Bug 287094 - www/glpi: update to 10.0.18 (fixed 9 CVEs)
Summary: www/glpi: update to 10.0.18 (fixed 9 CVEs)
Status: Closed FIXED
Alias: None
Product: Ports & Packages
Classification: Unclassified
Component: Individual Port(s) (show other bugs)
Version: Latest
Hardware: Any Any
: --- Affects Some People
Assignee: Vladimir Druzenko
URL:
Keywords:
Depends on:
Blocks:
 
Reported: 2025-05-27 09:28 UTC by Mathias Monnerville
Modified: 2025-05-27 19:51 UTC (History)
4 users (show)

See Also:


Attachments
Patch 10.0.17 to 10.0.18 (16.02 KB, patch)
2025-05-27 09:28 UTC, Mathias Monnerville
m: maintainer-approval+
Details | Diff
Poudriere logs for 10.0.18 (39.66 KB, text/plain)
2025-05-27 09:29 UTC, Mathias Monnerville
m: maintainer-approval+
Details
Patch 10.0.17 to 10.0.18 (16.16 KB, patch)
2025-05-27 09:36 UTC, Mathias Monnerville
m: maintainer-approval+
Details | Diff

Note You need to log in before you can comment on or make changes to this bug.
Description Mathias Monnerville 2025-05-27 09:28:53 UTC
Created attachment 260734 [details]
Patch 10.0.17 to 10.0.18

This is a patch release of www/glpi  from 10.0.17 to 10.0.18.

This is a security release (3 high severity, 6 moderate security fixes).

ChangeLog:
- https://github.com/glpi-project/glpi/releases/tag/10.0.18

Also attached the Poudriere testport logs.
Comment 1 Bugzilla Automation freebsd_committer freebsd_triage 2025-05-27 09:28:53 UTC
Maintainer informed via mail
Comment 2 Mathias Monnerville 2025-05-27 09:29:45 UTC
Created attachment 260735 [details]
Poudriere logs for 10.0.18
Comment 3 Mathias Monnerville 2025-05-27 09:30:39 UTC
(In reply to Mathias Monnerville from comment #2)

Typo: poudriere logs for 10.0.18 (not .17)
Comment 4 Mathias Monnerville 2025-05-27 09:36:43 UTC
Created attachment 260737 [details]
Patch 10.0.17 to 10.0.18

I now use a new maintainer email address and just included it in the patch as well.
Comment 5 commit-hook freebsd_committer freebsd_triage 2025-05-27 19:16:46 UTC
A commit in branch main references this bug:

URL: https://cgit.FreeBSD.org/ports/commit/?id=49f8093ab5cec53af2eff5079fe550291ce03809

commit 49f8093ab5cec53af2eff5079fe550291ce03809
Author:     Mathias Monnerville <m@kappa.st>
AuthorDate: 2025-05-27 19:03:45 +0000
Commit:     Vladimir Druzenko <vvd@FreeBSD.org>
CommitDate: 2025-05-27 19:11:30 +0000

    www/glpi: Update 10.0.17 => 10.0.18 (fixed 9 CVEs)

    This is a security release (3 high severity, 6 moderate security fixes).

    Changelog:
    https://github.com/glpi-project/glpi/releases/tag/10.0.18

    Update maintainer email.
    Replace PORTVERSION with DISTVERSION.
    Use gettext-tools instead gettext in USES.

    PR:     287094
    MFH:    2025Q2

 www/glpi/Makefile  |   8 +-
 www/glpi/distinfo  |   6 +-
 www/glpi/pkg-plist | 241 ++---------------------------------------------------
 3 files changed, 13 insertions(+), 242 deletions(-)
Comment 6 commit-hook freebsd_committer freebsd_triage 2025-05-27 19:32:51 UTC
A commit in branch 2025Q2 references this bug:

URL: https://cgit.FreeBSD.org/ports/commit/?id=a58ec22c377eff3d21786e7e3185301519d4594a

commit a58ec22c377eff3d21786e7e3185301519d4594a
Author:     Mathias Monnerville <m@kappa.st>
AuthorDate: 2025-05-27 19:03:45 +0000
Commit:     Vladimir Druzenko <vvd@FreeBSD.org>
CommitDate: 2025-05-27 19:30:41 +0000

    www/glpi: Update 10.0.17 => 10.0.18 (fixed 9 CVEs)

    This is a security release (3 high severity, 6 moderate security fixes).

    Changelog:
    https://github.com/glpi-project/glpi/releases/tag/10.0.18

    Update maintainer email.
    Replace PORTVERSION with DISTVERSION.
    Use gettext-tools instead gettext in USES.

    PR:             287094
    Security:       CVE-2025-24799
    Security:       CVE-2025-24801
    Security:       CVE-2025-21619
    Security:       CVE-2024-11955
    Security:       CVE-2025-21627
    Security:       CVE-2025-21626
    Security:       CVE-2025-23024
    Security:       CVE-2025-23046
    Security:       CVE-2025-25192
    MFH:            2025Q2
    (cherry picked from commit 49f8093ab5cec53af2eff5079fe550291ce03809)

 www/glpi/Makefile  |   8 +-
 www/glpi/distinfo  |   6 +-
 www/glpi/pkg-plist | 241 ++---------------------------------------------------
 3 files changed, 13 insertions(+), 242 deletions(-)
Comment 7 Vladimir Druzenko freebsd_committer freebsd_triage 2025-05-27 19:51:43 UTC
Thanks.