On 4/14/2017 04:04, Andrea wrote:
Hi, I'm looking at DPorts and I see that most of the ports are at least
a couple of months old. As an example firefox-51.0.1 and
thunderbird-45.6.0 have multiple vulnerabilities fixed in more recent
versions.

Are you confusing dports and packages?
Firefox is at 52.0 in dports right now which came in late march, and in 2 days it will be at 53.0 once the stage branch is merged with master.

Packages /= ports.
If one can't wait for packages (which are a best effort convenience) then one always has the option to build from dports using synth.

John


How can we help with it? Is it a matter of submitting patches to upgrade
single ports (as an example firefox and thunderbird) or should we wait
that the bulk of DPorts is synchronized with FreeBSD ports and then sort
out single problems (if any?).

It also seems to me, looking at the git commits, that a new port system
is on the way so maybe we should wait for it (and if needed help with it
once released)? If this is the case, how do you handle this transition
period? Vulnerabilities in browsers scares me the most.

Kind regards,
Andrea

Reply via email to