Date: Wed, 7 Aug 2013 08:06:52 -0700 From: Jason Helfman <jgh@FreeBSD.org> To: Alexey Dokuchaev <danfe@freebsd.org> Cc: "svn-ports-head@freebsd.org" <svn-ports-head@freebsd.org>, "svn-ports-all@freebsd.org" <svn-ports-all@freebsd.org>, "Timur I. Bakeyev" <timur@freebsd.org>, "ports-committers@freebsd.org" <ports-committers@freebsd.org> Subject: Re: svn commit: r324296 - head/net/samba36 Message-ID: <CAMuy=%2Bh9XXqR8zeDeQr6Zfci2DOWNtK_z8Q=hVzaEnL4X492vA@mail.gmail.com> In-Reply-To: <20130807134234.GB14969@FreeBSD.org> References: <201308060032.r760W83G023317@svn.freebsd.org> <CAMuy=%2Bhsw=bH2YcQVY4HvE7YdbVb%2B873_oYhCNoJzSMNaYJrxA@mail.gmail.com> <CALdFvJE5p72Asytxuomq24fbGJj_sDAVYwKESOxXE8kqhpjPog@mail.gmail.com> <20130807132239.GB10293@FreeBSD.org> <CALdFvJE57uCOmu4uDDSgRG=r0CY0kss3A=Sx6dWrbim8WKb6Ww@mail.gmail.com> <20130807134234.GB14969@FreeBSD.org>
next in thread | previous in thread | raw e-mail | index | archive | help
On Wed, Aug 7, 2013 at 6:42 AM, Alexey Dokuchaev <danfe@freebsd.org> wrote: > On Wed, Aug 07, 2013 at 03:38:04PM +0200, Timur I. Bakeyev wrote: > > Well, it's said that CVE code should be inserted there and by such a code > > it's possible to fetch description and vulnerable versions in theory... > But > > true, never thought of it thoroughly.. > > VuXML entries have too much stuff that has to be input manually, from exact > versions vulnerable (NVidia drivers give me real PITA in this regard) up to > writing summary excerpts, which in general case cannot be easily factored > out from upstream CVE entry. > > ./danfe > > I was really surprised to read this thread based on my original inquiry. Vuxml is well-documented in the Porters Handbook, and there are plenty of existing entries to learn from how to create an entry of your own. Beyond this, there is a large group of committers that would be willing to review your first attempt at making an entry and helping you to get it to a point where it is committable. When I was a mentee, I constantly took on new challenges that I was never exposed to as a contributor with the flood of incoming problem reports that were coming in. Once I took on a vulnerability, because I knew that I would need to write a vuxml entry and learn it. I suggest trying to write an entry. I would be more than willing to review it, as well. -jgh -- Jason Helfman | FreeBSD Committer jgh@FreeBSD.org | http://people.freebsd.org/~jgh | The Power to Serve
Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?CAMuy=%2Bh9XXqR8zeDeQr6Zfci2DOWNtK_z8Q=hVzaEnL4X492vA>