From owner-freebsd-questions@freebsd.org Thu Sep 15 10:04:53 2016 Return-Path: Delivered-To: freebsd-questions@mailman.ysv.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:1900:2254:206a::19:1]) by mailman.ysv.freebsd.org (Postfix) with ESMTP id 967B9BDAC54 for ; Thu, 15 Sep 2016 10:04:53 +0000 (UTC) (envelope-from roland@micite.net) Received: from mail.micite.net (lawrencium.micite.net [149.210.214.224]) by mx1.freebsd.org (Postfix) with ESMTP id 5F20D18E2 for ; Thu, 15 Sep 2016 10:04:52 +0000 (UTC) (envelope-from roland@micite.net) Received: from [192.168.178.26] (62-251-11-72.ip.xs4all.nl [62.251.11.72]) by mail.micite.net (Postfix) with ESMTPSA id 6D262201A for ; Thu, 15 Sep 2016 11:58:58 +0200 (CEST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=micite.net; s=20150418; t=1473933538; bh=4LK6NgPSAa4/xSRbyvOoS9feeeZ7ZmidOGJSIt8RX9Y=; h=To:From:Subject:Date; b=JZxZpmLuDieNl7nWuX4Q3liRI/2ZcKPjsr+chSVSeVWU0B7cBgU6A8p2OrMW0etom 3eqUfH2nWXWuQQNM6o9nVF1k8Q0cKNLNfDX6P0tzomVXvdFFuX+3bOWG1W/KzV8P6B qM9UXJ2DoIp/9zz/jVd2hqD+oRPAXJjMqKdYABYM= To: freebsd-questions@freebsd.org From: Roland van Laar Subject: pkg audit and port upgrades Message-ID: <7c6f67b1-422d-bdd7-18aa-7aac6da13e90@micite.net> Date: Thu, 15 Sep 2016 11:58:58 +0200 User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:45.0) Gecko/20100101 Thunderbird/45.2.0 MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8; format=flowed Content-Transfer-Encoding: 7bit X-BeenThere: freebsd-questions@freebsd.org X-Mailman-Version: 2.1.23 Precedence: list List-Id: User questions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Thu, 15 Sep 2016 10:04:53 -0000 Hello Community, My question: How do I know if a vulnerable port has had an update? I get daily emails from pkg audit telling me about vulnerabilities in my ports. Today it was curl, but the latest curl hasn't yet had an update. I update the ports tree and rebuild my ports. Only to notice during the build that it stops the build because the port is still vulnerable. => Please update your ports tree and try again. => Note: Vulnerable ports are marked as such even if there is no update available. => If you wish to ignore this vulnerability rebuild with 'make DISABLE_VULNERABILITIES=yes' *** Error code 1 Is there a way to know before I build my ports to know if there is a vulnerability? Regards, Roland van Laar