On Tue, 18 Aug 2026 15:17:01 +0200
Michael Gmelin <[email protected]> wrote:

> On Mon, 10 Aug 2026 16:27:41 -0400
> "Dan Langille" <[email protected]> wrote:
> 
> > Hello,
> > 
> > I use periodic/security/410.pkg-audit as part of a Nagios reporting
> > tool. This monitoring check lets me know when a particular host has
> > a vuln. I have used it, or something like it, for years.
> > 
> > Alert fatigue is a real issue. Sometimes it takes months for given
> > known vuln to be fixed. In the meantime, a sea of red covers the
> > Nagios page making it difficult to see new / other vulns.
> > 
> > My goal: selectively silence a vuln.
> > 
> > Background: Back in April, I posted about this issue on Mastodon.
> > One solution, for ignoring vulns on a given port, worked.
> > https://bsd.network/web/@[email protected]/115925654143396302
> > 
> > However, now I want to modify this approach and ignore a list of
> > vulns.
> > 
> > In short, alter 410.pkg-audit to use a user-specified file and to
> > ignore upon any vulns specified in that file.
> > 
> > My short idea:
> > 
> > 1 - use the --file option on pkg-audit
> > 2 - using /var/db/pkg/vuln.xml as input, remove the vuln you don't
> > want to see 3 - output the results to a new file, say:
> > /var/db/pkg/vuln-filtered.xml 4 - run pkg-audit -f
> > /var/db/pkg/vuln-filtered.xml
> > 
> > For step 2, the file is XML and I'm sure there are many tools to
> > choose from which will delete based on vid in this:
> > 
> > 6d3488ae-2e0f-11f1-88c7-00a098b42aeb
> > 0be929a5-2e0f-11f1-88c7-00a098b42aeb
> > 
> > I'm posting in the hopes that someone takes up this challenge and
> > codes something up. I'm happy to test, but can't do the coding.
> 
> I've been using something like this locally for a while. I polished it
> a bit and added[0] it as security/periodic-filter-vuxml to the ports
> tree. It's intentionally simple, testing is welcome, see pkg-message
> for usage.
> 
> It basically adds a periodic job that runs prior to 405/410.pkg-audit,
> which downloads the vulnerability database if needed and removes
> entries as configured. No component/code of pkg is modified.

Congratulation! If I may suggest something. Your pkg-message should
form a base of a man page for this solution. 

-- 
 Piotr Smyrak

Reply via email to