Re: Status of Python 3.11

Gert Doering <[email protected]>
Newsgroups gmane.os.freebsd.devel.ports
Message-ID <[email protected]>
Hi,

On Tue, Aug 11, 2026 at 08:47:12PM +0200, Piotr Smyrak wrote:
> > > IIUC, you are building your own packages. I would like to propose a
> > > simpler approach that does not require any development whatsoever.
> > > You could either patch the local ports tree or just revert the
> > > commits that added these vulnerabilities to the XML file, and
> > > build the VuXML DB from such patched port, publish the XML artifact
> > > to be accessible from within Freshports network, and modify this
> > > setting in pkg.conf:
> > >
> > > #VULNXML_SITE = "http://vuxml.freebsd.org/freebsd/vuln.xml.xz"; 
[..]
> You could setup a git hook that detects changes to the XML files in
> security/vuxml/vuln and triggers a rebuild of your own DB. 

This is not really the way to address CVE alert fatigue for people
that do not want to hack around the alerting system by building their
own stuff left and right.

Most of my machines do not build anything locally, or even have a ports
or source tree checked out (using binpkg and freebsd-update saves quite
a significant bit of CPU = power = co2 costs...).  So having something
that tells daily-security "ignore these two vulns, please" would be
much more useful for me.

gert
-- 
"If was one thing all people took for granted, was conviction that if you 
 feed honest figures into a computer, honest figures come out. Never doubted 
 it myself till I met a computer with a sense of humor."
                             Robert A. Heinlein, The Moon is a Harsh Mistress

Gert Doering - Munich, Germany                             [email protected]
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.