NetBSD/pkgsrc YAb1VhS — doc CHANGES-2026

   doc: Updated net/gobgp to 4.10.0
VersionDeltaFile
1.6765+2-1doc/CHANGES-2026
+2-11 files

NetBSD/pkgsrc MGhn69Y — net/gobgp Makefile go-modules.mk

   gobgp: Update to 4.10.0

   da824d9 GoBGP 4.10.0
   723f98c feat: add multi-topology IDs to link descriptor API
   a15f873 server: apply AS path option updates without resetting sessions
   03eaa74 server: drop the queued outgoing messages on a state change
   9470f3d server: drain an InfiniteChannel until its output closes
   056eb2e table: don't panic on an rpki condition for an unvalidated path
   55fa98f table: skip rejected paths in DropStale and MarkLLGRStaleOrDrop
   e37cdd8 table: skip rejected paths when building Drop withdrawals
   c4d9e77 server: move the ingress loop checks out of the handleUpdate loop
   9b49e3f bfd: use transport local address for BFD
   0cc5883 packet/bgp: reject an OPEN message that carries AS 0
   e59efa7 docs: say that a neighbor setting wins over the peer group
   05ba735 server: make a peer group update reach the peers in the group
   b2a5ee1 server: keep the neighbor configuration as the caller passed it
   9041a8c config/oc: stop forcing peer-as and min-adv-interval from the group
   3e9288d fix(metrics): stop reporting peer gauges as counters
   7ad257a table: do not emit an empty AS_PATH segment when merging AS4_PATH

    [90 lines not shown]
VersionDeltaFile
1.2+34-34net/gobgp/distinfo
1.2+10-10net/gobgp/go-modules.mk
1.2+2-2net/gobgp/Makefile
+46-463 files

NetBSD/pkgsrc BX3VnmJ — doc CHANGES-2026

   Updated time/py-pytimeparse, devel/py-test-mock
VersionDeltaFile
1.6764+3-1doc/CHANGES-2026
+3-11 files

NetBSD/pkgsrc qeJsviH — devel/py-test-mock Makefile distinfo

   py-test-mock: updated to 3.16.0

   3.16.0

   * Fixed ``duplicate_iterators=True`` for async functions spied with ``mocker.spy``.
   * Fixed async mock assertion introspection to use awaited arguments instead of the latest call's arguments.
   * ``mocker.resetall(return_value=True, side_effect=True)`` now also applies to non-callable mocks, such as those returned by ``mocker.create_autospec(SomeClass, instance=True)``. Previously both arguments were silently ignored for them.
   * Added ``SpyType`` for annotating ``mocker.spy`` results.
   * Dropped support for EOL Python 3.9.
   * Removed handling of ``RuntimeError: stop called on unstarted patcher``, which can no longer occur in the supported Python versions.
   * Added support for Python 3.15.
VersionDeltaFile
1.31+4-4devel/py-test-mock/distinfo
1.36+3-3devel/py-test-mock/Makefile
+7-72 files

NetBSD/pkgsrc 2WSlNnL — time/py-pytimeparse distinfo Makefile

   py-pytimeparse: updated to 1.1.9

   1.1.9

   Py3 only
   slurm day clock
   remove pipe character from sign regex
   remove codecs.open
   guard against malformed floats and fix interpret-as-minutes bug
VersionDeltaFile
1.2+9-5time/py-pytimeparse/PLIST
1.5+5-4time/py-pytimeparse/Makefile
1.4+4-4time/py-pytimeparse/distinfo
+18-133 files

NetBSD/pkgsrc PrLNHgQ — doc CHANGES-2026

   doc: Updated net/ddns-route53 to 2.16.0
VersionDeltaFile
1.6763+2-1doc/CHANGES-2026
+2-11 files

NetBSD/pkgsrc KK9xnbV — doc CHANGES-2026

   Updated www/py-django-filter, www/py-djangorestframework
VersionDeltaFile
1.6762+3-1doc/CHANGES-2026
+3-11 files

NetBSD/pkgsrc krPSUef — net/ddns-route53 Makefile go-modules.mk

   ddns-route53: Update to 2.16.0

   Preserve WAN provider failures after successful fallback by @crazy-max in #1440
   Avoid reusing log events for WAN provider failures by @bensynapse in #1437
   Simplify shutdown lifecycle by @crazy-max in #1377
   Add support for OpenBSD architectures by @atmosx in #1382
   Bump github.com/alecthomas/kong to 1.16.1 in #1428
   Bump github.com/aws/aws-sdk-go-v2 dependencies in #1373
    github.com/aws/aws-sdk-go-v2 to 1.47.1
    github.com/aws/aws-sdk-go-v2/config to 1.33.6
    github.com/aws/aws-sdk-go-v2/credentials to 1.20.6
    github.com/aws/aws-sdk-go-v2/service/route53 to 1.70.1
   Bump github.com/crazy-max/gonfig to 0.9.0 by @crazy-max in #1448
   Bump github.com/dromara/carbon/v2 to 2.6.18 in #1436
   Bump github.com/go-playground/validator/v10 to 10.30.5 in #1434
   Bump github.com/rs/zerolog to 1.35.1 in #1375
   Bump github.com/stretchr/testify to 1.12.1 in #1431
   Bump golang.org/x/crypto to 0.52.0 in #1413
   Bump golang.org/x/sys to 0.48.0 in #1433
VersionDeltaFile
1.3+166-175net/ddns-route53/distinfo
1.3+54-57net/ddns-route53/go-modules.mk
1.27+2-3net/ddns-route53/Makefile
+222-2353 files

NetBSD/pkgsrc x72KnWR — www/py-djangorestframework Makefile distinfo

   py-djangorestframework: updated to 3.18.3

   3.18.3

   Bug fixes

   Revert return value of order_by_precedence from 3.18.1


   3.18.2

   Security

   GHSA-33wh-fxxf-88vv: Harden content negotiation against large Accept headers
   GHSA-3547-9m27-7rxg: Refuse non-text encoding charsets
   GHSA-xw6w-gcfp-cf8m: Make TokenProxy deletion actually delete the token

   Features


    [6 lines not shown]
VersionDeltaFile
1.36+4-4www/py-djangorestframework/distinfo
1.49+2-2www/py-djangorestframework/Makefile
+6-62 files

NetBSD/pkgsrc GCi5lVV — www/py-django-filter Makefile distinfo

   py-django-filter: updated to 26.2

   26.2 (2026-10-03)

   * Added testing against Python 3.15.

   * Dropped support for Python 3.10.

   * LinkWidget will now conditionally escape provided label text.

     Filter choices are under developer control, and applications populating them
     from user-supplied values, including via ``AllValuesFilter``, must filter
     those appropriately, as always. Nonetheless, escaping labels by default
     serves as defense-in-depth hardening. Apply ``mark_safe()`` to labels
     intended to contain HTML.
VersionDeltaFile
1.17+4-4www/py-django-filter/distinfo
1.23+2-3www/py-django-filter/Makefile
+6-72 files

NetBSD/src 0WX7do7 — sys/arch/aarch64/aarch64 cpufunc_asm_armv8.S, sys/arch/aarch64/include cpufunc.h

   aarch64: Add TLB invalidation functions for EL2.

   Add assembly implementations of three new EL2 TLB invalidation functions.
VersionDeltaFile
1.9+45-1sys/arch/aarch64/aarch64/cpufunc_asm_armv8.S
1.33+5-1sys/arch/aarch64/include/cpufunc.h
+50-22 files

NetBSD/pkgsrc WgoVMvP — doc CHANGES-2026

   doc: Updated devel/nss to 3.131
VersionDeltaFile
1.6761+2-1doc/CHANGES-2026
+2-11 files

NetBSD/pkgsrc 3nR1Qzv — devel/nss Makefile distinfo

   nss: update to 3.131.

   Bug 2078438 remove unused private pkcs12, pkcs7, and smime functions.
   Bug 2070738 Fix generating nss.pc with system-nspr.
   Bug 2066048 replace sslSecurityInfo peerCert with peerCertDER.
   Bug 2067244 remove support for inherited DSA parameters in libssl.
   Bug 2017995 Fix issues with Unwrapping keys using tokens in FIPS mode.
   Bug 2069886 remove Windows-only AES-CTR implementation.
   Bug 2069887 improve algorithm policy enforcement for ML-DSA.
   Bug 2064512 reject non-RFC 8410 curve OIDs when encoding an X25519 or Ed25519 SubjectPublicKeyInfo.
   Bug 2076212 Clear freed CMS members in the destructors.
   Bug 2076212 Release the previous signer certificate when re-verifying a PKCS#7 signature.
   Bug 2076212 Make SEC_PKCS7DecoderAbort fail the decode.
   Bug 2076212 Fail closed after an incomplete PKCS#12 decode.
   Bug 2076240 remove unused NSSCryptoContext and NSSTrustDomain functions.
   Bug 1993638 can’t import eddsa .p12 from OpenSSL.
   Bug 2055638 fix clang format.
   Bug 2072045 pk12util fails to import private key into SoftHSM token despite initialized slot and valid PKCS#12 file.
   Bug 2075580 p7content: open output file in binary mode.

    [19 lines not shown]
VersionDeltaFile
1.220+4-4devel/nss/distinfo
1.305+2-2devel/nss/Makefile
+6-62 files

NetBSD/src yMMDR11 — sys/arch/aarch64/include armreg.h

   aarch64: fix HPFAR_EL2_FIPA defines for various configurations

   HPFAR_EL2_FIPA is 36bits long when FEAT_D128 and FEAT_LPA aren't
   implemented, i.e. HPFAR_EL2[39:4]

   Add HPFAR_EL2_FIPA_LPA for when FEAT_D128 is not implemented and
   FEAT_LPA is.

   Provide HPFAR_EL2_FIPA_{D128_,LPA_,}BITS for the Faulting Intermediate
   Physical Address.

   Remove HPFAR_EL2_FIPA_BITSHIFT
VersionDeltaFile
1.82+8-4sys/arch/aarch64/include/armreg.h
+8-41 files

NetBSD/pkgsrc xGR7zbG — doc TODO CHANGES-2026

   doc: Updated net/samba4 to 4.25.0
VersionDeltaFile
1.28114+1-2doc/TODO
1.6760+2-1doc/CHANGES-2026
+3-32 files

NetBSD/pkgsrc guIgPlt — net/samba4 Makefile PLIST, net/samba4/patches patch-nsswitch_winbind__nss__netbsd.c patch-lib_tsocket_tsocket__bsd.c

   samba: update to 4.25.0.

   NEW FEATURES/CHANGES
   ====================

   SMB3 Persistent Handles (Experimental)
   --------------------------------------

   Samba now includes experimental support for SMB3 Persistent Handles,
   a fundamental building block for Transparent Failover.

   Persistent Handles allow SMB clients to reconnect after a server
   restart or outage while retaining valid file handles. Samba persists
   all necessary handle state to durable on-disk storage so that open
   files can be reconstructed when clients reconnect. This enables
   applications that depend on uninterrupted file access, such as virtual
   machine storage and clustered database workloads, to tolerate
   temporary server failures without having to reopen files.


    [200 lines not shown]
VersionDeltaFile
1.4+7-7net/samba4/patches/patch-nsswitch_winbind__nss__netbsd.c
1.4+7-7net/samba4/patches/patch-lib_tsocket_tsocket__bsd.c
1.132+6-6net/samba4/distinfo
1.66+5-1net/samba4/PLIST
1.226+2-3net/samba4/Makefile
+27-245 files

NetBSD/pkgsrc jDgwdOq — doc CHANGES-2026

   doc: Updated archivers/7-zip to 26.04
VersionDeltaFile
1.6759+2-1doc/CHANGES-2026
+2-11 files

NetBSD/pkgsrc PIisnp7 — archivers/7-zip Makefile distinfo

   7-zip: update to 26.04.

   - Some bugs and vulnerabilities were fixed.
VersionDeltaFile
1.14+4-4archivers/7-zip/distinfo
1.17+3-3archivers/7-zip/Makefile
+7-72 files

NetBSD/pkgsrc 2KUCQyD — doc CHANGES-2026

   doc: Updated wayland/xwayland to 24.1.14
VersionDeltaFile
1.6758+2-1doc/CHANGES-2026
+2-11 files

NetBSD/pkgsrc 2pwTkON — wayland/xwayland Makefile distinfo

   xwayland: update to 24.1.14.

   This release contains the fixes for the issues reported in today's
   security advisory:
   https://lists.x.org/archives/xorg-announce/2026-October/003747.html

   * CVE-2026-88812: XKB SetGeometry TextDoodad Double Free
   * CVE-2026-93515: Present Extension Cross-Window Notify Use-After-Free
   * CVE-2026-93516: XInput Passive Grab modifierDevice Use-After-Free
   * CVE-2026-93517: GLX RenderLarge Heap Buffer Overflow
   * CVE-2026-93518: XKB ResizeKeyType Numeric Truncation
   * CVE-2026-93519: XFixes Pointer Barrier Event List Buffer Overflow
   * CVE-2026-93520: XKB ChangeKeycodeRange Heap Out-of-Bounds Write
   * CVE-2026-93521: RandR ChangeProviderProperty Heap Buffer Overflow
   * CVE-2026-93522: Glamor CopyArea CPU-FBO Heap Buffer Overflow
   * CVE-2026-93523: XInput2 PassiveUngrabDevice Modifier Out-of-Bounds Write
   * CVE-2026-93524: XKB SetMap Key Width/Action Count Desync Out-Of-Bounds Read
   * CVE-2026-93536: GestureBuildSprite Use-After-Free
VersionDeltaFile
1.6+4-4wayland/xwayland/distinfo
1.6+2-2wayland/xwayland/Makefile
+6-62 files

NetBSD/pkgsrc LDmgXRr — doc CHANGES-2026

   doc: Updated x11/modular-xorg-xephyr to 21.1.25
VersionDeltaFile
1.6757+2-1doc/CHANGES-2026
+2-11 files

NetBSD/pkgsrc y5WFrGg — doc CHANGES-2026

   doc: Updated x11/modular-xorg-server to 21.1.25
VersionDeltaFile
1.6756+2-1doc/CHANGES-2026
+2-11 files

NetBSD/pkgsrc 7tLlYrZ — x11/modular-xorg-server Makefile.common distinfo

   modular-xorg-server: update to 21.1.25.

   This release contains the fixes for the issues reported in today's
   security advisory:
   https://lists.x.org/archives/xorg-announce/2026-October/003747.html

   * CVE-2026-88812: XKB SetGeometry TextDoodad Double Free
   * CVE-2026-93515: Present Extension Cross-Window Notify Use-After-Free
   * CVE-2026-93516: XInput Passive Grab modifierDevice Use-After-Free
   * CVE-2026-93517: GLX RenderLarge Heap Buffer Overflow
   * CVE-2026-93518: XKB ResizeKeyType Numeric Truncation
   * CVE-2026-93519: XFixes Pointer Barrier Event List Buffer Overflow
   * CVE-2026-93520: XKB ChangeKeycodeRange Heap Out-of-Bounds Write
   * CVE-2026-93521: RandR ChangeProviderProperty Heap Buffer Overflow
   * CVE-2026-93522: Glamor CopyArea CPU-FBO Heap Buffer Overflow
   * CVE-2026-93523: XInput2 PassiveUngrabDevice Modifier Out-of-Bounds Write
   * CVE-2026-93524: XKB SetMap Key Width/Action Count Desync Out-Of-Bounds Read
   * CVE-2026-93536: GestureBuildSprite Use-After-Free
VersionDeltaFile
1.137+4-4x11/modular-xorg-server/distinfo
1.70+2-2x11/modular-xorg-server/Makefile.common
+6-62 files

NetBSD/src Hw7AAmN — libexec/httpd cgi-bozo.c

   httpd(8): Per RFC 3875, set the PWD of child CGI processes to the
   location of the script that is being run.

   Right now this only works with the -c option (where previously PWD would
   have been unset in the child), processes invoked with -C already got a
   PWD, and the wrapper script can also handle setting it to something
   sensible.

   "looks good" mrg

   PR bin/58713 httpd: CGIs have wrong cwd
VersionDeltaFile
1.58+11-1libexec/httpd/cgi-bozo.c
+11-11 files

NetBSD/pkgsrc Ufj0O8g — doc CHANGES-2026

   doc: Updated devel/lcov to 2.6nb4
VersionDeltaFile
1.6755+2-1doc/CHANGES-2026
+2-11 files

NetBSD/pkgsrc C5qhDJ9 — devel/lcov distinfo Makefile, devel/lcov/patches patch-tests_lcov_extract_extract2.sh patch-tests_common.tst

   lcov: add upstream patch fixing the remaining test issues

   Bump PKGREVISION.
VersionDeltaFile
1.32+10-32devel/lcov/Makefile
1.14+4-3devel/lcov/distinfo
1.2+1-1devel/lcov/patches/patch-tests_lcov_extract_extract2.sh
1.2+1-1devel/lcov/patches/patch-tests_common.tst
+16-374 files

NetBSD/src NJVYRJQ — libexec/httpd bozohttpd.8

   bozohttpd.8: Clarify how the CGI options work.
VersionDeltaFile
1.103+11-6libexec/httpd/bozohttpd.8
+11-61 files

NetBSD/pkgsrc-wip e8caf78 — yamusic-tui-git go-modules.mk Makefile, yamusic-tui-git/patches patch-ui_model_mainPage_playlistControl.go

yamusic-tui-git: update to 0.8.0

Upstream changes:
 * Theming support (configurable colors and "icons");
 * MacOS media control integration;
 * UI components toggle;
 * Volume indicator;
 * Switched to a new rotor API for my wave;
 * Various tracklist fixes and pages keybinding;
 * Support for HTTP proxy and self-signed SSL certs;
 * Parallel initial load and fetching playing track info;
 * Liked albums and UI changes for displaying albums;
 * Improved search results (now displays all of the artist's albums instead of popular tracks);
 * Show artist's albums action;
 * Fixed errors in offline mode;
 * Fixed mpris:artUrl field for linux media controls;
 * Fixed terminal title;
 * Fixed playlist controls;
 * Fixed rewind.
DeltaFile
+10-9yamusic-tui-git/distinfo
+18-0yamusic-tui-git/patches/patch-ui_model_mainPage_playlistControl.go
+4-4yamusic-tui-git/Makefile
+2-2yamusic-tui-git/go-modules.mk
+34-154 files

NetBSD/pkgsrc noM3mUR — doc CHANGES-2026

   doc: Updated www/resterm to 1.13.0
VersionDeltaFile
1.6754+2-1doc/CHANGES-2026
+2-11 files

NetBSD/pkgsrc DdbEtFo — www/resterm Makefile go-modules.mk

   resterm: Update to 1.13.0

   Digest auth
   Custom Host headers
   WebSocket
   CLI exit codes

   Fixed
   Canceling an SSE stream closes its connection immediately, even if the server is silent. Switching workspaces no longer leaves the old stream open.
   Closing or canceling a WebSocket session while a send is in progress no longer reports a send error in place of the close or cancellation.
   A WebSocket send that fails before reaching the socket now fails only that send, rather than ending the whole session.
   # @ws close 4001 "client done" now sends client done, without the surrounding quotes. Quotes inside the reason are preserved.
VersionDeltaFile
1.56+9-105www/resterm/distinfo
1.47+2-34www/resterm/go-modules.mk
1.62+1-1www/resterm/Makefile
+12-1403 files