Date: Sun, 28 Sep 2008 16:14:24 +0400 From: Eygene Ryabinkin <rea-fbsd@codelabs.ru> To: Miroslav Lachman <000.fbsd@quip.cz> Cc: freebsd-hackers@freebsd.org, Roman Kurakin <rik@inse.ru>, bug-followup@freebsd.org, freebsd-ports@freebsd.org Subject: Re: ports/126853: ports-mgmt/portaudit: speed up audit of installed packages Message-ID: <4bESZpNwE3z/DdlE2fwK/BXzQSo@2MQ0uKCiT7mdMUuLeUzs8Nv3ToQ> In-Reply-To: <48DF6735.4030906@quip.cz> References: <WGReTVL6CLts/44OKi4qLEsAGHs@jm/Q2DKg1djxmpGNf45V%2BWpjPIE> <48DE5CC0.9000708@localhost.inse.ru> <o/JeKQBFxyWYOEj%2BysAVRhQK6g8@iXA9ZWPrtc2I2BMzBXoToMd7YdQ> <48DF6735.4030906@quip.cz>
next in thread | previous in thread | raw e-mail | index | archive | help
--24zk1gE8NUlDmwG9
Content-Type: text/plain; charset=koi8-r
Content-Disposition: inline
Content-Transfer-Encoding: quoted-printable
Miroslav, good day.
Sun, Sep 28, 2008 at 01:15:01PM +0200, Miroslav Lachman wrote:
> Is there any possibility to cooperate portaudit / pkg_audit with=20
> pkg_version to show vulnerable package with information if newer (not=20
> vulnerable) package (or port) version is available for upgrade to?
>=20
> If I read nightly security e-mail with for example 4 vulnerable=20
> packages, then I need to log in to server and manualy try, if newer=20
> (fixed) packages are available. It seems not so hard to check output of=
=20
> `pkg_version -vIL =3D` and compare both versions (installed and available=
)=20
> with portaudit in some shellscript, I didn't start to write it yet ;).
I think it won't be very hard: I'll try to see how to extend portaudit
with such functionality -- it would be very handy, in my opinion.
Hadn't you have a chance to test my patch?
Thanks!
--=20
Eygene
_ ___ _.--. #
\`.|\..----...-'` `-._.-'_.-'` # Remember that it is hard
/ ' ` , __.--' # to read the on-line manual =20
)/' _/ \ `-_, / # while single-stepping the kernel.
`-'" `"\_ ,_.-;_.-\_ ', fsc/as #
_.-'_./ {_.' ; / # -- FreeBSD Developers handbook=20
{_.-``-' {_/ #
--24zk1gE8NUlDmwG9
Content-Type: application/pgp-signature
Content-Disposition: inline
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2.0.9 (FreeBSD)
iEYEARECAAYFAkjfdR8ACgkQthUKNsbL7Yh9pwCgn6ZCc+sKUfLOeGOAhKmAGZdr
ZbkAn2OVuz4Q/VpOhRyWBuIb2kMMp30K
=VoRh
-----END PGP SIGNATURE-----
--24zk1gE8NUlDmwG9--
Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?4bESZpNwE3z/DdlE2fwK/BXzQSo>
