From nobody Wed Jun 19 06:43:27 2024 X-Original-To: dev-commits-ports-all@mlmmj.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mlmmj.nyi.freebsd.org (Postfix) with ESMTP id 4W3vG73wdRz5P3pY; Wed, 19 Jun 2024 06:43:27 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from mxrelay.nyi.freebsd.org (mxrelay.nyi.freebsd.org [IPv6:2610:1c1:1:606c::19:3]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "mxrelay.nyi.freebsd.org", Issuer "R3" (verified OK)) by mx1.freebsd.org (Postfix) with ESMTPS id 4W3vG731PLz3ymZ; Wed, 19 Jun 2024 06:43:27 +0000 (UTC) (envelope-from git@FreeBSD.org) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1718779407; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=sIXcWjBhDv9cdqY7cJlP+AJoVdhHIPYue3LcAoW7Vxw=; b=s3Bb2UMH3ELuVKJmLSyk5ENSAvGtY84sSB/AZRkqR7dqn40xVVsaqq45NO9Zpf/xSir3/A Vc/p/e3bLSIXDg5KC0z/kCqZcaKnChgx5LNF/wGfaiaXs+YSjQIYn2h1EQQ4i1/vtOMM+1 L0MP8qcXmiABpHkQeQnL6OyCX668u6e2nOSWsU+q9ugoAqUB3PBQ3B9ZHuDqTqR5FN7yr9 0stofkj6hlAhv/VXB12sbM7snmQJ7swV0TU1/eRcUQDC6xW8pmdyOkWv+pmbmTXTy+1jiV izyL3IWgTlUWtM0mDnOymquRjjxTEaxoBZ4E0/YzxZ2PnxAKQJA+bngHsVEa5A== ARC-Seal: i=1; s=dkim; d=freebsd.org; t=1718779407; a=rsa-sha256; cv=none; b=HShzYfa8QscU6l0EKDZDUtWlBhI8V/amj/1BjJ1P44W3weDTUGcO0xUcAIjZHPPj1lvsHS X5nuqJT7cyAaeAT2X8n6E3541Co3iAtkjinMTFa0ivNGUT+NVLj0fuNqT0IwqKaG3j/tyy Jckra6hPQOHryXhxSWBr3abG0CzoUFaU6bMt2cTi3CHuT8Sg3604QYqg1dJvvFSF5KRJ57 i+mLDt3TfxrRPWSVYlj6uXHuOvXXE9jDH06rLqCynuLJ41Iz7SPlyFsGnM1Bju0QX4euDS gwIMblrUotbLsvph+pZFzqNBTxmttlwOiwA8+Ts/rXgKygNwGRnqfqr0/rG9aA== ARC-Authentication-Results: i=1; mx1.freebsd.org; none ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1718779407; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=sIXcWjBhDv9cdqY7cJlP+AJoVdhHIPYue3LcAoW7Vxw=; b=LZF2nY56ZWnH9owRaz3Y5BkVc270g+d5X4ZBDSWya+ngTHff7meAUJXPACePEfyJHMecIG cgVJbl9bbxNi8+TFL+Aw0eN794CXP7YbrlzpSug1STd2NYUBhagqKVspR5Qa7A03WCZg4h fenrV+kDzpiyAwtBFeGTcVsWPBACIPP9qF1d69RaEv+Rv1g3k8B6g+4CqTMD9b4Bd7XViX TZyAjJUB71YAdySsmxQHh8WwRU5c0FWPEHEGBoJSy13/PmJDzsqeQ1+pJszLR6qZrtKHa0 4rFaWyVIzj+6I2j+mH1m31qD6PLfHNxKz8Gz4L1JeR/qkAYknHdXtNKDA+fOOw== Received: from gitrepo.freebsd.org (gitrepo.freebsd.org [IPv6:2610:1c1:1:6068::e6a:5]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (Client did not present a certificate) by mxrelay.nyi.freebsd.org (Postfix) with ESMTPS id 4W3vG72ZSdzXXD; Wed, 19 Jun 2024 06:43:27 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from gitrepo.freebsd.org ([127.0.1.44]) by gitrepo.freebsd.org (8.17.1/8.17.1) with ESMTP id 45J6hRPB092815; Wed, 19 Jun 2024 06:43:27 GMT (envelope-from git@gitrepo.freebsd.org) Received: (from git@localhost) by gitrepo.freebsd.org (8.17.1/8.17.1/Submit) id 45J6hRiJ092812; Wed, 19 Jun 2024 06:43:27 GMT (envelope-from git) Date: Wed, 19 Jun 2024 06:43:27 GMT Message-Id: <202406190643.45J6hRiJ092812@gitrepo.freebsd.org> To: ports-committers@FreeBSD.org, dev-commits-ports-all@FreeBSD.org, dev-commits-ports-branches@FreeBSD.org From: Fernando =?utf-8?Q?Apestegu=C3=ADa?= Subject: git: d18807bcfba5 - 2024Q2 - www/forgejo: update to 7.0.4 (fixes security vulnerabilities) List-Id: Commit messages for all branches of the ports repository List-Archive: https://lists.freebsd.org/archives/dev-commits-ports-all List-Help: List-Post: List-Subscribe: List-Unsubscribe: X-BeenThere: dev-commits-ports-all@freebsd.org Sender: owner-dev-commits-ports-all@FreeBSD.org MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: 8bit X-Git-Committer: fernape X-Git-Repository: ports X-Git-Refname: refs/heads/2024Q2 X-Git-Reftype: branch X-Git-Commit: d18807bcfba5dd79b8d8fdce2c6baf9f962fa69f Auto-Submitted: auto-generated The branch 2024Q2 has been updated by fernape: URL: https://cgit.FreeBSD.org/ports/commit/?id=d18807bcfba5dd79b8d8fdce2c6baf9f962fa69f commit d18807bcfba5dd79b8d8fdce2c6baf9f962fa69f Author: Stefan Bethke AuthorDate: 2024-06-17 17:16:10 +0000 Commit: Fernando ApesteguĂ­a CommitDate: 2024-06-19 06:42:50 +0000 www/forgejo: update to 7.0.4 (fixes security vulnerabilities) CVE-2024-24789: the archive/zip package's handling of certain types of invalid zip files differs from the behavior of most zip implementations. This misalignment could be exploited to create an zip file with contents that vary depending on the implementation reading the file. PR: 279781 Reported by: stb@lassitu.de (maintainer) MFH: 2024Q2 Security: CVE-2024-24789 (cherry picked from commit be43fb2830c94e23e0d9aa49ef9b982b0ab31e2c) --- www/forgejo/Makefile | 3 +-- www/forgejo/distinfo | 6 +++--- 2 files changed, 4 insertions(+), 5 deletions(-) diff --git a/www/forgejo/Makefile b/www/forgejo/Makefile index 5ce85017635c..67963a09227c 100644 --- a/www/forgejo/Makefile +++ b/www/forgejo/Makefile @@ -1,7 +1,6 @@ PORTNAME= forgejo DISTVERSIONPREFIX= v -DISTVERSION= 1.21.10-0 -PORTREVISION= 3 +DISTVERSION= 7.0.4 CATEGORIES= www MASTER_SITES= https://codeberg.org/forgejo/forgejo/releases/download/${DISTVERSIONPREFIX}${DISTVERSION}/ DISTNAME= forgejo-src-${DISTVERSION} diff --git a/www/forgejo/distinfo b/www/forgejo/distinfo index 35e0c2d393a7..e60439031aae 100644 --- a/www/forgejo/distinfo +++ b/www/forgejo/distinfo @@ -1,3 +1,3 @@ -TIMESTAMP = 1712360403 -SHA256 (forgejo-src-1.21.10-0.tar.gz) = 0cc21835404e40355cf7125b479efebb1fecf2cc17d018d4d54521d75943caf5 -SIZE (forgejo-src-1.21.10-0.tar.gz) = 58820868 +TIMESTAMP = 1718527772 +SHA256 (forgejo-src-7.0.4.tar.gz) = 881e55d92a4145238a8e7a39dd5c64d547c7629361005ded0393f33ec9e6bba4 +SIZE (forgejo-src-7.0.4.tar.gz) = 54935871