[Midnightbsd-cvs] [MidnightBSD/mports] 370d79: security/clamav: update to 1.5.4 (#695)

Lucas Holt noreply at github.com
Fri Aug 7 13:03:01 EDT 2026


  Branch: refs/heads/master
  Home:   https://github.com/MidnightBSD/mports
  Commit: 370d79d8a0377e627270fd14017305a83be21d6f
      https://github.com/MidnightBSD/mports/commit/370d79d8a0377e627270fd14017305a83be21d6f
  Author: Lucas Holt <luke at foolishgames.com>
  Date:   2026-08-07 (Fri, 07 Aug 2026)

  Changed paths:
    M security/clamav/Makefile
    M security/clamav/distinfo
    M security/clamav/pkg-plist

  Log Message:
  -----------
  security/clamav: update to 1.5.4 (#695)

## Summary

- update ClamAV regular release from 1.5.2 to 1.5.4
- regenerate distinfo
- update generated documentation plist entries
- address CVE-2026-20337, CVE-2026-20338, CVE-2026-20339,
CVE-2026-20345, CVE-2026-20346, CVE-2026-20347, CVE-2026-20348, and
CVE-2025-8088

Upstream advisory:
https://blog.clamav.net/2026/08/clamav-154-and-146-security-patch.html

## Validation

- `bmake makesum`
- `bmake patch`
- `bmake check-license`
- `bmake`
- `bmake fake`
- `bmake package`
- package created: `clamav-1.5.4,1.mport`
- `portlint -C`: 0 fatal errors, 6 pre-existing warnings
- `bmake test` is intentionally disabled by the existing `NO_TEST=yes`
setting

The libclamav and libfreshclam shared-library versions are unchanged, so
dependent port revisions do not need bumps.

## Summary by Sourcery

Update the ClamAV port to the 1.5.4 regular release and refresh
associated packaging metadata.

Bug Fixes:
- Pull in upstream security fixes for multiple CVEs via the 1.5.4 ClamAV
release.

Enhancements:
- Regenerate distinfo and update packaging plist entries to match the
new ClamAV release artifacts.

Signed-off-by: Lucas Holt <luke at foolishgames.com>



To unsubscribe from these emails, change your notification settings at https://github.com/MidnightBSD/mports/settings/notifications


More information about the Midnightbsd-cvs mailing list