Created attachment 184207 [details] patch devel/oniguruma5 suffered from security problems.
Created attachment 184208 [details] patch
Committed, thanks!
A commit references this bug: Author: pi Date: Thu Jul 13 10:52:33 UTC 2017 New revision: 445643 URL: https://svnweb.freebsd.org/changeset/ports/445643 Log: textproc/jq: change dependency from oniguruma5 to oniguruma6 PR: 220586 Submitted by: Yuri Victorovich <yuri@rawbw.com> (maintainer) Changes: head/textproc/jq/Makefile
User requested [1] MFH. Given security context, re-opening [1] https://lists.freebsd.org/pipermail/freebsd-ports/2017-July/109436.html
(In reply to Kubilay Kocak from comment #4) @pi: Should I MFH?
Yes, please MFH
Can this be merged into the quarterly ports? This is causing problems, for example, on FreeBSD systems with PHP at Digital Ocean. The cloud init scripts use jq to parse JSON configuration files, and requires oniguruma5. The php56-mbstring package requires oniguruma6. To make a long story short, this can result in the server coming up without any network configuration after a reboot.
It should be mer(In reply to Fred Condo from comment #7) Agreed.
Requested MFH from ports-secteam/portmgr (as I don't believe this is covered by any blanket approval).
A new quarterly has seen the light, so this is done.