Skip site navigation (1)Skip section navigation (2)
Date:      Fri, 2 Oct 2015 21:42:10 -1000
From:      parv@pair.com
To:        f-q <freebsd-questions@freebsd.org>
Subject:   Working of "pkg audit <package name>"
Message-ID:  <20151003074210.GA50460@holstein.holy.cow>

next in thread | raw e-mail | index | archive | help
I want to know if running "pkg audit" makes any sense for a port
installed that has not been updated officially yet. Also, is it
possible to supplement the vuxml catalog for such ports installed?

Firefox 39 or 40 had been installed from ports. I got tired of
seeing package being vulnerable on every ports tree update process
that rebuilds "security/vuxml". As the "www/firefox" port has not
been updated yet, so I fetched source of firefox 41.0.1; updated
distinfo; installed (after rebuilding databases/sqlite3 with DBSTAT
option & moving out "files/patch-bug702179" out of "files").

Now I see vulnerability warnings going back to 2004, which are
just useless & rather amusing. At least the installed firefox is not
vulnerable any more (yet).


  - parv

-- 




Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?20151003074210.GA50460>