Bug 238798

Summary: www/drupal8: update to 8.6.16 (fixes sa-core-2019-007)
Product: Ports & Packages Reporter: Krzysztof <ports>
Component: Individual Port(s)Assignee: Jose Alonso Cardenas Marquez <acm>
Status: Closed FIXED    
Severity: Affects Many People CC: ports
Priority: Normal Keywords: security
Version: LatestFlags: bugzilla: maintainer-feedback? (acm)
koobs: merge-quarterly?
Hardware: Any   
OS: Any   
URL: https://www.drupal.org/sa-core-2019-007
Bug Depends on:    
Bug Blocks: 237802    
Attachments:
Description Flags
drupal8 update to 8.6.16
none
drupal8 update to 8.7.4 none

Description Krzysztof 2019-06-25 08:49:04 UTC
Created attachment 205324 [details]
drupal8 update to 8.6.16

There is Security Advisory for drupal8 less then 8.6.16. You can check it at: https://www.drupal.org/sa-core-2019-007

I've made a patch which updates port to this new version.

I've tested this patch with poudriere. There is no errors.

Also I've checked the port with portlint. The result is:
% portlint -AC
WARN: Makefile: for new port, make $FreeBSD$ tag in comment section empty, to make SVN happy.
WARN: Makefile: extra item placed in the USES/USE_x section, for example, "SHEBANG_FILES".
WARN: Consider to set DEVELOPER=yes in /etc/make.conf
0 fatal errors and 3 warnings found.
Comment 1 Kubilay Kocak freebsd_committer freebsd_triage 2019-06-25 09:23:56 UTC
Comment on attachment 205324 [details]
drupal8 update to 8.6.16

Please don't set maintainer-approval unless you are the port maintainer
Comment 2 Krzysztof 2019-06-25 11:27:50 UTC
Pardon :-)))
Comment 3 Krzysztof 2019-07-09 04:57:18 UTC
Created attachment 205594 [details]
drupal8 update to 8.7.4

As Alonso suggested drupal 8.6.x will loose security updates at the end of this year (2019).

So I've made a patch which updates to 8.7.4.

I've tested this patch with poudriere. So I can share logs from poudriere if it is needed.
Comment 4 Jose Alonso Cardenas Marquez freebsd_committer 2019-07-21 04:03:27 UTC
- I have updated drupal8 to 8.7.5 because 8.6.x security updates will end of 2019