notbugAs an Amazon Associate I earn from qualifying purchases.
Want a good read? Try FreeBSD Mastery: Jails (IT Mastery Book 15)
All times are UTC
Ukraine
The safest procedure: change your FreshPorts password. Anything you had set before Friday March 24 2023 09:49:20 UTC should be changed. You can read more here: SQL inejection issues fixed and FreshSource code fixes Sorry about the extra work for you.
All known SQL injection issues patched. There is no evidence it was exploited. That doesn’t mean it wasn’t. Please change your password.
non port: security/bastillion/Makefile
SVNWeb

Number of commits found: 20

Wed, 7 Sep 2022
[ 21:10 Stefan Eßer (se) search for other commits by this committer ]    commit hash:b7f05445c00f2625aa19b4154ebcbce5ed2daa52  commit hash:b7f05445c00f2625aa19b4154ebcbce5ed2daa52  commit hash:b7f05445c00f2625aa19b4154ebcbce5ed2daa52  b7f0544  (Only the first 10 of 27931 ports in this commit are shown above. View all ports for this commit)
Add WWW entries to port Makefiles

It has been common practice to have one or more URLs at the end of the
ports' pkg-descr files, one per line and prefixed with "WWW:". These
URLs should point at a project website or other relevant resources.

Access to these URLs required processing of the pkg-descr files, and
they have often become stale over time. If more than one such URL was
present in a pkg-descr file, only the first one was tarnsfered into
the port INDEX, but for many ports only the last line did contain the
port specific URL to further information.

There have been several proposals to make a project URL available as
a macro in the ports' Makefiles, over time.
(Only the first 15 lines of the commit message are shown above View all of this commit message)
Thu, 21 Jul 2022
[ 08:15 Tobias C. Berner (tcberner) search for other commits by this committer ]    commit hash:419b0eeeb16b2ff6e4cee38805cf3c5d37cfd6cd  commit hash:419b0eeeb16b2ff6e4cee38805cf3c5d37cfd6cd  commit hash:419b0eeeb16b2ff6e4cee38805cf3c5d37cfd6cd  419b0ee 
cleanup: remove remaining occurrences of $FreeBSD$
Mon, 14 Feb 2022
[ 08:22 Alexander Leidinger (netchild) search for other commits by this committer ]    commit hash:309b41bfc9633881b6ada1307e702665e370c28a  commit hash:309b41bfc9633881b6ada1307e702665e370c28a  commit hash:309b41bfc9633881b6ada1307e702665e370c28a  309b41b 
security/bastillion: update to 3.14.0
Mon, 10 Jan 2022
[ 10:58 Alexander Leidinger (netchild) search for other commits by this committer ]    commit hash:c527917cbbc6cd220af415f1661109ca42bc6d41  commit hash:c527917cbbc6cd220af415f1661109ca42bc6d41  commit hash:c527917cbbc6cd220af415f1661109ca42bc6d41  c527917 
security/bastillion: update to 3.13.00

Contains updates to h2 and log4j.
Tue, 4 Jan 2022
[ 10:37 Alexander Leidinger (netchild) search for other commits by this committer ]    commit hash:1a85399f16362dd0d288311a688d8cca49a8bc93  commit hash:1a85399f16362dd0d288311a688d8cca49a8bc93  commit hash:1a85399f16362dd0d288311a688d8cca49a8bc93  1a85399 
security/bastillion: update to 3.12.02

Release notes at
https://github.com/bastillion-io/Bastillion/releases/tag/v3.12.02
Thu, 23 Dec 2021
[ 14:52 Alexander Leidinger (netchild) search for other commits by this committer ]    commit hash:85fc17bba80bb26d659c469a8ec5bd3b780d85b0  commit hash:85fc17bba80bb26d659c469a8ec5bd3b780d85b0  commit hash:85fc17bba80bb26d659c469a8ec5bd3b780d85b0  85fc17b 
security/bastillion: update to 3.12.00

This update contains an incompatible DB change, please read UPDATING
*before* updating.
Fri, 17 Dec 2021
[ 07:42 Alexander Leidinger (netchild) search for other commits by this committer ]    commit hash:94d2bb62d559d10849f6e0f24f937c6d76825737  commit hash:94d2bb62d559d10849f6e0f24f937c6d76825737  commit hash:94d2bb62d559d10849f6e0f24f937c6d76825737  94d2bb6 
security/bastillion: update to 3.11.01 (log4j 2.16)

Revert my previous log4j fix (disable JNDI lookups via env variable),
the update to 3.11.01 contains the fixed log4j 2.16.
Tue, 14 Dec 2021
[ 12:46 Alexander Leidinger (netchild) search for other commits by this committer ]    commit hash:ef15683d48c1f829a6b3c81a240fb884e9f9d2e2  commit hash:ef15683d48c1f829a6b3c81a240fb884e9f9d2e2  commit hash:ef15683d48c1f829a6b3c81a240fb884e9f9d2e2  ef15683 
security/bastillion: fix log4j vulnerablity

Disable format msg lookup via shell variable on startup.

Security:	CVE-2021-44228
Wed, 7 Apr 2021
[ 08:09 Mathieu Arnold (mat) search for other commits by this committer ]    commit hash:cf118ccf875508b9a1c570044c93cfcc82bd455c  commit hash:cf118ccf875508b9a1c570044c93cfcc82bd455c  commit hash:cf118ccf875508b9a1c570044c93cfcc82bd455c  cf118cc  (Only the first 10 of 8873 ports in this commit are shown above. View all ports for this commit)
One more small cleanup, forgotten yesterday.
Reported by:	lwhsu
Tue, 6 Apr 2021
[ 14:31 Mathieu Arnold (mat) search for other commits by this committer ]    commit hash:305f148f482daf30dcf728039d03d019f88344eb  commit hash:305f148f482daf30dcf728039d03d019f88344eb  commit hash:305f148f482daf30dcf728039d03d019f88344eb  305f148  (Only the first 10 of 29333 ports in this commit are shown above. View all ports for this commit)
Remove # $FreeBSD$ from Makefiles.
Sun, 24 May 2020
[ 07:37 netchild search for other commits by this committer ] Original commit   Revision:536365
Update to 3.10.00.
This fixes some potential XSS in the included jquery, but there is no
information if bastillion is vulnerable in some place or not.

As all the action in bastillion happens after authentication, and
is limited to what you enter yourself, it looks like the impact
or attack surface of the jquery XSS on bastillion is low.

ChangeLog:	https://github.com/bastillion-io/Bastillion/releases/tag/v3.10.00
CVE:		CVE-2020-11022
CVE:		CVE-2020-11023
Fri, 13 Dec 2019
[ 10:12 netchild search for other commits by this committer ] Original commit   Revision:520010
Update to 3.09.00:
 - removed license key requirement
Thu, 3 Oct 2019
[ 17:22 glewis search for other commits by this committer ] Original commit   Revision:513677
Remove references to EoL'ed Java versions

* Java 9 and 10 are EoL'ed upstream and the ports for them are scheduled
  for deletion, so switch the version specification here to 11+.

PR:		241022
Approved by:	netchild@
Sponsored by:	The FreeBSD Foundation
Thu, 26 Sep 2019
[ 08:46 netchild search for other commits by this committer ] Original commit   Revision:512884
Update to bugfix release 3.08.01.
Wed, 11 Sep 2019
[ 17:53 netchild search for other commits by this committer ] Original commit   Revision:511830
 - Add update tool.
 - Add update instructions (datastore needs to be updated).
 - Convert pkg-message to UCL format.
 - Rework plist generation target.
Tue, 10 Sep 2019
[ 11:50 netchild search for other commits by this committer ] Original commit   Revision:511756
Fix build by actually committing the change in the plist...
Mon, 9 Sep 2019
[ 20:00 netchild search for other commits by this committer ] Original commit   Revision:511696
Update to 3.08.
Sat, 17 Aug 2019
[ 20:13 netchild search for other commits by this committer ] Original commit   Revision:509166
Fix URL.

Noticed by:	pkubaj
Fri, 16 Aug 2019
[ 06:42 netchild search for other commits by this committer ] Original commit   Revision:509065
Improvements to the port MAkefile, no package changes.

Suggested by:	mat
Wed, 14 Aug 2019
[ 20:36 netchild search for other commits by this committer ] Original commit   Revision:508967 (Only the first 10 of 11 ports in this commit are shown above. View all ports for this commit)
Add new port "Bastillion".

Bastillion is an open-source web-based SSH console that centrally manages
administrative access to systems.

A bastion host for administrators with features that promote infrastructure
security, including key management and auditing.

Number of commits found: 20