Re: Scanning the entire Ports tree for Rust vulns
Thierry Thomas <[email protected]>
| Newsgroups | gmane.os.freebsd.devel.hackers |
|---|---|
| Organization | Kabbale Eros |
| Message-ID | <agA5_5pMm9V96clG@alien> |
Le sam. 9 mai 26 à 23:25:30 +0200, Alan Somers <[email protected]> écrivait : > TLDR; It's possible to preemptively scan the whole ports tree for Rust > crates with known vulnerabilities, without building anything Very interesting! You should put your script under /usr/ports/Tools/scripts and send a note about it to ports-secteam. If it could be launched for only one port at a time, portmgr might run it from Mk/Scripts/qa.sh for the concerned ports. Best regards. -- Th. Thomas.
signature.asc
(application/pgp-signature, 833 B)
-----BEGIN PGP SIGNATURE----- iQIzBAEBCAAdFiEE5Ta+hThTmdALb6p28cUWs8g1l1MFAmoAOfMACgkQ8cUWs8g1 l1N8whAAt9Vv/W+JPNwzjwxIE1dV56xgEOeO1Cmplp/xmCwLMbnr0EsczvDPR8e/ yMAAdb4gDT3qguxYhp1IAYp0782yITjB2n73pSj9I1ghLSzUyv+yAOpmfkp51lsl 3RhF14+GH4rmLFB9JIpZsWDVKqJKDcJSOkkdnNZ9iWjoWEtPjiABhny76OHpoKGK GHKl7h+X6wEmo4o6sJ7WHyCuEW5tXm1ryYxHnoRXnL1SfYPp/LFHi825+1YVWAor CJ15SOM1tuEpHZobWO4i4JA1HnKTh/I6STi0528GqRfDha2jhH+wg8XhDCQB5XHQ QZ+zqA176srtwJVAmAH6VGcOECSx7yo0sGVFNRDSX6YJfPlurLPTT6hh/T7RpAsJ Y6oXmLhHByvrjBpFVVLKB92O+SH7lywew5agUnQtpvbU9On1NKEESc7jPpVk2SA8 IB7oL145rutPBp1IpWIXC6u36Xpx7O8ESMhKHwbM9lAICEGBuEzn03vQv0YKB/FS hngZRqIzFX+acrakllOHSC4VctsbOjG8SlHh9uX/WSOaRWhHXd+65kq5h9On54dC GfFjwI4tOu9QWvpn7ZJwdYtT2at5W+4yYeIeD2u2e19BbVdE+eDtW739oBY6ot0G h0rqI10/Aw9SEkEApLMspDV/Iv4ruyZTioj+8qDSTzjvM+6jt4A= =m4KE -----END PGP SIGNATURE-----