Bug 206807 - Update graphics/shotwell to snapshot to fix security issue
Summary: Update graphics/shotwell to snapshot to fix security issue
Status: Closed FIXED
Alias: None
Product: Ports & Packages
Classification: Unclassified
Component: Individual Port(s) (show other bugs)
Version: Latest
Hardware: Any Any
: --- Affects Only Me
Assignee: Koop Mast
URL:
Keywords: patch-ready
Depends on:
Blocks:
 
Reported: 2016-01-31 22:28 UTC by Koop Mast
Modified: 2016-02-05 16:36 UTC (History)
2 users (show)

See Also:


Attachments
Update shotwell to a git snapshot (5.18 KB, patch)
2016-01-31 22:28 UTC, Koop Mast
no flags Details | Diff

Note You need to log in before you can comment on or make changes to this bug.
Description Koop Mast freebsd_committer freebsd_triage 2016-01-31 22:28:04 UTC
Created attachment 166369 [details]
Update shotwell to a git snapshot

Update to a snapshot, to fix ssl cert validation. Sadly it doesn't look upstream shotwell is still active so we need to update to a snapshot. Also to fix this they had to port it to webkit2gtk3.

Announcement: https://mail.gnome.org/archives/distributor-list/2016-January/msg00000.html
upstream bug: https://bugzilla.gnome.org/show_bug.cgi?id=751709
Comment 1 Mark Felder freebsd_committer freebsd_triage 2016-02-04 15:24:18 UTC
The right thing to do here is protect our users. As we have the capability to do so and as long as this does not rely on a defunct version of webkit we should be able to keep it alive in our ports tree.

I can approve this snapshot update and MFH.
Comment 2 commit-hook freebsd_committer freebsd_triage 2016-02-05 16:32:54 UTC
A commit references this bug:

Author: kwm
Date: Fri Feb  5 16:32:10 UTC 2016
New revision: 408219
URL: https://svnweb.freebsd.org/changeset/ports/408219

Log:
  Document shotwell failure to validate TLS certificates.

  PR:		206807

Changes:
  head/security/vuxml/vuln.xml
Comment 3 commit-hook freebsd_committer freebsd_triage 2016-02-05 16:35:56 UTC
A commit references this bug:

Author: kwm
Date: Fri Feb  5 16:34:59 UTC 2016
New revision: 408220
URL: https://svnweb.freebsd.org/changeset/ports/408220

Log:
  Update shotwell to a git snapshot.

  Update to a snapshot, to fix ssl cert validation. Sadly it doesn't
  look upstream shotwell is still active so we need to update to a
  snapshot. Also to fix this, they had to port it to webkit2gtk3.

  PR:		206807
  Approved by:	ports-secteam (feld)
  MFH:		2016Q1

Changes:
  head/graphics/shotwell/Makefile
  head/graphics/shotwell/distinfo
  head/graphics/shotwell/files/patch-Makefile
  head/graphics/shotwell/pkg-plist