Bug 206807

Summary: Update graphics/shotwell to snapshot to fix security issue
Product: Ports & Packages Reporter: Koop Mast <kwm>
Component: Individual Port(s)Assignee: Koop Mast <kwm>
Status: Closed FIXED    
Severity: Affects Only Me CC: feld, ports-secteam
Priority: --- Keywords: patch-ready
Version: Latest   
Hardware: Any   
OS: Any   
Attachments:
Description Flags
Update shotwell to a git snapshot none

Description Koop Mast freebsd_committer freebsd_triage 2016-01-31 22:28:04 UTC
Created attachment 166369 [details]
Update shotwell to a git snapshot

Update to a snapshot, to fix ssl cert validation. Sadly it doesn't look upstream shotwell is still active so we need to update to a snapshot. Also to fix this they had to port it to webkit2gtk3.

Announcement: https://mail.gnome.org/archives/distributor-list/2016-January/msg00000.html
upstream bug: https://bugzilla.gnome.org/show_bug.cgi?id=751709
Comment 1 Mark Felder freebsd_committer freebsd_triage 2016-02-04 15:24:18 UTC
The right thing to do here is protect our users. As we have the capability to do so and as long as this does not rely on a defunct version of webkit we should be able to keep it alive in our ports tree.

I can approve this snapshot update and MFH.
Comment 2 commit-hook freebsd_committer freebsd_triage 2016-02-05 16:32:54 UTC
A commit references this bug:

Author: kwm
Date: Fri Feb  5 16:32:10 UTC 2016
New revision: 408219
URL: https://svnweb.freebsd.org/changeset/ports/408219

Log:
  Document shotwell failure to validate TLS certificates.

  PR:		206807

Changes:
  head/security/vuxml/vuln.xml
Comment 3 commit-hook freebsd_committer freebsd_triage 2016-02-05 16:35:56 UTC
A commit references this bug:

Author: kwm
Date: Fri Feb  5 16:34:59 UTC 2016
New revision: 408220
URL: https://svnweb.freebsd.org/changeset/ports/408220

Log:
  Update shotwell to a git snapshot.

  Update to a snapshot, to fix ssl cert validation. Sadly it doesn't
  look upstream shotwell is still active so we need to update to a
  snapshot. Also to fix this, they had to port it to webkit2gtk3.

  PR:		206807
  Approved by:	ports-secteam (feld)
  MFH:		2016Q1

Changes:
  head/graphics/shotwell/Makefile
  head/graphics/shotwell/distinfo
  head/graphics/shotwell/files/patch-Makefile
  head/graphics/shotwell/pkg-plist