Bug 233475 - www/gitea: Update to 1.6.0 (Fixes security vulnerability)
Summary: www/gitea: Update to 1.6.0 (Fixes security vulnerability)
Status: Closed FIXED
Alias: None
Product: Ports & Packages
Classification: Unclassified
Component: Individual Port(s) (show other bugs)
Version: Latest
Hardware: Any Any
: --- Affects Only Me
Assignee: Bernhard Froehlich
URL:
Keywords:
Depends on:
Blocks:
 
Reported: 2018-11-24 16:16 UTC by Stefan Bethke
Modified: 2018-11-29 14:44 UTC (History)
2 users (show)

See Also:


Attachments
vixml entry for four gitea vulns. (1.69 KB, patch)
2018-11-24 16:16 UTC, Stefan Bethke
no flags Details | Diff

Note You need to log in before you can comment on or make changes to this bug.
Description Stefan Bethke 2018-11-24 16:16:05 UTC
Update www/gitea to version 1.6.0

Release notes: https://blog.gitea.io/2018/11/gitea-1.6.0-is-released/

The time has come for another major release! We are proudly to present Gitea 1.6.0 to the world. In this release, we merged 178 pull requests – it’s less than last time (258).

Fixes four security vulnerabilities.
Comment 1 Stefan Bethke 2018-11-24 16:16:37 UTC
Created attachment 199514 [details]
vixml entry for four gitea vulns.
Comment 2 Bernhard Froehlich freebsd_committer freebsd_triage 2018-11-26 12:39:49 UTC
I'll take it.

Discussed with: joneum (irc)
Comment 3 commit-hook freebsd_committer freebsd_triage 2018-11-26 12:48:31 UTC
A commit references this bug:

Author: decke
Date: Mon Nov 26 12:48:04 UTC 2018
New revision: 485939
URL: https://svnweb.freebsd.org/changeset/ports/485939

Log:
  Update to 1.6.0

  Changelog: https://blog.gitea.io/2018/11/gitea-1.6.0-is-released/

  PR:		233475
  MFH:		2018Q4

Changes:
  head/www/gitea/Makefile
  head/www/gitea/distinfo
  head/www/gitea/pkg-plist
Comment 4 Bernhard Froehlich freebsd_committer freebsd_triage 2018-11-26 12:55:12 UTC
The mentioned security issues do not have any CVE numbers assigned so we normally do not document those in our vuxml. Since there was no patch for the port itself to bring it to 1.6.0 I did the update myself and did some light runtime testing which seemed fine.
Comment 5 commit-hook freebsd_committer freebsd_triage 2018-11-29 14:44:15 UTC
A commit references this bug:

Author: decke
Date: Thu Nov 29 14:43:20 UTC 2018
New revision: 486175
URL: https://svnweb.freebsd.org/changeset/ports/486175

Log:
  MFH: r485939

  Update to 1.6.0

  Changelog: https://blog.gitea.io/2018/11/gitea-1.6.0-is-released/

  PR:		233475
  Approved by:	portmgr (miwi)

Changes:
_U  branches/2018Q4/
  branches/2018Q4/www/gitea/Makefile
  branches/2018Q4/www/gitea/distinfo
  branches/2018Q4/www/gitea/pkg-plist