From nobody Wed Jun 19 06:37:29 2024 X-Original-To: dev-commits-ports-all@mlmmj.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mlmmj.nyi.freebsd.org (Postfix) with ESMTP id 4W3v7F4vljz5P3df; Wed, 19 Jun 2024 06:37:29 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from mxrelay.nyi.freebsd.org (mxrelay.nyi.freebsd.org [IPv6:2610:1c1:1:606c::19:3]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "mxrelay.nyi.freebsd.org", Issuer "R3" (verified OK)) by mx1.freebsd.org (Postfix) with ESMTPS id 4W3v7F4Q3pz3xfj; Wed, 19 Jun 2024 06:37:29 +0000 (UTC) (envelope-from git@FreeBSD.org) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1718779049; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=CYktac0B7gNhpCewRP+x46vA9vGSSsu70EyrWCjUuWc=; b=vt/dVkjr1GSrxHC9WKwoZfAbRfhGuOTTE4KhiJuLMpbd1FBTLfImTHFCcqk3HFd07nm1li 3J0I54PDy/7Uhtu96H+g8yYEP7YKCIAsCZymUpN8wvyS4Zty7y/NqJfDgSbjnntjIOunZN kVh++OuMT0B+5ZLmnTCZtknpGJOTcbeyEtZbxTnwNa+XWslyL+WMBo96PGx8/9u1W4d5Yo qJKDiGoOUlyvl5MaNvVbnrDM2Ds+NRfm8OehIHGDhAkqAdDKUwNb/zl86w7/nYV/IB60uy TFo0/O40sC1e6heXT8TP70BjS9K35wk30kuwsHdCoUkQfJ5iayGa0zk5cpH4dw== ARC-Seal: i=1; s=dkim; d=freebsd.org; t=1718779049; a=rsa-sha256; cv=none; b=IT6LVPlCTJC8It8E3utSPEaBVn9rBlCQW3RnxOjK40hU/gPiUdrzG4x3cRNkxs7W3+M0Fi DK35wFoTJbwQ+DQGSIk+S1ERNin3XwmSYWVbj6g5+mHZifHvpVMvXBIllDLWv/zL5dhzcr dfHmvoiYUqZBuaq1E/ua+8V6Y+XdN6ulwwSwqNJMYaEtjmeUiNi02ie73WlF86vHwZtWEy MvvZeJVdyRZrlQCTGx6qIn+Fmi3xCnicQbiDrFaj7MqV6anOhxpxo2CVIalUuXaNFArKhp zt093b6snJYqqK0+WInCWgPb42Z8l0TZpjJI5Gnp+82NiOVVPBoZm9DCjNvUSg== ARC-Authentication-Results: i=1; mx1.freebsd.org; none ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1718779049; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=CYktac0B7gNhpCewRP+x46vA9vGSSsu70EyrWCjUuWc=; b=dG6l+wijzEYUolaiYj9rF6YLA57oD88PAE4+1yHVQBliLy4Xbb+elfv1eFv6qtqTvmUja2 QXO9TBoqgEuMH9hRFfhOie45cVmb9svGpk2DlbU/K33fMgORZYgO7GelZXMUdXaz4Qvj3p ORmBGLgovB8ES/DSAmbV59LZZEse0WyZmljp8oECRxofF8eqkV/kVa8dhvusdIwRPBW558 k2bxkYtY+Nyp3yk45nLuF81Wrptdn7Y0NfPlqkzLC7cgR0NZwUQ36umyTgIs4fozbmMkLT Am/brdk5l4v9tQaKwHYJwBrSXGSydj9st2Pe491/eSMo0ZkWfhz5yHKEyFsijA== Received: from gitrepo.freebsd.org (gitrepo.freebsd.org [IPv6:2610:1c1:1:6068::e6a:5]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (Client did not present a certificate) by mxrelay.nyi.freebsd.org (Postfix) with ESMTPS id 4W3v7F3zB8zWvK; Wed, 19 Jun 2024 06:37:29 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from gitrepo.freebsd.org ([127.0.1.44]) by gitrepo.freebsd.org (8.17.1/8.17.1) with ESMTP id 45J6bT6m076956; Wed, 19 Jun 2024 06:37:29 GMT (envelope-from git@gitrepo.freebsd.org) Received: (from git@localhost) by gitrepo.freebsd.org (8.17.1/8.17.1/Submit) id 45J6bTCQ076953; Wed, 19 Jun 2024 06:37:29 GMT (envelope-from git) Date: Wed, 19 Jun 2024 06:37:29 GMT Message-Id: <202406190637.45J6bTCQ076953@gitrepo.freebsd.org> To: ports-committers@FreeBSD.org, dev-commits-ports-all@FreeBSD.org, dev-commits-ports-main@FreeBSD.org From: Fernando =?utf-8?Q?Apestegu=C3=ADa?= Subject: git: be43fb2830c9 - main - www/forgejo: update to 7.0.4 (fixes security vulnerabilities) List-Id: Commit messages for all branches of the ports repository List-Archive: https://lists.freebsd.org/archives/dev-commits-ports-all List-Help: List-Post: List-Subscribe: List-Unsubscribe: X-BeenThere: dev-commits-ports-all@freebsd.org Sender: owner-dev-commits-ports-all@FreeBSD.org MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: 8bit X-Git-Committer: fernape X-Git-Repository: ports X-Git-Refname: refs/heads/main X-Git-Reftype: branch X-Git-Commit: be43fb2830c94e23e0d9aa49ef9b982b0ab31e2c Auto-Submitted: auto-generated The branch main has been updated by fernape: URL: https://cgit.FreeBSD.org/ports/commit/?id=be43fb2830c94e23e0d9aa49ef9b982b0ab31e2c commit be43fb2830c94e23e0d9aa49ef9b982b0ab31e2c Author: Stefan Bethke AuthorDate: 2024-06-17 17:16:10 +0000 Commit: Fernando ApesteguĂ­a CommitDate: 2024-06-19 06:37:17 +0000 www/forgejo: update to 7.0.4 (fixes security vulnerabilities) CVE-2024-24789: the archive/zip package's handling of certain types of invalid zip files differs from the behavior of most zip implementations. This misalignment could be exploited to create an zip file with contents that vary depending on the implementation reading the file. PR: 279781 Reported by: stb@lassitu.de (maintainer) MFH: 2024Q2 Security: CVE-2024-24789 --- www/forgejo/Makefile | 3 +-- www/forgejo/distinfo | 6 +++--- 2 files changed, 4 insertions(+), 5 deletions(-) diff --git a/www/forgejo/Makefile b/www/forgejo/Makefile index fb6728294317..1f2696736529 100644 --- a/www/forgejo/Makefile +++ b/www/forgejo/Makefile @@ -1,7 +1,6 @@ PORTNAME= forgejo DISTVERSIONPREFIX= v -DISTVERSION= 7.0.3 -PORTREVISION= 1 +DISTVERSION= 7.0.4 CATEGORIES= www MASTER_SITES= https://codeberg.org/forgejo/forgejo/releases/download/${DISTVERSIONPREFIX}${DISTVERSION}/ DISTNAME= forgejo-src-${DISTVERSION} diff --git a/www/forgejo/distinfo b/www/forgejo/distinfo index 18205d8b2c4b..e60439031aae 100644 --- a/www/forgejo/distinfo +++ b/www/forgejo/distinfo @@ -1,3 +1,3 @@ -TIMESTAMP = 1716464783 -SHA256 (forgejo-src-7.0.3.tar.gz) = c9e85222eb27508e74a284cb125df7c6d7cfc31f52c62f1e305d2aeb1bdb7abc -SIZE (forgejo-src-7.0.3.tar.gz) = 54895104 +TIMESTAMP = 1718527772 +SHA256 (forgejo-src-7.0.4.tar.gz) = 881e55d92a4145238a8e7a39dd5c64d547c7629361005ded0393f33ec9e6bba4 +SIZE (forgejo-src-7.0.4.tar.gz) = 54935871