HardenedBSD Services pushed to branch freebsd/main at HardenedBSD / Ports
Commits:
b029f6c8 by Vidar Karlsen at 2026-03-10T21:00:19+03:00
www/awstats: Remove
awdownloadcsv.pl (security vuln)
Problem:
awdownloadcsv.pl is vulnerable to command injection and path traversal,
ref [1] and [2].
The GitHub issue [1] mentions that it is deprecated, and the readme does
not list this file among the files that are (supposed to be) part of the
distribution.
Solution:
This commit prevents
awdownloadcsv.pl to be installed, thus removing the
vulnerability.
[1]
https://github.com/eldy/AWStats/issues/276
[2]
https://www.openwall.com/lists/oss-security/2026/03/08/8
While here, clean up sorting of IPV6_RUN_DEPENDS.
PR: 293698
MFH: 2026Q1
- - - - -
ac7488c1 by Dmitry Marakasov at 2026-03-10T21:34:28+03:00
devel/cppcheck: update 2.19.1 → 2.20.0
- - - - -
f3951885 by Dmitry Marakasov at 2026-03-10T21:34:28+03:00
games/linwarrior: deprecate
- - - - -
58d1e2f2 by Dmitry Marakasov at 2026-03-10T21:34:29+03:00
devel/omnilinter: update 0.7.0 → 0.7.1
- - - - -
2791408e by Dmitry Marakasov at 2026-03-10T21:34:29+03:00
astro/josm: update 19439 → 19481
- Switch to latest supported openjdk
- Simplify wrapper script, run with correct java
- - - - -
db52a59b by Dmitry Marakasov at 2026-03-10T21:34:29+03:00
astro/osmosis: switch to default java version
- - - - -
64185136 by Dmitry Marakasov at 2026-03-10T21:34:29+03:00
astro/gpsprune: switch to default java version
- - - - -
a9262807 by Dmitry Marakasov at 2026-03-10T21:34:29+03:00
games/luanti: update 5.14.0 → 5.15.1
PR: 293560
Tested by:
giorgio...@protonmail.com
- - - - -
31d509bd by Dmitry Marakasov at 2026-03-10T21:34:30+03:00
games/widelands: update 1.2.1 → 1.3.1
PR: 293644
Tested by:
thi...@laeran.pl.eu.org
- - - - -
d4d2f6ac by Adam Weinberger at 2026-03-10T14:42:55-04:00
sysutils/goaccess: Update to 1.10.1
- - - - -
91df7cc8 by Adam Weinberger at 2026-03-10T14:51:09-04:00
textproc/qo: Update to 0.3.1
- - - - -
0d7ef50c by Dan Kotowski at 2026-03-10T14:26:03-05:00
graphics/igt-gpu-tools: Fix builds since D49183
- - - - -
56676a34 by Joel Bodenmann at 2026-03-10T21:19:09+01:00
audio/subtui: Update to 2.10.0
Changelog:
https://github.com/MattiaPun/SubTUI/releases/tag/v2.10.0
- - - - -
d4ce7315 by Guido Falsi at 2026-03-10T21:21:48+01:00
mail/mailpit: Update to 1.29.3
Improved ONLY_FOR_ARCHS_REASON message to better explain the supported
architectures.
- - - - -
3f3ee57e by Dima Panov at 2026-03-11T01:03:57+03:00
net/dpdk: update to latest LTS release, 25.11.0, adopt (+)
Tested on: aarch64, amd64
Release notes:
http://doc.dpdk.org/guides/rel_notes/release_25_11.html
Approved by: Bruce Richardson (former maintainer)
- - - - -
8605c56f by Craig Leres at 2026-03-10T15:24:44-07:00
devel/py-p4python: Update to 2025.2.2863679
PR: 293725
Approved by:
ant...@hesiod.org (maintainer)
- - - - -
c97f206e by Robert Gogolok at 2026-03-11T01:42:59+03:00
textproc/elasticsearch7: Correct product name
Rename ElasticSearch to Elasticsearch in the file pkg-message.
PR: 261591
Approved by: elastic (maintainer, timeout 4+ years)
- - - - -
faadb589 by Jason W. Bacon at 2026-03-10T18:03:35-05:00
biology/salmon: Unbreak: Relax libgff version requirement
Also drop unnecessary libboost dep
Reported by: pkg-fallout
- - - - -
91316bf1 by Vladimir Druzenko at 2026-03-11T02:07:27+03:00
security/chkrootkit: Update 0.58b => 0.59
Changelog:
- New checks: Process executed from memory
- New commands: nologin
- XZ Backdoor Bottkitty (UEFI Bootkit)
- Bug fixes
https://www.chkrootkit.org/#new
Remove local patches with support FreeBSD 9.
PR: 293520
Approved by: Lacey Powers <
lacey....@gmail.com> (maintainer)
MFH: 2026Q1
- - - - -
0b351112 by NetBird Developers at 2026-03-11T02:39:10+03:00
security/netbird: Update 0.66.1 => 0.66.3
Changelogs:
https://github.com/netbirdio/netbird/releases/tag/v0.66.2
https://github.com/netbirdio/netbird/releases/tag/v0.66.3
Commit log:
https://github.com/netbirdio/netbird/compare/v0.66.1...v0.66.3
PR: 293710
- - - - -
50 changed files:
- astro/gpsprune/Makefile
- astro/josm/Makefile
- astro/josm/distinfo
- astro/josm/files/
josm.sh.in
- astro/osmosis/Makefile
- audio/subtui/Makefile
- audio/subtui/distinfo
- biology/salmon/Makefile
- devel/cppcheck/Makefile
- devel/cppcheck/distinfo
- devel/cppcheck/files/patch-CMakeLists.txt
- devel/omnilinter/Makefile
- devel/omnilinter/distinfo
- devel/py-p4python/Makefile
- devel/py-p4python/distinfo
- games/linwarrior/Makefile
- games/luanti/Makefile
- games/luanti/distinfo
- games/luanti/pkg-plist
- games/widelands/Makefile
- games/widelands/distinfo
- − games/widelands/files/patch-c0b44ccc04df35a9a23ca9be3e05f5d3a5428f6f
- games/widelands/pkg-plist
- graphics/igt-gpu-tools/Makefile
- graphics/igt-gpu-tools/files/patch-runner_executor.c
- mail/mailpit/Makefile
- mail/mailpit/distinfo
- mail/mailpit/files/patch-package-lock.json
- net/dpdk/Makefile
- net/dpdk/distinfo
- net/dpdk/files/patch-config_meson.build
- − net/dpdk/files/patch-kernel_freebsd_contigmem_contigmem.c
- − net/dpdk/files/patch-kernel_freebsd_nic__uio_nic__uio.c
- + net/dpdk/files/patch-meson.build
- net/dpdk/pkg-plist
- security/chkrootkit/Makefile
- security/chkrootkit/distinfo
- + security/chkrootkit/files/patch-Makefile
- − security/chkrootkit/files/patch-chklastlog.c
- − security/chkrootkit/files/patch-chkwtmp.c
- security/netbird/Makefile
- security/netbird/distinfo
- sysutils/goaccess/Makefile
- sysutils/goaccess/distinfo
- + sysutils/goaccess/files/patch-src_wsauth.c
- textproc/elasticsearch7/files/
pkg-message.in
- textproc/qo/Makefile
- textproc/qo/distinfo
- www/awstats/Makefile
- www/awstats/pkg-plist
The diff was not included because it is too large.
View it on GitLab:
https://git.hardenedbsd.org/hardenedbsd/ports/-/compare/c2a1cd5d3c65a8e13f75d6dbcf8ded3ac7decbb6...0b3511120155d64a240c809f4a60c49d55b48eb5
--
View it on GitLab:
https://git.hardenedbsd.org/hardenedbsd/ports/-/compare/c2a1cd5d3c65a8e13f75d6dbcf8ded3ac7decbb6...0b3511120155d64a240c809f4a60c49d55b48eb5
You're receiving this email because of your account on
git.hardenedbsd.org.