Re: Status of Python 3.11
Gert Doering <[email protected]>
| Newsgroups | gmane.os.freebsd.devel.ports |
|---|---|
| Message-ID | <[email protected]> |
Hi,
On Tue, Aug 11, 2026 at 08:47:12PM +0200, Piotr Smyrak wrote:
> > > IIUC, you are building your own packages. I would like to propose a
> > > simpler approach that does not require any development whatsoever.
> > > You could either patch the local ports tree or just revert the
> > > commits that added these vulnerabilities to the XML file, and
> > > build the VuXML DB from such patched port, publish the XML artifact
> > > to be accessible from within Freshports network, and modify this
> > > setting in pkg.conf:
> > >
> > > #VULNXML_SITE = "http://vuxml.freebsd.org/freebsd/vuln.xml.xz";
[..]
> You could setup a git hook that detects changes to the XML files in
> security/vuxml/vuln and triggers a rebuild of your own DB.
This is not really the way to address CVE alert fatigue for people
that do not want to hack around the alerting system by building their
own stuff left and right.
Most of my machines do not build anything locally, or even have a ports
or source tree checked out (using binpkg and freebsd-update saves quite
a significant bit of CPU = power = co2 costs...). So having something
that tells daily-security "ignore these two vulns, please" would be
much more useful for me.
gert
--
"If was one thing all people took for granted, was conviction that if you
feed honest figures into a computer, honest figures come out. Never doubted
it myself till I met a computer with a sense of humor."
Robert A. Heinlein, The Moon is a Harsh Mistress
Gert Doering - Munich, Germany [email protected]