Bug 211930 - Mk/bsd.default-versions.mk: Change default Perl version to 5.22 or 5.24 (5.20 End-of-Life)
Summary: Mk/bsd.default-versions.mk: Change default Perl version to 5.22 or 5.24 (5.20...
Status: Closed Not Accepted
Alias: None
Product: Ports & Packages
Classification: Unclassified
Component: Individual Port(s) (show other bugs)
Version: Latest
Hardware: Any Any
: --- Affects Many People
Assignee: Port Management Team
URL:
Keywords: needs-patch, needs-qa, security
Depends on:
Blocks:
 
Reported: 2016-08-17 09:50 UTC by theis
Modified: 2016-08-17 21:48 UTC (History)
4 users (show)

See Also:
koobs: maintainer-feedback? (perl)
koobs: maintainer-feedback? (ports-secteam)
koobs: exp-run?


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description theis 2016-08-17 09:50:57 UTC
Current default version of Perl 5, 5.20, has reached end of life last year. 
A recent vulnerability was fixed in the ports tree, but one cannot expect bug fixes from upstream anymore.
Comment 1 Kubilay Kocak freebsd_committer freebsd_triage 2016-08-17 10:01:12 UTC
Assign to portmgr as default-versions.mk is unmaintained and an exp-run is likely.

Request feedback from Perl maintainer (perl) and ports-secteam as stakeholders (security)
Comment 2 Mathieu Arnold freebsd_committer freebsd_triage 2016-08-17 11:38:25 UTC
The plan was to make 5.22 the default last september and 5.24 this september.

We're still waiting for mod_perl to do an official release supporting anything after 5.20.

As soon as mod_perl is fixed, I think I will switch to 5.24 as the default.
Comment 3 Paul J Murphy 2016-08-17 15:41:56 UTC
N.B. Perl 5.20 is not actually end of life for critical security fixes.  perl.org's policy is actually 3 years from release of 5.x.0.  5.20.0 was released on 2014-May-27, so its real end of support life for critical security fixes (despite other statements on perl.org which directly contradict this) is actually 2017-May-27.

See http://perldoc.perl.org/perlhist.html and http://perldoc.perl.org/perlpolicy.html
Comment 4 Terry Kennedy 2016-08-17 21:33:35 UTC
(In reply to Mathieu Arnold from comment #2)

Steve Hay told me that as soon as the official Perl 5.22 release is out, he'll release mod_perl 2.0.10 with the fix (already in Git).
Comment 5 Mathieu Arnold freebsd_committer freebsd_triage 2016-08-17 21:48:49 UTC
(In reply to Terry Kennedy from comment #4)
> (In reply to Mathieu Arnold from comment #2)
> 
> Steve Hay told me that as soon as the official Perl 5.22 release is out,
> he'll release mod_perl 2.0.10 with the fix (already in Git).

Yes, I know, I'm just waiting for it :-)