Re: [Bug 263060] devel/py-py: Update to 1.10.0 (security) -> 1.11.0 (for @py311 support)

2023-04-24 Thread Hubert Tournier
Hello, Project's URL is https://github.com/pytest-dev/py Version 1.11.0 is the last version available. When you look at https://osv.dev/vulnerability/PYSEC-2022-42969 you see the "Last affected 1.11.0" entry, which means that the latest available version is vulnerable (otherwise, you would have a "

45 vulnerable ports unreported in VuXML

2023-03-26 Thread Hubert Tournier
Hello, While working on pipinfo , an alternative Python packages management tool, I noticed that some Python packages installed as FreeBSD ports where marked as vulnerable by the Python Packaging Authority