Re: Security Patches for Port Applications in Releases

2007-01-17 Thread Oliver Fromme
Stevan Tiefert wrote: I installed the new release 6.2 on my workstation. I installed also portaudit and run it immediatly afterwards. What have I to see? 5 vulnerable packages in my release. What was your installation source? I noticed that there are a lot of stale packages on

Re: Security Patches for Port Applications in Releases

2007-01-17 Thread Jason C. Wells
Stevan Tiefert wrote: Hello list, I installed the new release 6.2 on my workstation. I installed also portaudit and run it immediatly afterwards. What have I to see? 5 vulnerable packages in my release. The whole OSS community is a moving target. Security is not a static thing. For

Re: Security Patches for Port Applications in Releases

2007-01-17 Thread Jeremy C. Reed
Just to let you know, the http://www.pkgsrc.org/ collection mostly works fine on FreeBSD. It provides a quarterly stable branch that only has updates for security fixes and other essential updates. This has been maintained for a few years now. The quarterly stable branch is not scheduled on

Security Patches for Port Applications in Releases

2007-01-15 Thread Stevan Tiefert
Hello list, I installed the new release 6.2 on my workstation. I installed also portaudit and run it immediatly afterwards. What have I to see? 5 vulnerable packages in my release. My questions: - Why can I update FreeBSD with security-patches and the Release-Packages have no