From owner-freebsd-questions@FreeBSD.ORG Wed Jan 21 19:27:17 2015 Return-Path: Delivered-To: freebsd-questions@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [8.8.178.115]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by hub.freebsd.org (Postfix) with ESMTPS id 3A81793D for ; Wed, 21 Jan 2015 19:27:17 +0000 (UTC) Received: from mail5.networktest.com (mail5.networktest.com [204.109.60.142]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (Client did not present a certificate) by mx1.freebsd.org (Postfix) with ESMTPS id 133A2F7 for ; Wed, 21 Jan 2015 19:27:16 +0000 (UTC) Received: from localhost (localhost [127.0.0.1]) by mail5.networktest.com (Postfix) with ESMTP id D65D12FCE46 for ; Wed, 21 Jan 2015 11:17:23 -0800 (PST) Received: from mail5.networktest.com ([127.0.0.1]) by localhost (mail5.networktest.com [127.0.0.1]) (maiad, port 10024) with ESMTP id 43323-02 for ; Wed, 21 Jan 2015 11:17:23 -0800 (PST) Received: from dhcp130.eng.networktest.com (ns.networktest.com [12.20.174.98]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) (Authenticated sender: dnewman@networktest.com) by mail5.networktest.com (Postfix) with ESMTPSA id 9B5DA2FCE43 for ; Wed, 21 Jan 2015 11:17:23 -0800 (PST) Message-ID: <54BFFB43.7060208@networktest.com> Date: Wed, 21 Jan 2015 11:17:23 -0800 From: David Newman User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.10; rv:31.0) Gecko/20100101 Thunderbird/31.4.0 MIME-Version: 1.0 To: freebsd-questions@freebsd.org Subject: frequency of pkg updates Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: 8bit X-BeenThere: freebsd-questions@freebsd.org X-Mailman-Version: 2.1.18-1 Precedence: list List-Id: User questions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Wed, 21 Jan 2015 19:27:17 -0000 How often is the FreeBSD pkg repository updated? Asking because 'sudo pkg audit' sometimes shows vulnerabilities in one or more packages, yet 'sudo pkg update && sudo pkg upgrade -f ' offers only to reinstall the vulnerable version. An updated pkg can take days to show up. The ports tree is updated much faster, but I'm trying to move to pkg where possible. (Yes, I know I could run poudriere and create a pkg repository, but I'm asking here about FreeBSD's pkg system.) This is on 10.1-RELEASE-p4 amd64. Thanks! dn