Hey Dewaye,
My response is in-line.
That is correct: we sync every six hours. Merge conflicts can delay
the sync since resolving them takes human effort. Merge conflicts are
usually resolved within 24-48 hours, most of the time much quicker.
>
> I note that FreeBSD UPDATING entries exist for: 20250228 and 20250117,
> while HardenedBSD's latest entries are: 20250214
> which suggests a 2 week delay between FreeBSD and HardenedBSD. Has
> something broken?
HardenedBSD does not change UPDATING. It's up to FreeBSD to keep
UPDATING up-to-date.
The link you're looking for is this:
https://git.hardenedbsd.org/hardenedbsd/HardenedBSD/-/tree/hardened/14-stable/master?ref_type=heads
The hardenedBSD-stable repo on GitHub is deprecated. It was only used
for building installation media. We don't use that repo anymore.
HardenedBSD maintains its own UPDATING file named
UPDATING-HardenedBSD. That tracks the __HardenedBSD_version (aka, the
hardening.version sysctl node). It's up to FreeBSD to maintain
UPDATING.
Thanks for letting me know! I'll reach out to the Lavabit folks to see
what's up.
Thanks,
--
Shawn Webb
Cofounder / Security Engineer
HardenedBSD
Tor-ified Signal:
+1 303-901-1600 / shawn_webb_opsec.50
https://git.hardenedbsd.org/hardenedbsd/pubkeys/-/raw/master/Shawn_Webb/03A4CBEBB82EA5A67D9F3853FF2E67A277F8E1FA.pub.asc