Bug 277184

Summary: www/grafana: Update to 10.3.3 and 9.5.16 (Fixes security vulnerability)
Product: Ports & Packages Reporter: Boris Korzun <drtr0jan>
Component: Individual Port(s)Assignee: Li-Wen Hsu <lwhsu>
Status: Closed FIXED    
Severity: Affects Some People CC: lwhsu, ports-secteam
Priority: --- Keywords: security
Version: LatestFlags: drtr0jan: merge-quarterly?
Hardware: Any   
OS: Any   
URL: https://grafana.com/blog/2024/02/14/grafana-security-release-medium-severity-security-fix-for-cve-2023-6152/
Attachments:
Description Flags
grafana.patch
drtr0jan: maintainer-approval+
grafana9.patch
drtr0jan: maintainer-approval+
vuxml.patch drtr0jan: maintainer-approval? (ports-secteam)

Description Boris Korzun 2024-02-20 14:08:51 UTC
Update to 10.3.3

Changelog: https://github.com/grafana/grafana/releases/tag/v10.3.3
Comment 1 Boris Korzun 2024-02-20 14:09:14 UTC
Created attachment 248631 [details]
grafana.patch
Comment 2 Boris Korzun 2024-02-20 14:10:12 UTC
Created attachment 248632 [details]
grafana9.patch

Update to 9.5.16

Changelog: https://github.com/grafana/grafana/releases/tag/v9.5.16
Comment 3 Boris Korzun 2024-02-20 14:11:24 UTC
Created attachment 248633 [details]
vuxml.patch
Comment 4 commit-hook freebsd_committer freebsd_triage 2024-02-23 23:18:20 UTC
A commit in branch main references this bug:

URL: https://cgit.FreeBSD.org/ports/commit/?id=44c1b6420862d96b7217b956187a1fe91e154b0c

commit 44c1b6420862d96b7217b956187a1fe91e154b0c
Author:     Boris Korzun <drtr0jan@yandex.ru>
AuthorDate: 2024-02-23 23:17:12 +0000
Commit:     Li-Wen Hsu <lwhsu@FreeBSD.org>
CommitDate: 2024-02-23 23:17:12 +0000

    www/grafana9: Update to 9.5.16

    PR:             277184
    MFH:            2024Q1
    Security:       6a851dc0-cfd2-11ee-ac09-6c3be5272acd

 www/grafana9/Makefile  |  5 ++---
 www/grafana9/distinfo  | 14 +++++++-------
 www/grafana9/pkg-plist |  2 ++
 3 files changed, 11 insertions(+), 10 deletions(-)
Comment 5 commit-hook freebsd_committer freebsd_triage 2024-02-23 23:18:21 UTC
A commit in branch main references this bug:

URL: https://cgit.FreeBSD.org/ports/commit/?id=5f96aab9814a310bd5dead76fa5d2994b48ec27d

commit 5f96aab9814a310bd5dead76fa5d2994b48ec27d
Author:     Boris Korzun <drtr0jan@yandex.ru>
AuthorDate: 2024-02-23 23:14:35 +0000
Commit:     Li-Wen Hsu <lwhsu@FreeBSD.org>
CommitDate: 2024-02-23 23:15:13 +0000

    security/vuxml: Document CVE-2023-6152 for www/grafana*

    PR:             277184

 security/vuxml/vuln/2024.xml | 59 ++++++++++++++++++++++++++++++++++++++++++++
 1 file changed, 59 insertions(+)
Comment 6 commit-hook freebsd_committer freebsd_triage 2024-02-23 23:18:22 UTC
A commit in branch main references this bug:

URL: https://cgit.FreeBSD.org/ports/commit/?id=8b885a37c0fa56c0316fa98f7f02206a68a18b7d

commit 8b885a37c0fa56c0316fa98f7f02206a68a18b7d
Author:     Boris Korzun <drtr0jan@yandex.ru>
AuthorDate: 2024-02-23 23:16:03 +0000
Commit:     Li-Wen Hsu <lwhsu@FreeBSD.org>
CommitDate: 2024-02-23 23:16:03 +0000

    www/grafana: Update to 10.3.3

    PR:             277184
    MFH:            2024Q1
    Security:       6a851dc0-cfd2-11ee-ac09-6c3be5272acd

 www/grafana/Makefile |  5 ++---
 www/grafana/distinfo | 18 +++++++++---------
 2 files changed, 11 insertions(+), 12 deletions(-)
Comment 7 commit-hook freebsd_committer freebsd_triage 2024-02-23 23:23:24 UTC
A commit in branch 2024Q1 references this bug:

URL: https://cgit.FreeBSD.org/ports/commit/?id=fa3fc4f064270ddfa81c2fece23eff237438f1d4

commit fa3fc4f064270ddfa81c2fece23eff237438f1d4
Author:     Boris Korzun <drtr0jan@yandex.ru>
AuthorDate: 2024-02-23 23:16:03 +0000
Commit:     Li-Wen Hsu <lwhsu@FreeBSD.org>
CommitDate: 2024-02-23 23:21:05 +0000

    www/grafana: Update to 10.3.3

    PR:             277184
    MFH:            2024Q1
    Security:       6a851dc0-cfd2-11ee-ac09-6c3be5272acd

    (cherry picked from commit 8b885a37c0fa56c0316fa98f7f02206a68a18b7d)

 www/grafana/Makefile |  4 ++--
 www/grafana/distinfo | 18 +++++++++---------
 2 files changed, 11 insertions(+), 11 deletions(-)
Comment 8 commit-hook freebsd_committer freebsd_triage 2024-02-23 23:23:25 UTC
A commit in branch 2024Q1 references this bug:

URL: https://cgit.FreeBSD.org/ports/commit/?id=c491aa2cd8a0a7e501a2a6692ae0b1f0492ae55d

commit c491aa2cd8a0a7e501a2a6692ae0b1f0492ae55d
Author:     Boris Korzun <drtr0jan@yandex.ru>
AuthorDate: 2024-02-23 23:17:12 +0000
Commit:     Li-Wen Hsu <lwhsu@FreeBSD.org>
CommitDate: 2024-02-23 23:22:01 +0000

    www/grafana9: Update to 9.5.16

    PR:             277184
    MFH:            2024Q1
    Security:       6a851dc0-cfd2-11ee-ac09-6c3be5272acd
    (cherry picked from commit 44c1b6420862d96b7217b956187a1fe91e154b0c)

 www/grafana9/Makefile  |  4 ++--
 www/grafana9/distinfo  | 14 +++++++-------
 www/grafana9/pkg-plist |  2 ++
 3 files changed, 11 insertions(+), 9 deletions(-)