Re: portaudit

From: Jacques A. Vidrine (nectar_at_FreeBSD.org)
Date: 03/17/04

  • Next message: FreeBSD Security Advisories: "FreeBSD Security Advisory FreeBSD-SA-04:05.openssl"
    Date: Wed, 17 Mar 2004 08:23:30 -0600
    To: "Peter C. Lai" <sirmoo@cowbert.2y.net>
    
    

    On Wed, Mar 17, 2004 at 02:00:51AM -0500, Peter C. Lai wrote:
    > Any reason why portaudit and its associated infrastructure was not announced to
    > this list or security-notifications? I recently discovered it, and discovered
    > the feature was added to bsd.port.mk in the beginning of feburary. Seeing as
    > the security officer apparently (without announcement) no longer issues
    > security notices (SNs) for ports, I am assuming that portaudit has replaced
    > SNs entirely, and that we should rely on that for ports operational security?
    > I'm not subscribed to -ports, -questions, or -current, which were apparently
    > where the portaudit introduction discussions took place.

    VuXML is the new mechanism for documenting security issues in ports. It
    has not been `announced' because it is still at an experimental stage.

    portaudit is one tool that reads the FreeBSD VuXML document, and is well-
    suited for automated checking.

    Cheers,

    -- 
    Jacques Vidrine / nectar@celabo.org / jvidrine@verio.net / nectar@freebsd.org
    _______________________________________________
    freebsd-security@freebsd.org mailing list
    http://lists.freebsd.org/mailman/listinfo/freebsd-security
    To unsubscribe, send any mail to "freebsd-security-unsubscribe@freebsd.org"
    

  • Next message: FreeBSD Security Advisories: "FreeBSD Security Advisory FreeBSD-SA-04:05.openssl"

    Relevant Pages

    • Re: PHP vulnerability and portupgrade
      ... >> Use portaudit to track security issues in ports. ...
      (freebsd-stable)
    • Re: How often portupgrades?
      ... > often to run portupgrades. ... uninstall) if a given port has a security fix for it. ... Did a smidge of research and I think it is portaudit ... worried about it then upgrade (perhaps have portaudit ...
      (freebsd-questions)
    • Re: portaudit
      ... announcing portaudit on this list. ... > the security officer apparently no longer issues ... and that we should rely on that for ports operational security? ... a start script for workstations which do not run periodicscripts ...
      (FreeBSD-Security)
    • RE: How often portupgrades?
      ... >> complete gnome port which took a couple days! ... > uninstall) if a given port has a security fix for it. ... > Did a smidge of research and I think it is portaudit ... > worried about it then upgrade (perhaps have portaudit ...
      (freebsd-questions)
    • Re: What happened with portaudit?
      ... >> ruby, openssl) in tomorrows security run output, but in today's security ... >> affected packages. ... run portaudit -Fa to refetch the database and check again? ...
      (FreeBSD-Security)