FreeBSD Ports Currently Frozen Due To A Very Large Commit

Written by Michael Larabel in BSD on 23 July 2026 at 12:25 PM EDT. 13 Comments
BSD
The FreeBSD project issued a statement today over the FreeBSD Ports repository having been frozen for the past two days. The freeze is not due to a malicious compromise but rather a very large commit breaking things.

Since 21 July the FreeBSD Ports repository has been frozen and as of writing remains that way. The status of the FreeBSD Ports freeze is being communicated via this web page. A mailing list post elaborates on the freeze, which comes down to a 150MB file having been committed and that breaking mirroring to the likes of GitHub that has a 100MB hard size limit.
"You may have noticed that the ports repository has been frozen for nearly 24 hours now, at the time of writing. Our statement regarding the situation and next steps follows.

A 150MB binary file was recently committed to the ports tree and, as a result, core@ made the decision to implement a temporary freeze of the ports tree in order to implement some clean up efforts. The commit in question severed our ports tree mirroring to github.com due to their filesize hard limit of 100MB, and introduced a blob of questionable licensing into the repository history.

Given the importance of github.com mirroring to our community, we are actively taking steps to remove the offending commits and restore mirroring to the external services. There is no concern that the ports tree has been compromised. The freeze was entirely intended to limit the number of commits that will need to be re-written in order to issue a corrected state.

It is important to us that we provide a reproducible and sustainable path for correcting this issue for the community and downstream consumers. As you're well-aware, correcting issues of this nature is not always as straightforward as
desired.

We are actively working on producing instructions which existing checkouts will need to follow to catch up with these corrections. To provide total transparency, we will also provide a procedure for verifying that the official repository changes enacted are limited to exactly the scope that we claim.

We are also implementing server-side hooks to prevent this from happening in the future.

Please stay tuned for additional updates from us, and thank you for your time."

Addressing this remains ongoing but at least it was not a malicious compromise, unlike the recent Arch Linux AUR fiasco.
Related News
About The Author

Michael Larabel is the principal author of Phoronix.com and founded the site in 2004 with a focus on enriching the Linux hardware experience. Michael has written more than 20,000 articles covering the state of Linux hardware support, Linux performance, graphics drivers, and other topics. Michael is also the lead developer of the Phoronix Test Suite, Phoromatic, and OpenBenchmarking.org automated benchmarking software. He can be followed via Twitter, LinkedIn, or contacted via MichaelLarabel.com.

Popular News This Week