[MacPorts] #16911: git-core requiring macports' ssh on leopard, openssh security concern
MacPorts
noreply at macports.org
Thu Nov 13 04:05:34 PST 2008
#16911: git-core requiring macports' ssh on leopard, openssh security concern
---------------------------------+------------------------------------------
Reporter: bcbarnes at gmail.com | Owner: macports-tickets at lists.macosforge.org
Type: defect | Status: closed
Priority: Normal | Milestone: Port Bugs
Component: ports | Version: 1.6.0
Resolution: fixed | Keywords:
Port: git-core |
---------------------------------+------------------------------------------
Comment(by ryandesign at macports.org):
Replying to [comment:14 bcbarnes@…]:
> Ah, if it's not entirely obvious by now, my concern I suppose has more
to do with the openssh port than the git-core port. Perhaps the openssh
maintainer should be cc'd on this if he is not already. Removing the
dependency for the git-core port mitigates the problem for me right now
(and I'm entirely happy with that change), but anyone installing openssh
via macports is subjected to my security concerns talked about above. I
do not know what other ports, if any, require the openssh port as a
dependency.
openssh has no maintainer, so anybody should feel free to make appropriate
changes to it. sshfs and dsh declare a port dependency on openssh, while
dsocks, scponly and rsnapshot only declare a binary dependency on ssh,
falling back to the openssh port if necessary.
--
Ticket URL: <http://trac.macports.org/ticket/16911#comment:16>
MacPorts <http://www.macports.org/>
Ports system for Mac OS
More information about the macports-tickets
mailing list