The ports tree does not undergo an audit -- therefore, an upgrade of all your packages runs the risk of introducing new problems, some of which may have security implications.
Of course, some of the updates made to the ports tree have been to fix known problems.
An informed admin will subscribe to applicable mailing lists, such as ports-security@, ports-bugs@, ports-changes@, and ports@.
|