Bug 266535 - www/grafana7: Deprecate and remove port
Summary: www/grafana7: Deprecate and remove port
Status: Closed FIXED
Alias: None
Product: Ports & Packages
Classification: Unclassified
Component: Individual Port(s) (show other bugs)
Version: Latest
Hardware: Any Any
: --- Affects Some People
Assignee: Fernando Apesteguía
URL:
Keywords: security
Depends on:
Blocks:
 
Reported: 2022-09-21 14:50 UTC by Boris Korzun
Modified: 2022-10-06 16:10 UTC (History)
2 users (show)

See Also:
bugzilla: maintainer-feedback? (robsonmantovani)
drtr0jan: maintainer-feedback? (robsonmantovani)


Attachments
grafana7.diff (440 bytes, patch)
2022-09-21 14:50 UTC, Boris Korzun
drtr0jan: maintainer-approval? (robsonmantovani)
Details | Diff

Note You need to log in before you can comment on or make changes to this bug.
Description Boris Korzun 2022-09-21 14:50:43 UTC
Created attachment 236733 [details]
grafana7.diff

There're at least three vulnerabilities (two critical and one moderate) in the port. There aren't fixes by upsream. Last version (7.5.16) has been released on on May 19, 2022. Current port version (7.5.15) has been released on Jan 25, 2022.

I think the port should be marked as deprecated.

Details:
- 7.x branch is deprecated upstream
- Has unfixed vulnerabilities
- grafana8 and grafana9 are available as replacements
- no consumers of grafana7 in the ports tree

Security:
CVE-2022-31107
CVE-2022-31176
CVE-2022-35957
Comment 1 Fernando Apesteguía freebsd_committer freebsd_triage 2022-10-06 16:10:30 UTC
Committed,

Thanks!
Comment 2 commit-hook freebsd_committer freebsd_triage 2022-10-06 16:10:57 UTC
A commit in branch main references this bug:

URL: https://cgit.FreeBSD.org/ports/commit/?id=13501dde5481abd54d610c65a37105eb46d61542

commit 13501dde5481abd54d610c65a37105eb46d61542
Author:     Boris Korzun <drtr0jan@yandex.ru>
AuthorDate: 2022-10-06 05:56:36 +0000
Commit:     Fernando Apesteguía <fernape@FreeBSD.org>
CommitDate: 2022-10-06 16:06:32 +0000

    www/grafana7: Deprecate

     * 7.x branch is deprecated upstream
     * Has unfixed vulnerabilities
     * grafana8 and grafana9 are available as replacements
     * no consumers of grafana7 in the ports tree

    PR:             266535
    Reported by:    drtr0jan@yandex.ru
    Approved by:    robsonmantovani@gmail.com (maintainer, timeout > 2 weeks)

 www/grafana7/Makefile | 3 +++
 1 file changed, 3 insertions(+)