Re: Status of Python 3.11

Piotr Smyrak <[email protected]>
Newsgroups gmane.os.freebsd.devel.ports
Message-ID <[email protected]>
Hello,

On Tue, 11 Aug 2026 20:58:31 +0200
Gert Doering <[email protected]> wrote:

> On Tue, Aug 11, 2026 at 08:47:12PM +0200, Piotr Smyrak wrote:
> > > > IIUC, you are building your own packages. I would like to
> > > > propose a simpler approach that does not require any
> > > > development whatsoever. You could either patch the local ports
> > > > tree or just revert the commits that added these
> > > > vulnerabilities to the XML file, and build the VuXML DB from
> > > > such patched port, publish the XML artifact to be accessible
> > > > from within Freshports network, and modify this setting in
> > > > pkg.conf:
> > > >
> > > > #VULNXML_SITE = "http://vuxml.freebsd.org/freebsd/vuln.xml.xz";
> > > >   
> [..]
> > You could setup a git hook that detects changes to the XML files in
> > security/vuxml/vuln and triggers a rebuild of your own DB.   
> 
> This is not really the way to address CVE alert fatigue for people
> that do not want to hack around the alerting system by building their
> own stuff left and right.

Of course. And I agree with you. Still this is a voluntary free software
project. So despite patches being welcome, they may not come ready
tomorrow. 

And by this proposal I am merely trying to help Dan lift some burden of
his back. Hopefully until the patches are in place.

> Most of my machines do not build anything locally, or even have a
> ports or source tree checked out (using binpkg and freebsd-update
> saves quite a significant bit of CPU = power = co2 costs...).  So
> having something that tells daily-security "ignore these two vulns,
> please" would be much more useful for me.

In test reporting there is a concept of an expected fail, or
acknowledged one, and certain monitoring systems allow for flipping
such forever failing test item into green by marking it as such. Which
may as well in future turn red when it stops failing and thus then
needs to be turned around again. 

What I am trying to say above is that the approach may also depend on
what monitoring tool one uses.

-- 
 Piotr Smyrak
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.