From nobody Wed Mar 9 10:09:03 2022 X-Original-To: dev-commits-ports-main@mlmmj.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mlmmj.nyi.freebsd.org (Postfix) with ESMTP id 009161A08E05; Wed, 9 Mar 2022 10:09:06 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from mxrelay.nyi.freebsd.org (mxrelay.nyi.freebsd.org [IPv6:2610:1c1:1:606c::19:3]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "mxrelay.nyi.freebsd.org", Issuer "R3" (verified OK)) by mx1.freebsd.org (Postfix) with ESMTPS id 4KD7Fr1lN3z4qYP; Wed, 9 Mar 2022 10:09:03 +0000 (UTC) (envelope-from git@FreeBSD.org) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1646820544; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=DKAY3b2y9HNWdpAcqXXMBmSh5oeCAZo3ab4Q165BgBA=; b=LovT3GR2nNoc2o1AbQgtggpNg3IbWoJun+mN9tA+RJSI6KfiJjC+9O3pISEjJmHuFEsgq+ WrW1pCbZMH9Sh/vh7p3IMRN2wnbnqX01Nu/tKuSiV2nDYXNIRYmUe1sPKMCeyYBTIEtyf/ H7IxJT0mfouQAK0Zo5Tgtv2QPzZDhQ3n0qcyk0YPdPVruD/bFrxbpQjTEt946DW+gzas2G AaPOdG29sQjbAqZnii4q29yLCt+0SLiq/4hQzUAdBijdtyfYbGx0CAcs746OnLgU/fy/XC jZLsIA0yOehyztFqOoojg1Xm9uI9UqROin9q0mFgvaiuf+C2KJgUcycqt8RsHA== Received: from gitrepo.freebsd.org (gitrepo.freebsd.org [IPv6:2610:1c1:1:6068::e6a:5]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (Client did not present a certificate) by mxrelay.nyi.freebsd.org (Postfix) with ESMTPS id A65736E93; Wed, 9 Mar 2022 10:09:03 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from gitrepo.freebsd.org ([127.0.1.44]) by gitrepo.freebsd.org (8.16.1/8.16.1) with ESMTP id 229A93MR090670; Wed, 9 Mar 2022 10:09:03 GMT (envelope-from git@gitrepo.freebsd.org) Received: (from git@localhost) by gitrepo.freebsd.org (8.16.1/8.16.1/Submit) id 229A938L090669; Wed, 9 Mar 2022 10:09:03 GMT (envelope-from git) Date: Wed, 9 Mar 2022 10:09:03 GMT Message-Id: <202203091009.229A938L090669@gitrepo.freebsd.org> To: ports-committers@FreeBSD.org, dev-commits-ports-all@FreeBSD.org, dev-commits-ports-main@FreeBSD.org From: Matthias Fechner Subject: git: 86f62d30a8b5 - main - www/gitlab-ce: Security update to 14.8.2 List-Id: Commits to the main branch of the FreeBSD ports repository List-Archive: https://lists.freebsd.org/archives/dev-commits-ports-main List-Help: List-Post: List-Subscribe: List-Unsubscribe: Sender: owner-dev-commits-ports-main@freebsd.org X-BeenThere: dev-commits-ports-main@freebsd.org MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: 8bit X-Git-Committer: mfechner X-Git-Repository: ports X-Git-Refname: refs/heads/main X-Git-Reftype: branch X-Git-Commit: 86f62d30a8b515d314db36c82e6bab75a2311159 Auto-Submitted: auto-generated ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1646820544; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=DKAY3b2y9HNWdpAcqXXMBmSh5oeCAZo3ab4Q165BgBA=; b=E7LDkU9o5YyWHL/PxRpj9Pyne6f/CjHyLACpUegFuilPAYI8/aZXQed1BGPPh7WsCEBnjO zPe/9U+x3chuOEBP8pza8tw9smZOFyhGsIBtJot2N/Id303NTmzLq7zynBJ7BXr1DGerjZ 31MEa9M+kj+HQXDAMe7mWkiXn/2PZtK8mvWBsfL0kqPp+X655KBuJxhRl8okG9pLQTMwsM 6XgznE2ZLkOfE07+5/vJVAn59vXnw30s86Sne5BmNxQd/ZInwO4TzkDmxPixxVLOvuCEb4 nmQm2oy+wTLLMRx+6QU+WojLv84Dhd4G6CaV6jI33XsgfSNK/m1YZzbW3/DzQQ== ARC-Seal: i=1; s=dkim; d=freebsd.org; t=1646820544; a=rsa-sha256; cv=none; b=ReBsQ3VK795SvsWjLplzziTzahzqeGVX5MkmMMQDcDcRicuL5nXmEBqgV3k1JfvaBR+VtW a3OtdnS/NLvbcIs6VVLOMG288NZN8jaDF4Rllgy+PExs5w3dVaR5du0Kwyx0oeKdEtoNSQ Kj37eT7RXWbUblP7rtUZA5FWPG2PX3VTDAdcqPaBYkYwGHWQ3stomzB5VJeY1d1iZfPHPM R2qJ6bL4SzPs/7kAOT0PBBKEitbvL4nMz98qYc3vouVGzlAFh5zyJyMVrD1zitO/V81bgi mwpkKCt2MuXMxrNwZDAlSXbklaO+IOSrfVwXpQV8nx551FUU6uuRCISA3/SAyQ== ARC-Authentication-Results: i=1; mx1.freebsd.org; none X-ThisMailContainsUnwantedMimeParts: N The branch main has been updated by mfechner: URL: https://cgit.FreeBSD.org/ports/commit/?id=86f62d30a8b515d314db36c82e6bab75a2311159 commit 86f62d30a8b515d314db36c82e6bab75a2311159 Author: Matthias Fechner AuthorDate: 2022-03-09 09:18:16 +0000 Commit: Matthias Fechner CommitDate: 2022-03-09 10:07:56 +0000 www/gitlab-ce: Security update to 14.8.2 Changelog: https://about.gitlab.com/releases/2022/02/23/gitlab-14-8-1-released/ https://about.gitlab.com/releases/2022/02/25/critical-security-release-gitlab-14-8-2-released/ https://gitlab.com/gitlab-org/gitlab-foss/-/blob/master/CHANGELOG.md 14.8.2 (2022-02-25) Security (8 changes) Limit commands_changes to certain keys (merge request) Add runners_token prefix to Group and Project (merge request) Anonymous user can enumerate all users through GraphQL endpoint (merge request) Check for unsafe characters in email addresses before sending (merge request) Warn when snippet contains unretrievable files (merge request) Prevent DOS when rendering math markdown (merge request) Check permission when creating members through service (merge request) Reset password field on page load (merge request) 14.8.1 (2022-02-23) Fixed (3 changes) Allow assigning users with private profiles with quick-actions (merge request) Stop backup files from requiring directories to exist when skipped (merge request) Fix toolbar buttons in Markdown field (merge request) Security: 2823048d-9f8f-11ec-8c9c-001b217b3468 --- www/gitlab-ce/Makefile | 4 ++-- www/gitlab-ce/distinfo | 6 +++--- www/gitlab-workhorse/Makefile | 4 ++-- www/gitlab-workhorse/distinfo | 6 +++--- 4 files changed, 10 insertions(+), 10 deletions(-) diff --git a/www/gitlab-ce/Makefile b/www/gitlab-ce/Makefile index e2d8efc275d8..c4700a883383 100644 --- a/www/gitlab-ce/Makefile +++ b/www/gitlab-ce/Makefile @@ -1,7 +1,7 @@ # Created by: Torsten Zuehlsdorff PORTNAME= gitlab-ce -PORTVERSION= 14.8.0 +PORTVERSION= 14.8.2 PORTREVISION= 0 CATEGORIES= www devel @@ -275,7 +275,7 @@ USE_GITLAB= yes GL_ACCOUNT= gitlab-org GL_PROJECT= gitlab-foss # Find the here: https://gitlab.com/gitlab-org/gitlab-foss/-/tags -GL_COMMIT= 3f274363e9dc9a1be75edfcd3dd5adb64b1e8c29 +GL_COMMIT= c7be43f6dd37211709111be3796af9e1f00d3713 USERS= git GROUPS= git diff --git a/www/gitlab-ce/distinfo b/www/gitlab-ce/distinfo index cfcf381fbb50..f37126b2ac6a 100644 --- a/www/gitlab-ce/distinfo +++ b/www/gitlab-ce/distinfo @@ -1,3 +1,3 @@ -TIMESTAMP = 1645606465 -SHA256 (gitlab-org-gitlab-foss-3f274363e9dc9a1be75edfcd3dd5adb64b1e8c29_GL0.tar.gz) = 8ac2d2bb30f954cc3caa8b29e648d3136bf29a2aa066fc1ce417b9065d5c5b5a -SIZE (gitlab-org-gitlab-foss-3f274363e9dc9a1be75edfcd3dd5adb64b1e8c29_GL0.tar.gz) = 102523804 +TIMESTAMP = 1646815687 +SHA256 (gitlab-org-gitlab-foss-c7be43f6dd37211709111be3796af9e1f00d3713_GL0.tar.gz) = e0e016834ca975918d229d77151cae644cdd2f7f64d5902b3c80b90cfe63a299 +SIZE (gitlab-org-gitlab-foss-c7be43f6dd37211709111be3796af9e1f00d3713_GL0.tar.gz) = 102527800 diff --git a/www/gitlab-workhorse/Makefile b/www/gitlab-workhorse/Makefile index 684820ce08e4..6051c3b783f3 100644 --- a/www/gitlab-workhorse/Makefile +++ b/www/gitlab-workhorse/Makefile @@ -1,7 +1,7 @@ # Created by: Torsten Zuehlsdorff PORTNAME= gitlab-workhorse -PORTVERSION= 14.8.0 +PORTVERSION= 14.8.2 PORTREVISION= 0 CATEGORIES= www @@ -25,7 +25,7 @@ USE_GITLAB= yes GL_ACCOUNT= gitlab-org GL_PROJECT= gitlab-foss # Find the commit hash here: https://gitlab.com/gitlab-org/gitlab-foss/-/tags -GL_COMMIT= 3f274363e9dc9a1be75edfcd3dd5adb64b1e8c29 +GL_COMMIT= c7be43f6dd37211709111be3796af9e1f00d3713 # for go dependencies USE_GITHUB= nodefault diff --git a/www/gitlab-workhorse/distinfo b/www/gitlab-workhorse/distinfo index e7f2d43e3539..42c51f45e116 100644 --- a/www/gitlab-workhorse/distinfo +++ b/www/gitlab-workhorse/distinfo @@ -1,4 +1,4 @@ -TIMESTAMP = 1646778762 +TIMESTAMP = 1646815663 SHA256 (Azure-azure-pipeline-go-v0.2.3_GH0.tar.gz) = 99bd58f4a07dd02d9615e3638b3bb6dbfad80ef678ccdb8e17e3fa2b0fef343e SIZE (Azure-azure-pipeline-go-v0.2.3_GH0.tar.gz) = 17102 SHA256 (Azure-azure-storage-blob-go-v0.13.0_GH0.tar.gz) = 6bf7145210331efa3f0417f6684cf764c22743cf23122048ec136600daebf443 @@ -199,8 +199,8 @@ SHA256 (uber-jaeger-client-go-v2.27.0_GH0.tar.gz) = 7590acdefcbbf9553bd3415bc7e5 SIZE (uber-jaeger-client-go-v2.27.0_GH0.tar.gz) = 210139 SHA256 (uber-jaeger-lib-v2.4.1_GH0.tar.gz) = c178bcad325857dba29551c16f40707701adf6e3a9e01e1ca3e5edfc3c6de8bc SIZE (uber-jaeger-lib-v2.4.1_GH0.tar.gz) = 38010 -SHA256 (gitlab-org-gitlab-foss-3f274363e9dc9a1be75edfcd3dd5adb64b1e8c29_GL0.tar.gz) = 8ac2d2bb30f954cc3caa8b29e648d3136bf29a2aa066fc1ce417b9065d5c5b5a -SIZE (gitlab-org-gitlab-foss-3f274363e9dc9a1be75edfcd3dd5adb64b1e8c29_GL0.tar.gz) = 102523804 +SHA256 (gitlab-org-gitlab-foss-c7be43f6dd37211709111be3796af9e1f00d3713_GL0.tar.gz) = e0e016834ca975918d229d77151cae644cdd2f7f64d5902b3c80b90cfe63a299 +SIZE (gitlab-org-gitlab-foss-c7be43f6dd37211709111be3796af9e1f00d3713_GL0.tar.gz) = 102527800 SHA256 (gitlab-org-gitaly-df7dadcc3f74276a7176234d4b1475299f46c05c_GL0.tar.gz) = 4c403ee52c1d42d54e9acd14026796782e8272e74c8eb7c3cedf9c924697647e SIZE (gitlab-org-gitaly-df7dadcc3f74276a7176234d4b1475299f46c05c_GL0.tar.gz) = 3703056 SHA256 (gitlab-org-golang-archive-zip-84007c99e03b62ee4dc62a94048d6e59552299d7_GL0.tar.gz) = 103a3e806657de5e2c7844326146c88490089fa8d07784270c359b5f5a8d06be