32-django14 + py33-django14 + py34-django14 + 1.41.4.11 + + + py26-django-devel + py27-django-devel + 20140423,1 + + + + +

The Django project reports:

+
+

These releases address an unexpected code-execution issue, a + caching issue which can expose CSRF tokens and a MySQL typecasting + issue. While these issues present limited risk and may not affect + all Django users, we encourage all users to evaluate their own + risk and upgrade as soon as possible.

+
+ +
+ + https://www.djangoproject.com/weblog/2014/apr/21/security/ + CVE-2014-0472 + CVE-2014-0473 + CVE-2014-0474 + + + 2014-04-21 + 2014-04-23 + 2014-04-24 + +
OpenSSL -- Multiple vulnerabilities - private data exposure Modified: branches/2014Q2/www/py-django-devel/Makefile ============================================================================== --- branches/2014Q2/www/py-django-devel/Makefile Thu Apr 24 15:54:50 2014 (r352013) +++ branches/2014Q2/www/py-django-devel/Makefile Thu Apr 24 16:20:30 2014 (r352014) @@ -14,16 +14,14 @@ DIST_SUBDIR= python MAINTAINER= lwhsu@FreeBSD.org COMMENT= High-level Python Web framework -LICENSE= BSD +LICENSE= BSD3CLAUSE -SNAPSHOTDATE= 20131025 +SNAPSHOTDATE= 20140423 -USE_XZ= yes -USES= gettext +USES= gettext tar:xz USE_PYTHON= yes USE_PYDISTUTILS= yes -PYTHON_PY3K_PLIST_HACK= yes -PYDISTUTILS_PKGNAME= Django +PYDISTUTILS_AUTOPLIST= yes PYDISTUTILS_PKGVERSION= 1.7 CONFLICTS= py2[0-9]-django-[0-9]* @@ -38,6 +36,9 @@ OPTIONS_GROUP= DATABASE OPTIONS_GROUP_DATABASE= PGSQL MYSQL SQLITE HTMLDOCS_DESC= Install the HTML documentation (requires Sphinx) +PLIST_FILES= man/man1/django-admin.1.gz \ + man/man1/gather_profile_stats.1.gz + .include .if ${PORT_OPTIONS:MPGSQL} @@ -57,7 +58,7 @@ RUN_DEPENDS+= ${PYTHON_PKGNAMEPREFIX}flu .endif .if ${PORT_OPTIONS:MHTMLDOCS} -. if empty(PORT_OPTIONS:MDOCS) +. if ! ${PORT_OPTIONS:MDOCS} IGNORE= you cannot build documentation while setting NOPORTDOCS . endif BUILD_DEPENDS+= ${PYTHON_PKGNAMEPREFIX}sphinx>0:${PORTSDIR}/textproc/py-sphinx Modified: branches/2014Q2/www/py-django-devel/distinfo ============================================================================== --- branches/2014Q2/www/py-django-devel/distinfo Thu Apr 24 15:54:50 2014 (r352013) +++ branches/2014Q2/www/py-django-devel/distinfo Thu Apr 24 16:20:30 2014 (r352014) @@ -1,2 +1,2 @@ -SHA256 (python/Django-20131025.tar.xz) = 56393be35977e9f106f085bb4a0025da5c4a4de3908eb40b22aef45c29c74cbe -SIZE (python/Django-20131025.tar.xz) = 4618532 +SHA256 (python/Django-20140423.tar.xz) = d40b8d98cac40d40844c552953aa7a6d1faba10b21aebffd765684d54f85cc29 +SIZE (python/Django-20140423.tar.xz) = 4540492 Modified: branches/2014Q2/www/py-django/Makefile ============================================================================== --- branches/2014Q2/www/py-django/Makefile Thu Apr 24 15:54:50 2014 (r352013) +++ branches/2014Q2/www/py-django/Makefile Thu Apr 24 16:20:30 2014 (r352014) @@ -2,7 +2,7 @@ # $FreeBSD$ PORTNAME= django -PORTVERSION= 1.6.2 +PORTVERSION= 1.6.3 CATEGORIES= www python MASTER_SITES= https://www.djangoproject.com/m/releases/${PORTVERSION}/ \ CHEESESHOP @@ -18,7 +18,6 @@ LICENSE= BSD3CLAUSE USE_PYTHON= yes USE_PYDISTUTILS= yes PYDISTUTILS_AUTOPLIST= yes -PYDISTUTILS_PKGNAME= Django CONFLICTS= py[23][0-9]-django-devel-[0-9]* py[23][0-9]-django-1.[0-57-9].* Modified: branches/2014Q2/www/py-django/distinfo ============================================================================== --- branches/2014Q2/www/py-django/distinfo Thu Apr 24 15:54:50 2014 (r352013) +++ branches/2014Q2/www/py-django/distinfo Thu Apr 24 16:20:30 2014 (r352014) @@ -1,2 +1,2 @@ -SHA256 (python/Django-1.6.2.tar.gz) = d1b3f8460e936f47846e7c4f80af951eda82a41c253c3a51ff3389863ff1c03a -SIZE (python/Django-1.6.2.tar.gz) = 6615116 +SHA256 (python/Django-1.6.3.tar.gz) = 6d9d3c468f9a09470d00e85fe492ba35edfc72cee7fb65ad0281010eba58b8f1 +SIZE (python/Django-1.6.3.tar.gz) = 6628812 Modified: branches/2014Q2/www/py-django14/Makefile ============================================================================== --- branches/2014Q2/www/py-django14/Makefile Thu Apr 24 15:54:50 2014 (r352013) +++ branches/2014Q2/www/py-django14/Makefile Thu Apr 24 16:20:30 2014 (r352014) @@ -2,7 +2,7 @@ # $FreeBSD$ PORTNAME= django -PORTVERSION= 1.4.10 +PORTVERSION= 1.4.11 CATEGORIES= www python MASTER_SITES= https://www.djangoproject.com/m/releases/${PORTVERSION:R}/ \ CHEESESHOP @@ -14,11 +14,11 @@ DIST_SUBDIR= python MAINTAINER= lwhsu@FreeBSD.org COMMENT= High-level Python Web framework -LICENSE= BSD +LICENSE= BSD3CLAUSE USE_PYTHON= 2 USE_PYDISTUTILS= yes -PYDISTUTILS_PKGNAME= Django +PYDISTUTILS_AUTOPLIST= yes CONFLICTS= py[23][0-9]-django-devel-[0-9]* py[23][0-9]-django-1.[0-35-9].* @@ -32,6 +32,10 @@ OPTIONS_GROUP= DATABASE OPTIONS_GROUP_DATABASE= PGSQL MYSQL SQLITE HTMLDOCS_DESC= Install the HTML documentation (requires Sphinx) +PLIST_FILES= man/man1/daily_cleanup.1.gz \ + man/man1/django-admin.1.gz \ + man/man1/gather_profile_stats.1.gz + .include .if ${PORT_OPTIONS:MPGSQL} Modified: branches/2014Q2/www/py-django14/distinfo ============================================================================== --- branches/2014Q2/www/py-django14/distinfo Thu Apr 24 15:54:50 2014 (r352013) +++ branches/2014Q2/www/py-django14/distinfo Thu Apr 24 16:20:30 2014 (r352014) @@ -1,2 +1,2 @@ -SHA256 (python/Django-1.4.10.tar.gz) = 3d1f083c039fdab1400c32b5406a60891c9dd16f880999c4a53d054742ac29de -SIZE (python/Django-1.4.10.tar.gz) = 7745002 +SHA256 (python/Django-1.4.11.tar.gz) = 4819d8b37405b33f4f0d156f60918094d566249f52137c5e6e0dbaa12995c201 +SIZE (python/Django-1.4.11.tar.gz) = 7752172 Modified: branches/2014Q2/www/py-django15/Makefile ============================================================================== --- branches/2014Q2/www/py-django15/Makefile Thu Apr 24 15:54:50 2014 (r352013) +++ branches/2014Q2/www/py-django15/Makefile Thu Apr 24 16:20:30 2014 (r352014) @@ -2,8 +2,7 @@ # $FreeBSD$ PORTNAME= django -PORTVERSION= 1.5.5 -PORTREVISION= 2 +PORTVERSION= 1.5.6 CATEGORIES= www python MASTER_SITES= https://www.djangoproject.com/m/releases/${PORTVERSION:R}/ \ CHEESESHOP @@ -15,12 +14,11 @@ DIST_SUBDIR= python MAINTAINER= lwhsu@FreeBSD.org COMMENT= High-level Python Web framework -LICENSE= BSD +LICENSE= BSD3CLAUSE USE_PYTHON= yes USE_PYDISTUTILS= yes -PYTHON_PY3K_PLIST_HACK= yes -PYDISTUTILS_PKGNAME= Django +PYDISTUTILS_AUTOPLIST= yes CONFLICTS= py[23][0-9]-django-devel-[0-9]* py[23][0-9]-django-1.[0-46-9].* @@ -34,6 +32,10 @@ OPTIONS_GROUP= DATABASE OPTIONS_GROUP_DATABASE= PGSQL MYSQL SQLITE HTMLDOCS_DESC= Install the HTML documentation (requires Sphinx) +PLIST_FILES= man/man1/daily_cleanup.1.gz \ + man/man1/django-admin.1.gz \ + man/man1/gather_profile_stats.1.gz + .include .if ${PORT_OPTIONS:MPGSQL} Modified: branches/2014Q2/www/py-django15/distinfo ============================================================================== --- branches/2014Q2/www/py-django15/distinfo Thu Apr 24 15:54:50 2014 (r352013) +++ branches/2014Q2/www/py-django15/distinfo Thu Apr 24 16:20:30 2014 (r352014) @@ -1,2 +1,2 @@ -SHA256 (python/Django-1.5.5.tar.gz) = 6ae69c1dfbfc9d0c44ae80e2fbe48e59bbbbb70e8df66ad2b7029bd39947d71d -SIZE (python/Django-1.5.5.tar.gz) = 8060441 +SHA256 (python/Django-1.5.6.tar.gz) = 9b7fcb99d20289189ec0f1e06d1d2bed3b4772e3a393fddbfb006ea7c3f9bfaf +SIZE (python/Django-1.5.6.tar.gz) = 8068359