From: Volker Schlecht Subject: [Security] security/age 1.2.1 To: ports Date: Wed, 18 Dec 2024 19:22:04 +0100 Here's an update for security/age fixing a security issue documented here: https://github.com/FiloSottile/age/security/advisories/GHSA-32gq-x56h-299c The update works, and I would like to commit this to -stable as well. ok for -current and -stable? Index: Makefile =================================================================== RCS file: /cvs/ports/security/age/Makefile,v retrieving revision 1.17 diff -u -p -r1.17 Makefile --- Makefile 20 Jun 2024 19:01:58 -0000 1.17 +++ Makefile 18 Dec 2024 18:06:03 -0000 @@ -1,7 +1,7 @@ COMMENT = simple, modern and secure file encryption tool MODGO_MODNAME = filippo.io/age -MODGO_VERSION = v1.2.0 +MODGO_VERSION = v1.2.1 DISTNAME = age-${MODGO_VERSION} Index: distinfo =================================================================== RCS file: /cvs/ports/security/age/distinfo,v retrieving revision 1.8 diff -u -p -r1.8 distinfo --- distinfo 20 Jun 2024 19:01:58 -0000 1.8 +++ distinfo 18 Dec 2024 18:06:03 -0000 @@ -1,4 +1,4 @@ -SHA256 (age-v1.2.0.zip) = 6AJuH+vJadg9i72MnZxil0O+NmuX8zyYg9YIEHZu9rs= +SHA256 (age-v1.2.1.zip) = wpwb5qzdbBL+O4DHZOJVObKPa9doke3RGYZJ0KvwZMY= SHA256 (go_modules/c2sp.org/!c!c!t!v/age/@v/v0.0.0-20240306222714-3ec4d716e805.mod) = 2ssdD8MjAO/iC8leBDTkFB9qjPVJ13PRrZGDw0gKtNo= SHA256 (go_modules/c2sp.org/!c!c!t!v/age/@v/v0.0.0-20240306222714-3ec4d716e805.zip) = VUUuIfeoB59uM0CKXjdVOpvFlgMm7zEOwaquj6yx0hY= SHA256 (go_modules/filippo.io/edwards25519/@v/v1.1.0.mod) = CZVW/E1+b1yxNe/di2u0wJMuOOoFjFP8X6XOKFVy+2E= @@ -9,14 +9,19 @@ SHA256 (go_modules/github.com/rogpeppe/g SHA256 (go_modules/github.com/rogpeppe/go-internal/@v/v1.12.0.zip) = 1FOecWwrfygkWE5MShf2TFCL1uU1kQakBqfiPncQnN4= SHA256 (go_modules/github.com/yuin/goldmark/@v/v1.4.13.mod) = 7n/kRmIDoB06wZrcE0zeyZvG3nGZLCjz3Zp0SAv/BgM= SHA256 (go_modules/github.com/yuin/goldmark/@v/v1.4.13.zip) = u0GmArF0NF/aOSyK2D/MkyF8KFx2NplndjC+kP63peM= +SHA256 (go_modules/golang.org/x/crypto/@v/v0.1.0.mod) = UyMpuLIbGJweFmNIgx2ltu2Mx8mCUJOmvjEM7M0m6MI= SHA256 (go_modules/golang.org/x/crypto/@v/v0.24.0.mod) = TfsA4zw5LLQjnS/FtlBpqR3vs7YZC7i5dyYmfuLnRfs= SHA256 (go_modules/golang.org/x/crypto/@v/v0.24.0.zip) = eFO1CX3q4N6H8TYaDGPQHwm/QajiD3AzOIQmqWGqnTg= SHA256 (go_modules/golang.org/x/mod/@v/v0.18.0.mod) = XErAMQolMwdXA5zPOpjnX+/by31ETd0EkjAAOkSUW94= SHA256 (go_modules/golang.org/x/mod/@v/v0.18.0.zip) = nGSj79pDySAUZ1NhsmIN4fKBXVmHWjefCzNhAY5b31k= +SHA256 (go_modules/golang.org/x/mod/@v/v0.9.0.mod) = YkVnRZxumUesSr3gtwNO5h3Ltqk3P1lwCUwLs+gSGWQ= +SHA256 (go_modules/golang.org/x/net/@v/v0.21.0.mod) = Du8+n+f2aL5bTSTI8SUcbFAtEWiVPICBrJ3D85nGTwY= SHA256 (go_modules/golang.org/x/net/@v/v0.26.0.mod) = 82mj44SGDykPhwGlhZt2CTrof6JdWHyMnIFqLC40p5w= SHA256 (go_modules/golang.org/x/net/@v/v0.26.0.zip) = PqkMFHQiacfB1SF7wePPWKcVUuVyT9QP+mm6UaEzrbA= SHA256 (go_modules/golang.org/x/sync/@v/v0.7.0.mod) = cA5dsA3SaqGaF9zl/FUkNtYPaMVgbIW4IfJMPWByoVE= SHA256 (go_modules/golang.org/x/sync/@v/v0.7.0.zip) = ILAQhSQOZhv/x/WTg/IbkPES1ml4QiDG5ZyAEkMhbSI= +SHA256 (go_modules/golang.org/x/sys/@v/v0.0.0-20220722155257-8c9f86f7a55f.mod) = 8DMzMJb+GY8xUd7tk/LeunTlC7/nc5E0BFvDt85KUCQ= +SHA256 (go_modules/golang.org/x/sys/@v/v0.1.0.mod) = 8DMzMJb+GY8xUd7tk/LeunTlC7/nc5E0BFvDt85KUCQ= SHA256 (go_modules/golang.org/x/sys/@v/v0.21.0.mod) = 0iezJfYh9OvijTm6dz6pm4cPOTt8CcNFksNlsW3VYN4= SHA256 (go_modules/golang.org/x/sys/@v/v0.21.0.zip) = JYj053yDd0vG8WjoWU8ty9IcHSaEmod/fmoNFROS5zU= SHA256 (go_modules/golang.org/x/telemetry/@v/v0.0.0-20240521205824-bda55230c457.mod) = txKIwdA6Q0+OoW7agOTdsHM8vdTtmW9KtmFv1dv3arM= @@ -25,9 +30,10 @@ SHA256 (go_modules/golang.org/x/term/@v/ SHA256 (go_modules/golang.org/x/term/@v/v0.21.0.zip) = O6WcXJKcUm4L8BZpbbj/7DE7Q4dkKGd+zaQZgxKm9pY= SHA256 (go_modules/golang.org/x/text/@v/v0.16.0.mod) = ChicdviH/nAsHxkZtDLcIejiMbXDI6N6Cz9yMB6QZsU= SHA256 (go_modules/golang.org/x/text/@v/v0.16.0.zip) = m3wFdciUIkvH+F36LvsO+T19VK6WLNlcjekM7LQH3pQ= +SHA256 (go_modules/golang.org/x/tools/@v/v0.1.12.mod) = KouTZYmPCCL6zmW6CJoTU+aKZdNC8wDKMXzOzN5kIfM= SHA256 (go_modules/golang.org/x/tools/@v/v0.22.0.mod) = cf0XssEb8eaLYH/TgnrjtX2H7PRxsFMjic+iCIsv6zo= SHA256 (go_modules/golang.org/x/tools/@v/v0.22.0.zip) = bBLNQZ2ZcpD+u0QWmNDlLKtacb6VmsfE3QI/hrLQHR4= -SIZE (age-v1.2.0.zip) = 233036 +SIZE (age-v1.2.1.zip) = 234143 SIZE (go_modules/c2sp.org/!c!c!t!v/age/@v/v0.0.0-20240306222714-3ec4d716e805.mod) = 115 SIZE (go_modules/c2sp.org/!c!c!t!v/age/@v/v0.0.0-20240306222714-3ec4d716e805.zip) = 1536469 SIZE (go_modules/filippo.io/edwards25519/@v/v1.1.0.mod) = 40 @@ -38,14 +44,19 @@ SIZE (go_modules/github.com/rogpeppe/go- SIZE (go_modules/github.com/rogpeppe/go-internal/@v/v1.12.0.zip) = 190596 SIZE (go_modules/github.com/yuin/goldmark/@v/v1.4.13.mod) = 41 SIZE (go_modules/github.com/yuin/goldmark/@v/v1.4.13.zip) = 229017 +SIZE (go_modules/golang.org/x/crypto/@v/v0.1.0.mod) = 171 SIZE (go_modules/golang.org/x/crypto/@v/v0.24.0.mod) = 190 SIZE (go_modules/golang.org/x/crypto/@v/v0.24.0.zip) = 1803483 SIZE (go_modules/golang.org/x/mod/@v/v0.18.0.mod) = 84 SIZE (go_modules/golang.org/x/mod/@v/v0.18.0.zip) = 166237 +SIZE (go_modules/golang.org/x/mod/@v/v0.9.0.mod) = 84 +SIZE (go_modules/golang.org/x/net/@v/v0.21.0.mod) = 155 SIZE (go_modules/golang.org/x/net/@v/v0.26.0.mod) = 155 SIZE (go_modules/golang.org/x/net/@v/v0.26.0.zip) = 1836588 SIZE (go_modules/golang.org/x/sync/@v/v0.7.0.mod) = 34 SIZE (go_modules/golang.org/x/sync/@v/v0.7.0.zip) = 26990 +SIZE (go_modules/golang.org/x/sys/@v/v0.0.0-20220722155257-8c9f86f7a55f.mod) = 33 +SIZE (go_modules/golang.org/x/sys/@v/v0.1.0.mod) = 33 SIZE (go_modules/golang.org/x/sys/@v/v0.21.0.mod) = 33 SIZE (go_modules/golang.org/x/sys/@v/v0.21.0.zip) = 1957330 SIZE (go_modules/golang.org/x/telemetry/@v/v0.0.0-20240521205824-bda55230c457.mod) = 138 @@ -54,5 +65,6 @@ SIZE (go_modules/golang.org/x/term/@v/v0 SIZE (go_modules/golang.org/x/term/@v/v0.21.0.zip) = 19883 SIZE (go_modules/golang.org/x/text/@v/v0.16.0.mod) = 220 SIZE (go_modules/golang.org/x/text/@v/v0.16.0.zip) = 9235305 +SIZE (go_modules/golang.org/x/tools/@v/v0.1.12.mod) = 327 SIZE (go_modules/golang.org/x/tools/@v/v0.22.0.mod) = 339 SIZE (go_modules/golang.org/x/tools/@v/v0.22.0.zip) = 3175435 Index: modules.inc =================================================================== RCS file: /cvs/ports/security/age/modules.inc,v retrieving revision 1.5 diff -u -p -r1.5 modules.inc --- modules.inc 20 Jun 2024 19:01:58 -0000 1.5 +++ modules.inc 18 Dec 2024 18:06:03 -0000 @@ -15,9 +15,10 @@ MODGO_MODULES = \ golang.org/x/tools v0.22.0 MODGO_MODFILES = \ - golang.org/x/crypto v0.24.0 \ - golang.org/x/mod v0.18.0 \ - golang.org/x/net v0.26.0 \ - golang.org/x/sys v0.21.0 \ - golang.org/x/tools v0.22.0 + golang.org/x/crypto v0.1.0 \ + golang.org/x/mod v0.9.0 \ + golang.org/x/net v0.21.0 \ + golang.org/x/sys v0.0.0-20220722155257-8c9f86f7a55f \ + golang.org/x/sys v0.1.0 \ + golang.org/x/tools v0.1.12