773,247 commits found in 93 milliseconds
www/rt50: Update to 5.0.10
This release fixes the following vulnerabilities:
CVE-2026-44231
CVE-2026-41075
CVE-2026-41076
CVE-2026-6841
CVE-2026-44227
CVE-2026-44230
CVE-2026-44229
CVE-2026-41073
Changelog: https://github.com/bestpractical/rt/releases/tag/rt-5.0.10
(cherry picked from commit c9eb2148d0e97027d1cf79f79c33f416641c5924 )
www/rt50: Update to 5.0.10
This release fixes the following vulnerabilities:
CVE-2026-44231
CVE-2026-41075
CVE-2026-41076
CVE-2026-6841
CVE-2026-44227
CVE-2026-44230
CVE-2026-44229
CVE-2026-41073
Changelog: https://github.com/bestpractical/rt/releases/tag/rt-5.0.10
misc/unclutter: Take maintainership
Add LICENSE and CONFLICTS_INSTALL.
PR: 295408
Approved by: fluffy (mentor)
graphics/zathura-pdf-mupdf: Update to 2026.05.10
https://pwmt.org/projects/zathura-pdf-mupdf/changelog/2026.05.10/index.html
PR: 295461
Approved by: uzsolt (maintainer)
Approved by: fluffy (mentor)
graphics/zathura: Update to 2026.05.20
Remove the indentation from pkg-message.
https://pwmt.org/projects/zathura/changelog/2026.05.20/index.html
PR: 295462
Approved by: quentin.stievenart at gmail.com (maintainer)
Approved by: fluffy (mentor)
java/jad: Mark DEPRECATED
This is a version that is over 25 years old and has multiple vulnerabilities.
https://www.cve.org/CVERecord?id=CVE-2016-20049
https://www.cve.org/CVERecord?id=CVE-2017-20227
PR: 295464
Approved by: ale (maintainer)
Approved by: fluffy (mentor)
net/rsync: update 3.4.2 -> 3.4.3
Changelog: https://download.samba.org/pub/rsync/NEWS#3.4.3
In addition to the six CVE fixes, this release adds defence-in-depth
hardening on several adjacent paths.
Other changes:
- Fixed a regression introduced by the 3.4.0 secure_relative_open() CVE fix
- secure_relative_open() now uses openat2(O_RESOLVE_BENEATH) on FreeBSD 13+
Security: CVE-2026-29518
Security: CVE-2026-43617
Security: CVE-2026-43618
Security: CVE-2026-43619
Security: CVE-2026-43620
Security: CVE-2026-45232
(cherry picked from commit f4f3b3e9632f321d690ba950e9baa79dabad7275 )
graphics/openxr: Update 1.1.59 => 1.1.60
Changelog:
https://github.com/KhronosGroup/OpenXR-SDK/releases/tag/release-1.1.60
Reported by: portscout
Sponsored by: UNIS Labs
net/rsync: update 3.4.1 -> 3.4.2
Changelog: https://download.samba.org/pub/rsync/NEWS#3.4.2
Major changes:
- Fixed a signed integer overflow in the PROXY protocol v2 header parser
- Fixed an invalid access to the files array
- Reject negative token values in the compressed-stream token decoder
- Fixed the element count passed to the xattr qsort()
- Fixed a buffer underflow in clean_fname()
- Fixed an uninitialized mul_one in the AVX2 get_checksum1 path (undefined behaviour)
- Fixed an uninitialized buf1 on the first call to get_checksum2() in the MD4 path
- Zero all new memory from internal allocations
- Removed support for the unmaintained rsync-patches archive
Port changes:
- Remove File system flags support (--fileflags)
PR: 295044
[3 lines not shown ] net/rsync: revert to single package without Python dependency
Restore the previous setup with a single net/rsync package that includes
the rrsync script but does not depend on Python.
Users who require the rrsync script must install Python separately,
as indicated in the install message.
Bump PORTREVISION
This reverts commit fc42790ae011acedf0195c7d31b1cf63b8c02155 .
This reverts commit f02bc3be718072b75bd291f81f66b7f15865f535 .
PR: 286073
(cherry picked from commit b350a4db575c9bea83ec5d7028066aa7bf91a9bb )
filesystems/libfsfat: fix build with NLS turned off
PR: 295468
filesystems/libfsext: fix build with NLS turned off
PR: 295468
security/vuxml: Document net/rsync vulnerability
- CVE-2026-29518
- CVE-2026-43617
- CVE-2026-43618
- CVE-2026-43619
- CVE-2026-43620
- CVE-2026-45232
net/rsync: update 3.4.2 -> 3.4.3
Changelog: https://download.samba.org/pub/rsync/NEWS#3.4.3
In addition to the six CVE fixes, this release adds defence-in-depth
hardening on several adjacent paths.
Other changes:
- Fixed a regression introduced by the 3.4.0 secure_relative_open() CVE fix
- secure_relative_open() now uses openat2(O_RESOLVE_BENEATH) on FreeBSD 13+
Security: CVE-2026-29518
Security: CVE-2026-43617
Security: CVE-2026-43618
Security: CVE-2026-43619
Security: CVE-2026-43620
Security: CVE-2026-45232
misc/comfyui: update 0.21.1 → 0.22.0
misc/py-comfyui-workflow-templates: update 0.9.77 → 0.9.79
misc/py-comfyui-workflow-templates-media-other: update 0.3.199 → 0.3.201
misc/py-comfyui-workflow-templates-media-image: update 0.3.139 → 0.3.140
misc/py-comfyui-workflow-templates-media-api: update 0.3.76 → 0.3.77
misc/py-comfyui-workflow-templates-core: update 0.3.233 → 0.3.235
misc/antigravity-cli: Fix typos and other cosmetic changes
databases/duckdb: Add missing patch
devel/folly: broken on aarch64
misc/antigravity-cli: Add pkg-message; Improve pkg-descr; Remove LICENSE
devel/concurrentqueue: update 1.0.4 → 1.0.5
audio/bangr-lv2: Fix build on 16
Reported by: fallout
FreeBSD /ports 39c0b38 — audio/boops-lv2/files patch-src_Airwindows_Galactic.cpp patch-src_Airwindows_XRegion.cpp audio/boops-lv2: Fix build on 16
FreeBSD /ports 05076d9 — databases/duckdb distinfo Makefile, databases/py-duckdb distinfo Makefile databases/{,py-}duckdb: update 1.5.2 → 1.5.3
misc/edflib: update 1.24 → 1.27
databases/p5-DBIx-SearchBuilder: Update to 1.85
(cherry picked from commit 860193b8cab8521e88100c4a40b6c43eed96e1c6 )