Bug 263060 - devel/py-py: Update to 1.10.0 (security) -> 1.11.0 (for @py311 support)
Summary: devel/py-py: Update to 1.10.0 (security) -> 1.11.0 (for @py311 support)
Status: Closed FIXED
Alias: None
Product: Ports & Packages
Classification: Unclassified
Component: Individual Port(s) (show other bugs)
Version: Latest
Hardware: Any Any
: Normal Affects Many People
Assignee: freebsd-python (Nobody)
URL: https://github.com/pytest-dev/py/blob...
Keywords: needs-patch, needs-qa, security
Depends on:
Blocks:
 
Reported: 2022-04-05 13:28 UTC by Jan Beich
Modified: 2023-09-01 19:01 UTC (History)
5 users (show)

See Also:
bugzilla: maintainer-feedback? (python)
fluffy: merge-quarterly+


Attachments
v1 (apply via "git am") (1.21 KB, patch)
2022-04-05 13:28 UTC, Jan Beich
no flags Details | Diff

Note You need to log in before you can comment on or make changes to this bug.
Description Jan Beich freebsd_committer freebsd_triage 2022-04-05 13:28:18 UTC
Created attachment 232967 [details]
v1 (apply via "git am")
Comment 1 Kubilay Kocak freebsd_committer freebsd_triage 2022-04-05 23:00:06 UTC
@Jan Is the current port version broken (build or run) with 3.11? If so please precede this version update with a USES=python:-3.10 version spec cap in main/quarterly to fix the version support

Also, 1.10.0 fixes a security vulnerability in versions <= 1.9.0 [1], so we'll need to update to that version first and merge.

Confirming that the port passes QA (upstream test suite) would be great too.

[1] https://github.com/pytest-dev/py/blob/1.11.0/CHANGELOG.rst
Comment 2 commit-hook freebsd_committer freebsd_triage 2022-05-09 04:27:14 UTC
A commit in branch main references this bug:

URL: https://cgit.FreeBSD.org/ports/commit/?id=52007e3315c0417337706bbf186d78a1b7e5a269

commit 52007e3315c0417337706bbf186d78a1b7e5a269
Author:     Mostly BSD <sec.research.2005@gmail.comaa>
AuthorDate: 2022-04-05 17:01:01 +0000
Commit:     Koichiro Iwao <meta@FreeBSD.org>
CommitDate: 2022-05-09 04:26:29 +0000

    sysutils/yadf: New port: Yet Another Duplicate Files Finder

    WWW:    https://github.com/jrimbault/yadf

    PR:             263060

 sysutils/yadf/Makefile (new)  | 133 +++++++++++++++++++++++++
 sysutils/yadf/distinfo (new)  | 225 ++++++++++++++++++++++++++++++++++++++++++
 sysutils/yadf/pkg-descr (new) |   8 ++
 3 files changed, 366 insertions(+)
Comment 3 Koichiro Iwao freebsd_committer freebsd_triage 2022-05-09 04:32:36 UTC
(In reply to commit-hook from comment #2)
This should be 263069, sorry for the noise.
Comment 4 George Mitchell 2023-04-24 17:45:53 UTC
It appears as if this bug should be closed.  However, can anyone here verify the WWW entry in the Makefile?  Visiting https://pylib.org sends one to a company that appears to be in the business of writing term papers.  https://pypi.org/project/py/ looks a lot more plausible to me.  In the mean time, version 1.11.0 is now listed in vulm.xml, and there doesn't seem to be a newer version available yet.
Comment 5 Jochen Neumeister freebsd_committer freebsd_triage 2023-09-01 19:01:54 UTC
I see, there is 1.11.0 into the Ports, so i close here.