On Tue, 11 Aug 2026 10:50:41 -0400
"Dan Langille" <[email protected]> wrote:

> On Tue, Aug 11, 2026, at 8:25 AM, Piotr Smyrak wrote:
> > On Tue, 11 Aug 2026 07:20:38 -0400
> > "Dan Langille" <[email protected]> wrote:
> >  
> >> On Tue, Aug 11, 2026, at 6:17 AM, Dan Mahoney wrote:  
> >> > To Dan's L's point, though.    
> >> 
> >> [snip]
> >>   
> >> > And yeah, pkg-audit needs a knob that exempts specific
> >> > CVEID's/vuxml entries/packages from its alert.  If you've looked
> >> > at your system, read the tea leaves, asked other knowledgeable
> >> > people, asked your favorite LLM, and asked your magic 8 ball and
> >> > you say "okay, this is an imap and pop3 vuln, I am sure I'm not
> >> > using those libs" OR "I have patched the code that consumes
> >> > those functions" OR "in fact I've deleted them post-install, let
> >> > me go on with life", you should be able to.    
> >> 
> >> Please my post to freebsd-ports@ titled "modifying pkg-audit to
> >> ignore specified vulns"
> >> 
> >> re:
> >> https://lists.freebsd.org/archives/freebsd-ports/2026-August/009871.html
> >> 
> >> I have done a manual proof-of-concept and now it's just a simple
> >> matter of coding.  
> >
> > Dan,
> >
> > IIUC, you are building your own packages. I would like to propose a
> > simpler approach that does not require any development whatsoever.
> > You could either patch the local ports tree or just revert the
> > commits that added these vulnerabilities to the XML file, and
> > build the VuXML DB from such patched port, publish the XML artifact
> > to be accessible from within Freshports network, and modify this
> > setting in pkg.conf:
> >
> > #VULNXML_SITE = "http://vuxml.freebsd.org/freebsd/vuln.xml.xz";; 
> >
> > This way you just redirect the whole infrastructure to a custom
> > advisory DB, still built and relying on a slightly adjusted project
> > DB.
> >
> > As long as you don't push from this local git repo of ports, you can
> > even commit the change. (I am assuming here, you use git to fetch
> > the tree).   
> 
> That is a nice idea. Thank you.  That helps me, definitely.
> 
> The "tricky" part may be knowing there is a new VuXML to build and
> then distributing it.

You could setup a git hook that detects changes to the XML files in
security/vuxml/vuln and triggers a rebuild of your own DB. 
 
> I'm an outlier. Most people do not build their own.

To me this is the FreeBSD spirit!

-- 
 Piotr Smyrak

Reply via email to