[MacPorts] #16911: git-core requiring macports' ssh on leopard, openssh security concern

MacPorts noreply at macports.org
Thu Nov 13 04:05:34 PST 2008


#16911: git-core requiring macports' ssh on leopard, openssh security concern
---------------------------------+------------------------------------------
  Reporter:  bcbarnes at gmail.com  |       Owner:  macports-tickets at lists.macosforge.org
      Type:  defect              |      Status:  closed                               
  Priority:  Normal              |   Milestone:  Port Bugs                            
 Component:  ports               |     Version:  1.6.0                                
Resolution:  fixed               |    Keywords:                                       
      Port:  git-core            |  
---------------------------------+------------------------------------------

Comment(by ryandesign at macports.org):

 Replying to [comment:14 bcbarnes@…]:
 > Ah, if it's not entirely obvious by now, my concern I suppose has more
 to do with the openssh port than the git-core port.  Perhaps the openssh
 maintainer should be cc'd on this if he is not already.  Removing the
 dependency for the git-core port mitigates the problem for me right now
 (and I'm entirely happy with that change), but anyone installing openssh
 via macports is subjected to my security concerns talked about above.  I
 do not know what other ports, if any, require the openssh port as a
 dependency.
 openssh has no maintainer, so anybody should feel free to make appropriate
 changes to it. sshfs and dsh declare a port dependency on openssh, while
 dsocks, scponly and rsnapshot only declare a binary dependency on ssh,
 falling back to the openssh port if necessary.

-- 
Ticket URL: <http://trac.macports.org/ticket/16911#comment:16>
MacPorts <http://www.macports.org/>
Ports system for Mac OS


More information about the macports-tickets mailing list