Subject: vulnerabilities not being checked at package compile time
To: None <tech-pkg@netbsd.org>
From: Steven M. Bellovin <smb@cs.columbia.edu>
List: tech-pkg
Date: 09/01/2005 10:48:06
I'm running audit-packages 1.38, which seems to put the vulnerability
list in /usr/pkg/share/pkg-vulnerabilities.  However, 'make' is
checking /usr/pkgsrc/distfiles/pkg-vulnerabilities.  I have up-to-date
pkgsrc (from the head), up-to-date audit-packages, and up-to-date
pkg_install.  Am I doing something wrong, or should I send-pr?
(This is on -current from 13 August.)