Bug 267177 - devel/git: Update to 2.38.1 (security release)
Summary: devel/git: Update to 2.38.1 (security release)
Status: Closed FIXED
Alias: None
Product: Ports & Packages
Classification: Unclassified
Component: Individual Port(s) (show other bugs)
Version: Latest
Hardware: Any Any
: Normal Affects Many People
Assignee: Renato Botelho
URL: https://lore.kernel.org/git/xmqq4jw1u...
Keywords: security
Depends on:
Blocks:
 
Reported: 2022-10-18 18:22 UTC by rob2g2
Modified: 2022-10-19 12:00 UTC (History)
3 users (show)

See Also:
garga: merge-quarterly+


Attachments
patch for vuln-2022.xml (1.28 KB, patch)
2022-10-18 18:22 UTC, rob2g2
no flags Details | Diff

Note You need to log in before you can comment on or make changes to this bug.
Description rob2g2 2022-10-18 18:22:17 UTC
Created attachment 237437 [details]
patch for vuln-2022.xml

please update git to 2.38.1 and add attached fix to vuln.xml to inform users. thanks.
Comment 1 Renato Botelho freebsd_committer freebsd_triage 2022-10-18 18:34:24 UTC
I already added them to vuxml and also upgraded devel/git
Comment 2 Graham Perrin freebsd_committer freebsd_triage 2022-10-18 18:39:15 UTC
^Triage: Assign to committer resolving
Comment 3 Kubilay Kocak freebsd_committer freebsd_triage 2022-10-18 22:40:53 UTC
^Triage: 

- Resolved in da372a849a7e (by commit), set resolution (FIXED) accordingly.
- VuXML added in ports 6d220756feb8

Commit log message doesn't include MFH, doesn't appear 2022Q4 [1] has received the this security fix merge, not sure why (not affected?), re-open.

[1] https://cgit.freebsd.org/ports/log/devel/git?h=2022Q4
Comment 4 Renato Botelho freebsd_committer freebsd_triage 2022-10-19 12:00:46 UTC
I forgot to cherry-pick it to quarterly.  Done now.  Thanks!