Re: git: 28676937f7e1 - main - security/vuxml: Document Jenkins Security Advisory 2022-06-22

From: Li-Wen Hsu <lwhsu_at_freebsd.org>
Date: Thu, 23 Jun 2022 19:24:55 UTC
On Thu, Jun 23, 2022 at 6:15 PM Herbert J. Skuhra <herbert@gojira.at> wrote:
>
> On Wed, 22 Jun 2022 21:11:51 +0200, Li-Wen Hsu wrote:
> >
> > The branch main has been updated by lwhsu:
> >
> > URL: https://cgit.FreeBSD.org/ports/commit/?id=28676937f7e12203df395188b61af15f451fa006
> >
> > commit 28676937f7e12203df395188b61af15f451fa006
> > Author:     Li-Wen Hsu <lwhsu@FreeBSD.org>
> > AuthorDate: 2022-06-22 19:05:48 +0000
> > Commit:     Li-Wen Hsu <lwhsu@FreeBSD.org>
> > CommitDate: 2022-06-22 19:11:40 +0000
> >
> >     security/vuxml: Document  Jenkins Security Advisory 2022-06-22
> >
> >     Sponsored by:   The FreeBSD Foundation
> > ---
> >  security/vuxml/vuln-2022.xml | 41 +++++++++++++++++++++++++++++++++++++++++
> >  1 file changed, 41 insertions(+)
>
> Hi,
>
> why are https://vuxml.freebsd.org/freebsd/index.html and
> https://vuxml.freebsd.org/freebsd/rss.xml again not
> up-to-date and why is 'pkg audit -F' not updating? I think at least
> six entries are missing.
>
> $ ls -l /var/db/pkg/vuln.xml
> -r--r--r--  1 root  wheel  7146577 Jun 13 03:56 /var/db/pkg/vuln.xml
>
> # pkg audit -F
> vulnxml file up-to-date
> 0 problem(s) in 0 installed package(s) found.
>
> Building and validating security/vuxml works.

I think this fix the issue:
https://cgit.freebsd.org/ports/commit/?id=7395437ea1bc4a020112ce58f1225a3d4d0561f8

It seems that there are more restrictive rules applied when building
theoe files. I'll see what we can do for reporting when there is
failure.

Best,
Li-Wen