NetBSD/src 03gDEp7sys/arch/sparc64/sparc64 autoconf.c

   sun4v: try to use the hypervisor interrupt api versions in descending order
VersionDeltaFile
1.253+15-6sys/arch/sparc64/sparc64/autoconf.c
+15-61 files

NetBSD/pkgsrc 1egmevJdevel/guile30-slib Makefile

   devel/guile30-slib: Catch up with slib version in variable

   This is kind of pointless, but choose consistency over thinking about
   the real problem for now.
VersionDeltaFile
1.3+2-2devel/guile30-slib/Makefile
+2-21 files

NetBSD/pkgsrc tACBsTxdoc TODO CHANGES-2026

   doc: Updated www/privoxy to 4.2.0
VersionDeltaFile
1.27744+1-2doc/TODO
1.5261+2-1doc/CHANGES-2026
+3-32 files

NetBSD/pkgsrc-wip 20f5889privoxy Makefile PLIST, privoxy/patches patch-man_privoxy.8 patch-config

privoxy: remove, updated in pkgsrc
DeltaFile
+0-361privoxy/patches/patch-configure.in
+0-120privoxy/patches/patch-GNUmakefile.in
+0-103privoxy/PLIST
+0-99privoxy/Makefile
+0-75privoxy/patches/patch-config
+0-42privoxy/patches/patch-man_privoxy.8
+0-8008 files not shown
+2-92214 files

NetBSD/pkgsrc 1ClUROtwww/privoxy Makefile, www/privoxy/patches patch-tools_uagen.pl patch-man_privoxy.8

   privoxy: update to 4.2.0.

   Provided by Stepan Ipatov in pkgsrc-wip.

   Privoxy 4.2.0 fixes a couple of bugs and brings general improvements
   such as support for elliptic-curve keys.

   Two potential security problems have been reported and addressed.
VersionDeltaFile
1.1+361-0www/privoxy/patches/patch-configure.in
1.1+120-0www/privoxy/patches/patch-GNUmakefile.in
1.73+65-41www/privoxy/Makefile
1.1+75-0www/privoxy/patches/patch-config
1.1+42-0www/privoxy/patches/patch-man_privoxy.8
1.1+26-0www/privoxy/patches/patch-tools_uagen.pl
+689-418 files not shown
+757-5814 files

NetBSD/pkgsrc LX9Cu60doc CHANGES-2026

   doc: Updated lang/quickjs to 20260604nb1
VersionDeltaFile
1.5260+2-1doc/CHANGES-2026
+2-11 files

NetBSD/pkgsrc QgAda4elang/quickjs Makefile distinfo, lang/quickjs/patches patch-Makefile patch-quickjs.c

   quickjs: fix for NetBSD sparc

   https://github.com/quickjs-ng/quickjs/issues/1663

   From vom513 on pkgsrc-users.

   Bump PKGREVISION.

   Shorten DESCR while here, regen patches.
VersionDeltaFile
1.9+44-4lang/quickjs/patches/patch-quickjs.c
1.11+18-15lang/quickjs/patches/patch-Makefile
1.3+2-6lang/quickjs/DESCR
1.19+3-3lang/quickjs/distinfo
1.22+2-1lang/quickjs/Makefile
+69-295 files

NetBSD/pkgsrc MLhGfWrdoc CHANGES-2026

   doc: Updated devel/nss to 3.126.1
VersionDeltaFile
1.5259+2-1doc/CHANGES-2026
+2-11 files

NetBSD/pkgsrc KUiMYmndevel/nss Makefile distinfo

   nss: update to 3.126.1.

   Bug 2054719 - fix content type tag for CMS AuthEnvelopedData plaintext.
VersionDeltaFile
1.213+4-4devel/nss/distinfo
1.299+2-2devel/nss/Makefile
+6-62 files

NetBSD/pkgsrc-wip eb9b31bprivoxy distinfo, privoxy/patches patch-GNUmakefile.in patch-configure.in

www/privoxy: Update to 4.2.0

Improve detection of gethostbyaddr_r and gethostbyname_r by using
compile-time checks with implicit function declarations disabled.
DeltaFile
+290-0privoxy/patches/patch-configure.in
+3-3privoxy/patches/patch-GNUmakefile.in
+2-2privoxy/distinfo
+295-53 files

NetBSD/pkgsrc fjd2i8edoc TODO

   doc/TODO: SOGo update

   + SOGo-5.12.10, SOPE-5.12.10.
VersionDeltaFile
1.27743+3-3doc/TODO
+3-31 files

NetBSD/pkgsrc FTmR0U8doc CHANGES-2026

   doc: Updated www/php-ja-wordpress to 7.0.4
VersionDeltaFile
1.5258+2-1doc/CHANGES-2026
+2-11 files

NetBSD/pkgsrc W6ujdkrwww/php-ja-wordpress Makefile distinfo

   www/php-ja-wordpress: update to 7.0.4

   7.0.4 (2026-08-12)

   Security updates

   This release features several security fixes.  Because this is a security
   release, it is recommended that you update your sites immediately.

   The security team would like to thank the following people for responsibly
   reporting vulnerabilities, and allowing them to be fixed in this release:

   * An authenticated Author+ remote code execution issue via malicious file
     upload on sites that use Imagick and Ghostscript reported by the team at
     pwn.ai
VersionDeltaFile
1.32+4-4www/php-ja-wordpress/distinfo
1.35+2-2www/php-ja-wordpress/Makefile
+6-62 files

NetBSD/pkgsrc d0DN8Ntdoc CHANGES-2026

   doc: Updated www/wordpress to 7.0.4
VersionDeltaFile
1.5257+2-1doc/CHANGES-2026
+2-11 files

NetBSD/pkgsrc E9PaFJVwww/wordpress Makefile distinfo

   www/wordpress: update to 7.0.4

   7.0.4 (2026-08-12)

   Security updates

   This release features several security fixes.  Because this is a security
   release, it is recommended that you update your sites immediately.

   The security team would like to thank the following people for responsibly
   reporting vulnerabilities, and allowing them to be fixed in this release:

   * An authenticated Author+ remote code execution issue via malicious file
     upload on sites that use Imagick and Ghostscript reported by the team at
     pwn.ai
VersionDeltaFile
1.103+4-4www/wordpress/distinfo
1.122+2-2www/wordpress/Makefile
+6-62 files

NetBSD/pkgsrc HJhVDl3doc CHANGES-2026

   doc: Updated www/ruby-rack2 to 2.2.24
VersionDeltaFile
1.5256+2-1doc/CHANGES-2026
+2-11 files

NetBSD/pkgsrc 3HoI6pFwww/ruby-rack2 Makefile distinfo

   www/ruby-rack2: update to 2.2.24

   2.2.23 (2026-04-01)

   Security

   * CVE-2026-34763 Root directory disclosure via unescaped regex interpolation
     in Rack::Directory.

   * CVE-2026-34230 Avoid O(n^2) algorithm in Rack::Utils.select_best_encoding
     which could lead to denial of service.

   * CVE-2026-26961 Raise error for multipart requests with multiple boundary
     parameters.

   * CVE-2026-34786 Rack::Static header_rules bypass via URL-encoded path
     mismatch.

   * CVE-2026-34831 Content-Length mismatch in Rack::Files error responses.

    [19 lines not shown]
VersionDeltaFile
1.17+4-4www/ruby-rack2/distinfo
1.17+2-2www/ruby-rack2/Makefile
+6-62 files

NetBSD/pkgsrc fo4OhyUdoc CHANGES-2026

   doc: Updated www/ruby-rack to 3.2.7
VersionDeltaFile
1.5255+2-1doc/CHANGES-2026
+2-11 files

NetBSD/pkgsrc 3VjoZsUwww/ruby-rack Makefile distinfo

   www/ruby-rack: update to 3.2.7

   3.2.7 (2026-08-13)

   Fixed

   * Restore Ruby 2.4/2.5 compatibility.
VersionDeltaFile
1.56+4-4www/ruby-rack/distinfo
1.58+2-2www/ruby-rack/Makefile
+6-62 files

NetBSD/pkgsrc 1nLoWfYdoc CHANGES-2026

   Updated lang/python31[012], lang/py31[012]-html-docs
VersionDeltaFile
1.5254+7-1doc/CHANGES-2026
+7-11 files

NetBSD/pkgsrc 8ObfnDPlang/py312-html-docs Makefile distinfo, lang/python312 dist.mk distinfo

   python312 py312-html-docs: updated to 3.12.14

   3.12.14

   macOS
   gh-137586: Invoke osascript with absolute path in webbrowser and turtledemo.
   Tests
   gh-149776: Fix test_socket on Linux kernel 7.1 and newer: skip UDP Lite tests if it’s not supported. Patch by Victor Stinner.
   Security
   gh-155558: Update bundled libexpat to version 2.8.3 for the fix to CVE 2026-72522.
   gh-153030: Fixed quadratic complexity in incremental parsing of long unterminated constructs (such as tags or comments) in html.parser.HTMLParser, which could be exploited for a denial of service.
   gh-152674: The xml.etree.ElementTree.Element methods findall(), iterfind() and find() avoid quadratic behavior when using XPath index predicates ([1], [last()], [last()-N]) on XML documents with many same-tag siblings.
   gh-152216: Update bundled libexpat to version 2.8.2.
   gh-151987: The tarfile.TarFile.extract() method now applies the given filter when it extracts a link target from the archive as a fallback.
   gh-151981: In tarfile, seeking a stream now stops when end of the stream is reached.
   gh-151544: Modules/Setup.local is no longer used as a landmark to discover whether Python is running in a source tree, as it could potentially affect actual installs. The pybuilddir.txt file is now the sole indicator of running in a source tree.
   gh-151558: Fixed an vulnerability in the tarfile data and tar extraction filters where crafted archives could create a symlink pointing outside the destination directory. This was a bypass of CVE 2025-4330.
   gh-150599: Fix a possible stack buffer overflow in bz2 when a bz2.BZ2Decompressor is reused after a decompression error. The decompressor now becomes unusable after libbz2 reports an error.
   gh-150743: http.client now limits the number of chunked-response trailer lines it will read to 100, and the number of interim (1xx) responses it will skip to 100. A malicious or broken server could previously stream trailer lines or 100 Continue responses forever, hanging the client even when a socket timeout was in use. Reported by @YLChen-007 via GHSA-w4q2-g22w-6fr4.

    [31 lines not shown]
VersionDeltaFile
1.18+4-4lang/python312/distinfo
1.15+4-4lang/py312-html-docs/distinfo
1.15+2-2lang/python312/dist.mk
1.15+2-2lang/py312-html-docs/Makefile
+12-124 files

NetBSD/pkgsrc uK5mcbHlang/py311-html-docs Makefile distinfo, lang/python311 dist.mk distinfo

   python311 py311-html-docs: updated to 3.11.16

   3.11.16

   macOS
   gh-137586: Invoke osascript with absolute path in webbrowser and turtledemo.
   Tests
   gh-149776: Fix test_socket on Linux kernel 7.1 and newer: skip UDP Lite tests if it’s not supported. Patch by Victor Stinner.
   Security
   gh-155558: Update bundled libexpat to version 2.8.3 for the fix to CVE-2026-72522.
   gh-153030: Fixed quadratic complexity in incremental parsing of long unterminated constructs (such as tags or comments) in html.parser.HTMLParser, which could be exploited for a denial of service.
   gh-152674: The xml.etree.ElementTree.Element methods findall(), iterfind() and find() avoid quadratic behavior when using XPath index predicates ([1], [last()], [last()-N]) on XML documents with many same-tag siblings.
   gh-152216: Update bundled libexpat to version 2.8.2.
   gh-151987: The tarfile.TarFile.extract() method now applies the given filter when it extracts a link target from the archive as a fallback.
   gh-151981: In tarfile, seeking a stream now stops when end of the stream is reached.
   gh-151544: Modules/Setup.local is no longer used as a landmark to discover whether Python is running in a source tree, as it could potentially affect actual installs. The pybuilddir.txt file is now the sole indicator of running in a source tree.
   gh-151558: Fixed an vulnerability in the tarfile data and tar extraction filters where crafted archives could create a symlink pointing outside the destination directory. This was a bypass of CVE-2025-4330.
   gh-150599: Fix a possible stack buffer overflow in bz2 when a bz2.BZ2Decompressor is reused after a decompression error. The decompressor now becomes unusable after libbz2 reports an error.
   gh-150743: http.client now limits the number of chunked-response trailer lines it will read to 100, and the number of interim (1xx) responses it will skip to 100. A malicious or broken server could previously stream trailer lines or 100 Continue responses forever, hanging the client even when a socket timeout was in use. Reported by @YLChen-007 via GHSA-w4q2-g22w-6fr4.

    [28 lines not shown]
VersionDeltaFile
1.25+4-4lang/python311/distinfo
1.17+4-4lang/py311-html-docs/distinfo
1.17+2-2lang/python311/dist.mk
1.17+2-2lang/py311-html-docs/Makefile
+12-124 files

NetBSD/pkgsrc AaWUr7Hlang/py310-html-docs Makefile distinfo, lang/python310 dist.mk distinfo

   python310 py310-html-docs: updated to 3.10.21

   3.10.21

   macOS
   gh-137586: Invoke osascript with absolute path in webbrowser and turtledemo.
   Tests
   gh-149776: Fix test_socket on Linux kernel 7.1 and newer: skip UDP Lite tests if it’s not supported. Patch by Victor Stinner.
   Security
   gh-153030: Fixed quadratic complexity in incremental parsing of long unterminated constructs (such as tags or comments) in html.parser.HTMLParser, which could be exploited for a denial of service.
   gh-152674: The xml.etree.ElementTree.Element methods findall(), iterfind() and find() avoid quadratic behavior when using XPath index predicates ([1], [last()], [last()-N]) on XML documents with many same-tag siblings.
   gh-152216: Update bundled libexpat to version 2.8.2.
   gh-151987: The tarfile.TarFile.extract() method now applies the given filter when it extracts a link target from the archive as a fallback.
   gh-151981: In tarfile, seeking a stream now stops when end of the stream is reached.
   gh-151558: Fixed an vulnerability in the tarfile data and tar extraction filters where crafted archives could create a symlink pointing outside the destination directory. This was a bypass of CVE-2025-4330.
   gh-150599: Fix a possible stack buffer overflow in bz2 when a bz2.BZ2Decompressor is reused after a decompression error. The decompressor now becomes unusable after libbz2 reports an error.
   gh-150743: http.client now limits the number of chunked-response trailer lines it will read to 100, and the number of interim (1xx) responses it will skip to 100. A malicious or broken server could previously stream trailer lines or 100 Continue responses forever, hanging the client even when a socket timeout was in use. Reported by @YLChen-007 via GHSA-w4q2-g22w-6fr4.
   gh-149698: Update bundled libexpat to version 2.8.1 for the fix for CVE-2026-45186.
   gh-87451: The ftplib module’s undocumented ftpcp function no longer trusts the IPv4 address value returned from the source server in response to the PASV command by default, completing the fix for CVE-2021-4189. As with ftplib.FTP, the former behavior can be re-enabled by setting the trust_server_pasv_ipv4_address attribute on the source ftplib.FTP instance to True. Thanks to Qi Deng at Aurascape AI for the report.

    [23 lines not shown]
VersionDeltaFile
1.37+4-4lang/python310/distinfo
1.24+4-4lang/py310-html-docs/distinfo
1.22+2-2lang/python310/dist.mk
1.22+2-2lang/py310-html-docs/Makefile
+12-124 files

NetBSD/pkgsrc-wip d3fc4d0chromium Makefile distinfo

chromium: update to 151.0.7922.137
DeltaFile
+9-9chromium/distinfo
+2-2chromium/Makefile
+11-112 files

NetBSD/pkgsrc LG38zlCdoc TODO CHANGES-2026

   Updated www/nginx-devel, sysutils/py-ansible-compat, sysutils/ansible-lint
VersionDeltaFile
1.5253+4-1doc/CHANGES-2026
1.27742+1-2doc/TODO
+5-32 files

NetBSD/pkgsrc EJKRBjOsysutils/ansible-lint Makefile distinfo

   ansible-lint: updated to 26.8.0

   26.8.0

   Fix/sonarcloud unbounded recursion complexity
   feat: honor ANSIBLE_VAULT_PASSWORD_FILE for vault decryption
   fix: jinja[spacing] rule creating invalid syntax for minus modifiers
   chore(deps): update all dependencies
   chore(deps): update all dependencies pep621
   fix: remove stale words from cspell dictionary
   chore(deps): bump schemas npm packages for Dependabot CVEs
   fix(security): update dependencies [SECURITY]
   fix: address SonarCloud new code violations
   chore(deps): update all dependencies
   chore(deps): update all dependencies pep621
   fix(deps): exclude ansible-core 2.17.x (CVE-2026-11332)
   fix: expose ansible-galaxy on the uv tool-install path
   fix: var-naming for register projections
   chore: Adding OpenWrt 25.12 as platform

    [10 lines not shown]
VersionDeltaFile
1.77+4-4sysutils/ansible-lint/distinfo
1.86+3-3sysutils/ansible-lint/Makefile
+7-72 files

NetBSD/pkgsrc 29vJVwMsysutils/py-ansible-compat Makefile distinfo

   py-ansible-compat: updated to 26.8.0

   26.8.0

   fix: reduce cognitive complexity of 5 functions in runtime.py
   chore(deps): update all dependencies
   Sonar/s3776 s1172 src
   fix: annotate mutable class defaults with ClassVar
   chore(deps): update pep621
   fix(deps): exclude ansible-core 2.17.x (CVE-2026-11332)
   fix: skip collection modules in ANSIBLE_LIBRARY
   fix(CI): strip tox-local Ansible env vars in smoke tests
VersionDeltaFile
1.40+4-4sysutils/py-ansible-compat/distinfo
1.48+3-3sysutils/py-ansible-compat/Makefile
+7-72 files

NetBSD/pkgsrc sCt0UUQwww/nginx-devel Makefile options.mk

   nginx-devel: updated to 1.31.3

   1.31.3

   fixes for buffer overflow vulnerability when using map with regex
   (CVE-2026-42533), memory disclosure vulnerability when using
   ngx_http_slice_module (CVE-2026-60005), and use-after-free vulnerability when
   using ngx_http_ssi_module (CVE-2026-56434)
VersionDeltaFile
1.133+19-19www/nginx-devel/distinfo
1.50+6-6www/nginx-devel/options.mk
1.169+2-3www/nginx-devel/Makefile
+27-283 files

NetBSD/pkgsrc-wip ef247abvictorialogs-vlagent Makefile, victorialogs-vlogscli Makefile

victorialogs-*: use PKGBASE

Factor out the name of the program by using PKGBASE.
More resistant to copypastos for packaging of other VictoriaLogs
components.
DeltaFile
+2-2victorialogs-vlogscli/Makefile
+2-2victorialogs-vlagent/Makefile
+4-42 files

NetBSD/pkgsrc-wip 8c6fba9victorialogs DESCR

victorialogs: Describe what victoria-logs is
DeltaFile
+1-1victorialogs/DESCR
+1-11 files