From nobody Thu Dec 21 22:55:39 2023 X-Original-To: freebsd-ports@mlmmj.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mlmmj.nyi.freebsd.org (Postfix) with ESMTP id 4Sx5Ph4rtvz54NB5 for ; Thu, 21 Dec 2023 22:55:52 +0000 (UTC) (envelope-from stb@lassitu.de) Received: from gilb.zs64.net (gilb.zs64.net [IPv6:2a00:14b0:4200:32e0::1ea]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256 client-signature ECDSA (P-256) client-digest SHA256) (Client CN "gilb.zs64.net", Issuer "R3" (verified OK)) by mx1.freebsd.org (Postfix) with ESMTPS id 4Sx5Pg1xJjz4XZP for ; Thu, 21 Dec 2023 22:55:50 +0000 (UTC) (envelope-from stb@lassitu.de) Authentication-Results: mx1.freebsd.org; dkim=none; spf=pass (mx1.freebsd.org: domain of stb@lassitu.de designates 2a00:14b0:4200:32e0::1ea as permitted sender) smtp.mailfrom=stb@lassitu.de; dmarc=none Received: by gilb.zs64.net (Postfix, from stb@lassitu.de) id 158094A0310 for ; Thu, 21 Dec 2023 22:55:42 +0000 (UTC) From: Stefan Bethke Content-Type: multipart/signed; boundary="Apple-Mail=_8F241703-014D-4B45-BAFE-4758FF12DB61"; protocol="application/pgp-signature"; micalg=pgp-sha512 List-Id: Porting software to FreeBSD List-Archive: https://lists.freebsd.org/archives/freebsd-ports List-Help: List-Post: List-Subscribe: List-Unsubscribe: Sender: owner-freebsd-ports@freebsd.org X-BeenThere: freebsd-ports@freebsd.org Mime-Version: 1.0 (Mac OS X Mail 16.0 \(3731.700.6\)) Subject: Gitea 1.21.3 needs a committer urgently (security) Message-Id: <9C810097-C1EB-4979-B878-10D9A6AADB79@lassitu.de> Date: Thu, 21 Dec 2023 23:55:39 +0100 To: FreeBSD Ports X-Mailer: Apple Mail (2.3731.700.6) X-Spamd-Result: default: False [-4.79 / 15.00]; SIGNED_PGP(-2.00)[]; NEURAL_HAM_LONG(-1.00)[-1.000]; NEURAL_HAM_MEDIUM(-1.00)[-1.000]; NEURAL_HAM_SHORT(-0.99)[-0.986]; MV_CASE(0.50)[]; R_SPF_ALLOW(-0.20)[+mx]; MIME_GOOD(-0.20)[multipart/signed,text/plain]; ONCE_RECEIVED(0.10)[]; DMARC_NA(0.00)[lassitu.de]; R_DKIM_NA(0.00)[]; FROM_EQ_ENVFROM(0.00)[]; MLMMJ_DEST(0.00)[freebsd-ports@freebsd.org]; MIME_TRACE(0.00)[0:+,1:+,2:~]; RCVD_TLS_LAST(0.00)[]; ASN(0.00)[asn:13135, ipnet:2a00:14b0::/32, country:DE]; PREVIOUSLY_DELIVERED(0.00)[freebsd-ports@freebsd.org]; ARC_NA(0.00)[]; FROM_HAS_DN(0.00)[]; RCPT_COUNT_ONE(0.00)[1]; HAS_ATTACHMENT(0.00)[]; FREEFALL_USER(0.00)[stb]; TO_MATCH_ENVRCPT_ALL(0.00)[]; TO_DN_ALL(0.00)[]; MID_RHS_MATCH_FROM(0.00)[]; RCVD_COUNT_ONE(0.00)[1] X-Rspamd-Queue-Id: 4Sx5Pg1xJjz4XZP X-Spamd-Bar: ---- --Apple-Mail=_8F241703-014D-4B45-BAFE-4758FF12DB61 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset=us-ascii Hi, it would be great if a committer could pick up = https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=3D275742 Gitea is affected by the SSH issue (through a Go library), plus 1.21.2 = was not committed either, which also contains security fixes. Thanks, Stefan -- Stefan Bethke Fon +49 175 3288861 --Apple-Mail=_8F241703-014D-4B45-BAFE-4758FF12DB61 Content-Transfer-Encoding: 7bit Content-Disposition: attachment; filename=signature.asc Content-Type: application/pgp-signature; name=signature.asc Content-Description: Message signed with OpenPGP -----BEGIN PGP SIGNATURE----- iQEzBAEBCgAdFiEEJ+hF98o4r3eU/HiPD885WK4W4sEFAmWEwmsACgkQD885WK4W 4sHSwgf7B5yIbojjtGK7vtYn/oH6If+p5NnsHRVpbaekF5pU30OWvfQNb6VycpdW ESmaDmbEo0jsujKj7mLJUQAYXF+FfUP8FsGjiI0pgRxpJo235ToS9KLcRUC0UOTZ dLt/gRBfMo7hM124S9HCeLl+fqAXb8/1vF7pOjlaDZgZobBSat9JrUku/WPfeWjL bUS7Qyl+3ac5jt6qflkxcbDl/XykEtIwi+g1tajtZzT37FNHzq3Tv8ZfMmHd7h50 G8CetFqEPTnTufhKU+VI8WkqLLgPGNvIuBXQC5rMP0Dcia7etVi0dErCbyWKjmx/ /uiIg7n2+GH+qBaHAdEjR3BgU3sTyg== =ZCEB -----END PGP SIGNATURE----- --Apple-Mail=_8F241703-014D-4B45-BAFE-4758FF12DB61--