Skip site navigation (1)Skip section navigation (2)
Date:      Wed, 2 Jun 2010 17:55:58 +1000
From:      Peter Jeremy <peter@vk2pj.dyndns.org>
To:        Sylvio =?iso-8859-1?Q?C=E9sar?= <scjamorim@bsd.com.br>
Cc:        cvs-ports@freebsd.org, cvs-all@freebsd.org, ports-committers@freebsd.org
Subject:   Re: cvs commit: ports/math/dislin distinfo-6.0 distinfo-7.0 pkg-plist
Message-ID:  <20100602075558.GB41763@server.vk2pj.dyndns.org>
In-Reply-To: <AANLkTikIfjssGcH3trIW1wIrypmpy_2XOqESmxXaL2rg@mail.gmail.com>
References:  <201005291622.o4TGML6m063089@repoman.freebsd.org> <20100529203638.GA56806@FreeBSD.org> <AANLkTikIfjssGcH3trIW1wIrypmpy_2XOqESmxXaL2rg@mail.gmail.com>

next in thread | previous in thread | raw e-mail | index | archive | help

--xXmbgvnjoT4axfJE
Content-Type: text/plain; charset=iso-8859-1
Content-Disposition: inline
Content-Transfer-Encoding: quoted-printable

On 2010-May-29 19:38:20 -0300, Sylvio C=E9sar <scjamorim@bsd.com.br> wrote:
>2010/5/29 Alexey Dokuchaev <danfe@freebsd.org>:
>> On Sat, May 29, 2010 at 04:22:21PM +0000, Sylvio Cesar Teixeira wrote:
>>> sylvio =A0 =A0 =A02010-05-29 16:22:21 UTC
>>>
>>> =A0 FreeBSD ports repository
>>>
>>> =A0 Modified files:
>>> =A0 =A0 math/dislin =A0 =A0 =A0 =A0 =A0distinfo-6.0 distinfo-7.0 pkg-pl=
ist
>>> =A0 Log:
>>> =A0 - Tarball rerolled
>>
>> I've noticed several commits similar to this one about with port; which
>> brings us to the following questions:
>>
>> - Did you verified the changes?
>
>Yes, the pkg-plist update too to this port.

I think you may have misunderstood the issue.  The Project's concern
with rerolled distfiles is that they may contain unuathorised (and
potentially malicious) changes to the content.  In order to guard
against that, it is expected that before committing an update to the
distinfo file, the committer will diff both the old and new distfiles
and verify that any changes are not harmful.

--=20
Peter Jeremy

--xXmbgvnjoT4axfJE
Content-Type: application/pgp-signature
Content-Disposition: inline

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2.0.14 (FreeBSD)

iEYEARECAAYFAkwGDo4ACgkQ/opHv/APuIcJ6ACcC3nOUxUEuwk8YPGeCcvHfhY/
7vcAn3O+NcEOYFkzYtRmfQ1+QvoG8J54
=mDg/
-----END PGP SIGNATURE-----

--xXmbgvnjoT4axfJE--



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?20100602075558.GB41763>