FreeBSD ports you maintain which are out of date

2021-04-06 Thread portscout
Dear port maintainer,

The portscout new distfile checker has detected that one or more of your
ports appears to be out of date. Please take the opportunity to check
each of the ports listed below, and if possible and appropriate,
submit/commit an update. If any ports have already been updated, you can
safely ignore the entry.

You will not be e-mailed again for any of the port/version combinations
below.

Full details can be found at the following URL:
http://portscout.freebsd.org/r...@freebsd.org.html


Port| Current version | New version
+-+
devel/ruby-build| 20210309| v20210405
+-+
lang/ruby25 | 2.5.8   | 2.5.9
+-+
lang/ruby27 | 2.7.2   | 2.7.3
+-+
security/rubygem-ruby-saml  | 1.9.0   | 1.12.1
+-+


If any of the above results are invalid, please check the following page
for details on how to improve portscout's detection and selection of
distfiles on a per-port basis:

http://portscout.freebsd.org/info/portscout-portconfig.txt

Reported by:portscout!
___
freebsd-ruby@freebsd.org mailing list
https://lists.freebsd.org/mailman/listinfo/freebsd-ruby
To unsubscribe, send any mail to "freebsd-ruby-unsubscr...@freebsd.org"


[Bug 254802] lang/ruby27: Update to 2.7.3

2021-04-06 Thread bugzilla-noreply
https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=254802

Koichiro Iwao  changed:

   What|Removed |Added

 CC||m...@freebsd.org
 Status|New |In Progress
   Assignee|r...@freebsd.org|m...@freebsd.org

-- 
You are receiving this mail because:
You are the assignee for the bug.
___
freebsd-ruby@freebsd.org mailing list
https://lists.freebsd.org/mailman/listinfo/freebsd-ruby
To unsubscribe, send any mail to "freebsd-ruby-unsubscr...@freebsd.org"


[Bug 254800] lang/ruby26: Update to 2.6.7

2021-04-06 Thread bugzilla-noreply
https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=254800

Koichiro Iwao  changed:

   What|Removed |Added

   Assignee|r...@freebsd.org|m...@freebsd.org
 Status|New |In Progress
 CC||m...@freebsd.org

-- 
You are receiving this mail because:
You are the assignee for the bug.
___
freebsd-ruby@freebsd.org mailing list
https://lists.freebsd.org/mailman/listinfo/freebsd-ruby
To unsubscribe, send any mail to "freebsd-ruby-unsubscr...@freebsd.org"


[Bug 254799] lang/ruby25: Update to 2.5.9

2021-04-06 Thread bugzilla-noreply
https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=254799

Koichiro Iwao  changed:

   What|Removed |Added

   Assignee|r...@freebsd.org|m...@freebsd.org
 CC||m...@freebsd.org
 Status|New |In Progress

-- 
You are receiving this mail because:
You are the assignee for the bug.
___
freebsd-ruby@freebsd.org mailing list
https://lists.freebsd.org/mailman/listinfo/freebsd-ruby
To unsubscribe, send any mail to "freebsd-ruby-unsubscr...@freebsd.org"


[Bug 254003] sysutils/rubygem-bundler: Update to 2.2.15

2021-04-06 Thread bugzilla-noreply
https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=254003

Koichiro Iwao  changed:

   What|Removed |Added

 CC||m...@freebsd.org
   Assignee|r...@freebsd.org|m...@freebsd.org

--- Comment #3 from Koichiro Iwao  ---
Hi, thank you always. 

BTW, since the ports tree has been migrated to git, can you try submitting a
patch  with `git format-patch`?  I'm still not sure what is the best way when
outside contributors submit a patch but I would like to try `git format-patch`
and `git am`.

-- 
You are receiving this mail because:
You are the assignee for the bug.
___
freebsd-ruby@freebsd.org mailing list
https://lists.freebsd.org/mailman/listinfo/freebsd-ruby
To unsubscribe, send any mail to "freebsd-ruby-unsubscr...@freebsd.org"


[Bug 254793] security/vuxml: Document XML round-trip vulnerability of REXML in Ruby

2021-04-06 Thread bugzilla-noreply
https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=254793

Koichiro Iwao  changed:

   What|Removed |Added

 CC||m...@freebsd.org
 Status|New |In Progress
   Assignee|ports-sect...@freebsd.org   |m...@freebsd.org

-- 
You are receiving this mail because:
You are on the CC list for the bug.
___
freebsd-ruby@freebsd.org mailing list
https://lists.freebsd.org/mailman/listinfo/freebsd-ruby
To unsubscribe, send any mail to "freebsd-ruby-unsubscr...@freebsd.org"


[Bug 254793] security/vuxml: Document XML round-trip vulnerability of REXML in Ruby

2021-04-06 Thread bugzilla-noreply
https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=254793

--- Comment #1 from Koichiro Iwao  ---
Failed to apply the patch. Can you resubmit it?

-- 
You are receiving this mail because:
You are on the CC list for the bug.
___
freebsd-ruby@freebsd.org mailing list
https://lists.freebsd.org/mailman/listinfo/freebsd-ruby
To unsubscribe, send any mail to "freebsd-ruby-unsubscr...@freebsd.org"


[Bug 253822] lang/jruby: Update to 9.2.17.0

2021-04-06 Thread bugzilla-noreply
https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=253822

Koichiro Iwao  changed:

   What|Removed |Added

 Status|New |In Progress
   Assignee|r...@freebsd.org|m...@freebsd.org
 CC||m...@freebsd.org

-- 
You are receiving this mail because:
You are on the CC list for the bug.
You are the assignee for the bug.
___
freebsd-ruby@freebsd.org mailing list
https://lists.freebsd.org/mailman/listinfo/freebsd-ruby
To unsubscribe, send any mail to "freebsd-ruby-unsubscr...@freebsd.org"


[Bug 254793] security/vuxml: Document XML round-trip vulnerability of REXML in Ruby

2021-04-06 Thread bugzilla-noreply
https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=254793

Yasuhiro Kimura  changed:

   What|Removed |Added

 Attachment #223832|0   |1
is obsolete||

--- Comment #2 from Yasuhiro Kimura  ---
Created attachment 223857
  --> https://bugs.freebsd.org/bugzilla/attachment.cgi?id=223857&action=edit
Updated patch file

Chase update of ports tree.

-- 
You are receiving this mail because:
You are on the CC list for the bug.
___
freebsd-ruby@freebsd.org mailing list
https://lists.freebsd.org/mailman/listinfo/freebsd-ruby
To unsubscribe, send any mail to "freebsd-ruby-unsubscr...@freebsd.org"


[Bug 254793] security/vuxml: Document XML round-trip vulnerability of REXML in Ruby

2021-04-06 Thread bugzilla-noreply
https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=254793

--- Comment #3 from Yasuhiro Kimura  ---
(In reply to Koichiro Iwao from comment #1)

Please try updated patch.

Best Regards.

-- 
You are receiving this mail because:
You are on the CC list for the bug.
___
freebsd-ruby@freebsd.org mailing list
https://lists.freebsd.org/mailman/listinfo/freebsd-ruby
To unsubscribe, send any mail to "freebsd-ruby-unsubscr...@freebsd.org"


[Bug 254793] security/vuxml: Document XML round-trip vulnerability of REXML in Ruby

2021-04-06 Thread bugzilla-noreply
https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=254793

--- Comment #4 from commit-h...@freebsd.org ---
A commit in branch main references this bug:

URL:
https://cgit.FreeBSD.org/ports/commit/?id=cbbdab46f9b73b3593fb453c4a2523936d569e15

commit cbbdab46f9b73b3593fb453c4a2523936d569e15
Author: Koichiro Iwao 
AuthorDate: 2021-04-05 14:42:08 +
Commit: Koichiro Iwao 
CommitDate: 2021-04-06 13:53:57 +

security/vuxml: Document XML round-trip vulnerability of REXML in Ruby

Document XML round-trip vulnerability of REXML in Ruby.

PR: 254793
Reported by:Yasuhiro Kimura 
Security:   CVE-2021-28965

 security/vuxml/vuln.xml | 39 +++
 1 file changed, 39 insertions(+)

-- 
You are receiving this mail because:
You are on the CC list for the bug.
___
freebsd-ruby@freebsd.org mailing list
https://lists.freebsd.org/mailman/listinfo/freebsd-ruby
To unsubscribe, send any mail to "freebsd-ruby-unsubscr...@freebsd.org"


[Bug 254793] security/vuxml: Document XML round-trip vulnerability of REXML in Ruby

2021-04-06 Thread bugzilla-noreply
https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=254793

--- Comment #5 from Koichiro Iwao  ---
Thanks for the quick follow-up.

Submitting patches generated by `git format-patch` is helpful. Because I can
reuse most parts of the submitter's commit message. At least I'm very happy
with receiving format-patch style patch.

I can apply the submitter's patch with the following commands.

$ curl -L '' > /tmp/patch
$ git am /tmp/patch
$ git commit --amend --reset-author
(add some commit messages)

The reason why I reset author is the repository blocks commits which has
different committer and author.

remote:
remote: 
remote: meta, you are pushing a commit which author and committer are
different:
remote:
remote: author: Yasuhiro Kimura 
remote: commit: e88e34f77ee344af29c0514ea45557a447d63b67
remote: subject: security/vuxml: Document XML round-trip vulnerability of REXML
in Ruby
remote:
remote: Please check the author name and email are correct and then use:
remote: git push --push-option=confirm-author
remote: 
To gitrepo.freebsd.org:ports.git
 ! [remote rejected]   main -> main (pre-receive hook declined)
error: failed to push some refs to 'gitrepo.freebsd.org:ports.git'

-- 
You are receiving this mail because:
You are on the CC list for the bug.
___
freebsd-ruby@freebsd.org mailing list
https://lists.freebsd.org/mailman/listinfo/freebsd-ruby
To unsubscribe, send any mail to "freebsd-ruby-unsubscr...@freebsd.org"


[Bug 254793] security/vuxml: Document XML round-trip vulnerability of REXML in Ruby

2021-04-06 Thread bugzilla-noreply
https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=254793

Koichiro Iwao  changed:

   What|Removed |Added

 Status|In Progress |Closed
 Resolution|--- |FIXED

--- Comment #6 from Koichiro Iwao  ---
Committed, thanks!

-- 
You are receiving this mail because:
You are on the CC list for the bug.
___
freebsd-ruby@freebsd.org mailing list
https://lists.freebsd.org/mailman/listinfo/freebsd-ruby
To unsubscribe, send any mail to "freebsd-ruby-unsubscr...@freebsd.org"


[Bug 222872] lang/ruby23, lang/ruby24 and lang/ruby25: does not build with POSIX-compliant sh -c

2021-04-06 Thread bugzilla-noreply
https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=222872

Rene Ladan  changed:

   What|Removed |Added

 CC||r...@freebsd.org

--- Comment #5 from Rene Ladan  ---
Is this still relevant with lang/ruby27 ?

-- 
You are receiving this mail because:
You are the assignee for the bug.
___
freebsd-ruby@freebsd.org mailing list
https://lists.freebsd.org/mailman/listinfo/freebsd-ruby
To unsubscribe, send any mail to "freebsd-ruby-unsubscr...@freebsd.org"


[Bug 222872] lang/ruby26, lang/ruby27 and lang/ruby30: does not build with POSIX-compliant sh -c

2021-04-06 Thread bugzilla-noreply
https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=222872

Jilles Tjoelker  changed:

   What|Removed |Added

Summary|lang/ruby23, lang/ruby24|lang/ruby26, lang/ruby27
   |and lang/ruby25: does not   |and lang/ruby30: does not
   |build with POSIX-compliant  |build with POSIX-compliant
   |sh -c   |sh -c

--- Comment #6 from Jilles Tjoelker  ---
(In reply to Rene Ladan from comment #5)
Yes, the problematic code is still in lang/ruby26, lang/ruby27 and lang/ruby30.

-- 
You are receiving this mail because:
You are the assignee for the bug.
___
freebsd-ruby@freebsd.org mailing list
https://lists.freebsd.org/mailman/listinfo/freebsd-ruby
To unsubscribe, send any mail to "freebsd-ruby-unsubscr...@freebsd.org"