Re: SECURITY UPDATE: devel/jenkins-2.150.1/2.155 (fixes multiple CVEs)

2018-12-17 Thread Stuart Henderson
On 2018/12/17 18:58, Edward Lopez-Acosta wrote: > Not sure why the title got changed so I fixed it. > > Thank you for the explanation on when to use, and how to update, quirks. I > will keep this in mind for future submissions if applicable. > > What is the logic in not updating this for -stable

Re: SECURITY UPDATE: devel/jenkins-2.150.1/2.155 (fixes multiple CVEs)

2018-12-17 Thread Theo de Raadt
Edward Lopez-Acosta wrote: > What is the logic in not updating this for -stable too? There are no magic fairies building -stable packages on a constant basis. > Because they constantly update for security issues and this is not convenient? Yes. Also it isn't just a matter of building using

Re: SECURITY UPDATE: devel/jenkins-2.150.1/2.155 (fixes multiple CVEs)

2018-12-17 Thread Edward Lopez-Acosta
libgit2/libgit2' => 'libgit2-<0.27.7', 'devel/mercurial,-main' => 'mercurial-<4.5.3p1', 'devel/mercurial,-x11' => 'mercurial-x11-<4.5.3p1', Thx Ian - Forwarded message from Edward Lopez-Acosta - Date: Mon, 17 Dec 2018 21:25:05 +0000 From: Edward Lopez

Re: [elopezaco...@gmail.com: Re: SECURITY UPDATE: devel/jenkins-2.150.1/2.155 (fixes multiple CVEs)]

2018-12-17 Thread Stuart Henderson
x > Ian > - Forwarded message from Edward Lopez-Acosta > - > > Date: Mon, 17 Dec 2018 21:25:05 +0000 > From: Edward Lopez-Acosta > To: i...@openbsd.org > Subject: Re: SECURITY UPDATE: devel/jenkins-2.150.1/2.155 (fixes multiple > CVEs) > > Hi Ian, >

SECURITY UPDATE: devel/jenkins-2.150.1/2.155 (fixes multiple CVEs)

2018-12-14 Thread Edward Lopez-Acosta
Version update for multiple security issues including one marked as critical. I was not sure how to update quirks so that is not included in this diff. If someone is willing to teach me what to do I can add that in, or review changes to quirks after this is merged. Builds, installs, and