On Tue, Aug 11, 2026, at 6:17 AM, Dan Mahoney wrote:
> To Dan's L's point, though.

[snip]

> And yeah, pkg-audit needs a knob that exempts specific CVEID's/vuxml 
> entries/packages from its alert.  If you've looked at your system, read 
> the tea leaves, asked other knowledgeable people, asked your favorite 
> LLM, and asked your magic 8 ball and you say "okay, this is an imap and 
> pop3 vuln, I am sure I'm not using those libs" OR "I have patched the 
> code that consumes those functions" OR  "in fact I've deleted them 
> post-install, let me go on with life", you should be able to.

Please my post to freebsd-ports@ titled "modifying pkg-audit to ignore 
specified vulns"

re: https://lists.freebsd.org/archives/freebsd-ports/2026-August/009871.html

I have done a manual proof-of-concept and now it's just a simple matter of 
coding.
-- 
  Dan Langille
  [email protected]

Reply via email to