Created attachment 208679 [details] update net-im/py-matrix-synapse to 1.5.0 I've attached both a patch for the py-matrix-synapse port as well as a vuxml-entry for the recent 1.5.0 release. The patch is mostly a simple version bump w/ an additional dependency in accordance with upstream changes. I've also upgraded the sample log configuration for recent synapse releases.
Created attachment 208680 [details] vuxml entry for the new net-im/py-matrix-synapse security issue
Created attachment 209510 [details] update net-im/py-matrix-synapse to 1.6.1 Synapse is now at 1.6.1. The 1.6 release has removed one dependency, which I've reflected in the port accordingly. Additionally, the 1.6.1 release is another security release, see [1]. There's very little information on the nature of this security release, but I'll add a vuxml entry in the next comment. It would be nice if we could get these updates committed. That's now two security issues that our users might be unaware of. As for stability, 1.6.1 is currently running fine on my own server. I'm always grateful for feedback, if anyone wants to give this a spin. Cheers, Sascha [1] https://github.com/matrix-org/synapse/releases/tag/v1.6.1
Created attachment 209511 [details] another vuxml entry for the 1.6.1 vulnerability Here's the vuxml entry for the 1.6.1 release. Since there are very few details on the kind of security vulnerability, I've kept it pretty basic. Feedback is welcome, as usual. :)
A commit references this bug: Author: decke Date: Thu Nov 28 15:44:53 UTC 2019 New revision: 518587 URL: https://svnweb.freebsd.org/changeset/ports/518587 Log: Document net-im/py-matrix-synapse vulnerabilities PR: 241574 Submitted by: Sascha Biberhofer <ports@skyforge.at> Changes: head/security/vuxml/vuln.xml
A commit references this bug: Author: decke Date: Thu Nov 28 17:05:12 UTC 2019 New revision: 518593 URL: https://svnweb.freebsd.org/changeset/ports/518593 Log: net-im/py-matrix-synapse: Update to 1.6.1 which also fixes two vulnerabitilies PR: 241574 Submitted by: Sascha Biberhofer <ports@skyforge.at> Changes: head/net-im/py-matrix-synapse/Makefile head/net-im/py-matrix-synapse/distinfo head/net-im/py-matrix-synapse/files/log.config.in
Committed, thanks!