NetBSD/pkgsrc-wip a0784ccdnsdist Makefile distinfo, dnsdist/files dnsdist.sh

dnsdist: Upgrade to version 2.0.2
DeltaFile
+76-0dnsdist/Makefile
+28-0dnsdist/files/smf/manifest.xml
+24-0dnsdist/files/dnsdist.sh
+15-0dnsdist/patches/patch-configure
+10-0dnsdist/patches/patch-protobuf
+7-0dnsdist/distinfo
+160-02 files not shown
+168-08 files

NetBSD/pkgsrc PaU9AD8doc CHANGES-2025

   Updated www/py-django[4]
VersionDeltaFile
1.6999+3-1doc/CHANGES-2025
+3-11 files

NetBSD/pkgsrc EbUPBTAwww/py-django4 distinfo PLIST

   py-django: updated to 4.2.27

   Django 4.2.27 fixes one security issue with severity “high”, one security issue with severity “moderate”, and one bug in 4.2.26.

   CVE-2025-13372: Potential SQL injection in FilteredRelation column aliases on PostgreSQL

   FilteredRelation was subject to SQL injection in column aliases, using a suitably crafted dictionary, with dictionary expansion, as the **kwargs passed to QuerySet.annotate() or QuerySet.alias() on PostgreSQL.

   CVE-2025-64460: Potential denial-of-service vulnerability in XML Deserializer

   XML Serialization was subject to a potential denial-of-service attack due to quadratic time complexity when deserializing crafted documents containing many nested invalid elements. The internal helper django.core.serializers.xml_serializer.getInnerText() previously accumulated inner text inefficiently during recursion. It now collects text per element, avoiding excessive resource usage.

   Bugfixes

   Fixed a regression in Django 4.2.26 where DisallowedRedirect was raised by HttpResponseRedirect and HttpResponsePermanentRedirect for URLs longer than 2048 characters. The limit is now 16384 characters.
VersionDeltaFile
1.18+4-4www/py-django4/distinfo
1.3+4-1www/py-django4/PLIST
1.22+2-2www/py-django4/Makefile
+10-73 files

NetBSD/pkgsrc mhqLYcGwww/py-django distinfo Makefile

   py-django: updated to 5.2.9

   Django 5.2.9 fixes one security issue with severity “high”, one security issue with severity “moderate”, and several bugs in 5.2.8.

   CVE-2025-13372: Potential SQL injection in FilteredRelation column aliases on PostgreSQL

   FilteredRelation was subject to SQL injection in column aliases, using a suitably crafted dictionary, with dictionary expansion, as the **kwargs passed to QuerySet.annotate() or QuerySet.alias() on PostgreSQL.

   CVE-2025-64460: Potential denial-of-service vulnerability in XML Deserializer

   XML Serialization was subject to a potential denial-of-service attack due to quadratic time complexity when deserializing crafted documents containing many nested invalid elements. The internal helper django.core.serializers.xml_serializer.getInnerText() previously accumulated inner text inefficiently during recursion. It now collects text per element, avoiding excessive resource usage.

   Bugfixes

   Fixed a bug in Django 5.2 where django.utils.feedgenerator.Stylesheet.__str__() did not escape the url, mimetype, and media attributes, potentially leading to invalid XML markup.

   Fixed a bug in Django 5.2 on PostgreSQL where bulk_create() did not apply a field’s custom query placeholders.

   Fixed a regression in Django 5.2.2 that caused a crash when using aggregate functions with an empty Q filter over a queryset with annotations.

    [4 lines not shown]
VersionDeltaFile
1.124+4-4www/py-django/distinfo
1.152+2-2www/py-django/Makefile
+6-62 files

NetBSD/pkgsrc-wip ac27e0cclang distinfo, clang-tools-extra distinfo

llvm: updated to 21.1.7
DeltaFile
+3-3clang-tools-extra/distinfo
+3-3clang/distinfo
+3-3compiler-rt/distinfo
+3-3flang/distinfo
+3-3libcxx/distinfo
+3-3libcxxabi/distinfo
+18-189 files not shown
+43-4315 files

NetBSD/pkgsrc khlpYvCmultimedia/mlt Makefile.common distinfo, multimedia/mlt/patches patch-src_modules_qt_CMakeLists.txt

   mlt*: use installed mlt when building qt modules
VersionDeltaFile
1.1+21-0multimedia/mlt/patches/patch-src_modules_qt_CMakeLists.txt
1.3+6-1multimedia/mlt/Makefile.common
1.20+2-1multimedia/mlt/distinfo
+29-23 files

NetBSD/pkgsrc bUOz2E9multimedia/mlt-qt5 Makefile, multimedia/mlt-qt6 Makefile

   mlt-qt{5,6}: add missing mlt dependency
VersionDeltaFile
1.3+2-1multimedia/mlt-qt6/Makefile
1.3+2-1multimedia/mlt-qt5/Makefile
+4-22 files

NetBSD/pkgsrc 7GYhKfcdoc CHANGES-2025

   doc: Updated lang/go125 to 1.25.5
VersionDeltaFile
1.6998+3-1doc/CHANGES-2025
+3-11 files

NetBSD/pkgsrc 269raRGaudio/ymuse Makefile, chat/coyim Makefile

   Revbump all Go packages after go125 update
VersionDeltaFile
1.40+2-2audio/ymuse/Makefile
1.93+2-2chat/coyim/Makefile
1.55+2-2chat/gomuks/Makefile
1.84+2-2chat/matterircd/Makefile
1.20+2-2chat/neonmodem/Makefile
1.40+2-2chat/senpai/Makefile
+12-12196 files not shown
+404-381202 files

NetBSD/pkgsrc vqCaTBTlang/go version.mk, lang/go124 distinfo Makefile

   go: update to 1.24.11 and 1.25.5 (security)

   These releases include 2 security fixes following the security policy:

   - crypto/x509: excessive resource consumption in printing error string for
     host certificate validation

     Within HostnameError.Error(), when constructing an error string, there is no
     limit to the number of hosts that will be printed out.
     Furthermore, the error string is constructed by repeated string
     concatenation, leading to quadratic runtime.

     Therefore, a certificate provided by a malicious actor can result in
     excessive resource consumption.
     HostnameError.Error() now limits the number of hosts and utilizes
     strings.Builder when constructing an error string.

     Thanks to Philippe Antoine (Catena cyber) for reporting this issue.


    [13 lines not shown]
VersionDeltaFile
1.6+4-4lang/go125/distinfo
1.12+4-4lang/go124/distinfo
1.241+3-3lang/go/version.mk
1.2+2-2lang/go124/Makefile
1.2+2-2lang/go125/Makefile
+15-155 files

NetBSD/src BQY8DQysys/arch/ews4800mips/conf RAMDISK


   Trim sl and swwdog from the RAMDISK kernel in hopes of getting it to fit.
VersionDeltaFile
1.38+3-1sys/arch/ews4800mips/conf/RAMDISK
+3-11 files

NetBSD/pkgsrc NFroOdAdoc pkg-vulnerabilities

   pkg-vulnerabilities: add last 24 hours CVEs

   + kissfft (fixed upstream, latest stable release 131.2.0 still affected though),
     python (fixed upstream, no stable releases with fixes),
     zabbix-{agent,frontend}
VersionDeltaFile
1.674+17-1doc/pkg-vulnerabilities
+17-11 files

NetBSD/src UWbu8Ngsys/lib/libkern Makefile.inc

   Revert previous.  I guess I'll have to solve the m68k build issue
   a different way.
VersionDeltaFile
1.52+4-4sys/lib/libkern/Makefile.inc
+4-41 files

NetBSD/src HIO9hYXsys/arch/sparc/include bswap.h, sys/arch/sparc64/include bswap.h

   We can use __builtin_bswapX on sparc when using clang, so do so.

   PR port-sparc64/59789 bswap is slow
VersionDeltaFile
1.4+5-1sys/arch/sparc/include/bswap.h
1.4+5-1sys/arch/sparc64/include/bswap.h
+10-22 files

NetBSD/src qHWOJtnsys/lib/libkern Makefile.inc

   Make libkern depend on assym.h.
VersionDeltaFile
1.51+5-5sys/lib/libkern/Makefile.inc
+5-51 files

NetBSD/pkgsrc j9Nt2WQdoc CHANGES-2025

   Updated sysutils/gam to 7.29.01
VersionDeltaFile
1.6997+2-1doc/CHANGES-2025
+2-11 files

NetBSD/pkgsrc 2AVJrpysysutils/gam PLIST distinfo

   gam: update to 7.29.01

   Changes since 7.19.02:

   7.29.01

   Added option oneitemperrow to gam <UserTypeEntity> print calendars ... permissions to have each of a calendar's permissions displayed on a separate row with all of the other calendar fields.

   Updated gam yubikey reset_piv to handle YubiKey firmware updates that caused an error.

   7.29.00

   Added options mappermissionsemail <EmailAddress> <EmailAddress> and  mappermissionsemailfile <CSVFileInput> endcsv to these commands:

   gam [<UserTypeEntity>] copy shareddriveacls <SharedDriveEntity> to <SharedDriveEntity>
   gam [<UserTypeEntity>] sync shareddriveacls <SharedDriveEntity> with <SharedDriveEntity>
   gam <UserTypeEntity> copy drivefile <DriveFileEntity>
   gam <UserTypeEntity> move drivefile <DriveFileEntity>


    [318 lines not shown]
VersionDeltaFile
1.9+3-57sysutils/gam/PLIST
1.11+4-4sysutils/gam/distinfo
1.19+3-2sysutils/gam/Makefile
+10-633 files

NetBSD/src KxtwnzJdistrib/sgimips/ramdisk Makefile, sys/arch/sgimips/conf INSTALL32_IP3x


   Revert the size change of the install ramdisk and instead just remove
   a driver from the install kernel.  Same ramdisk size as before.  Not
   sure this platform can have a larger ramdisk size.
VersionDeltaFile
1.25+2-2distrib/sgimips/ramdisk/Makefile
1.8+4-0sys/arch/sgimips/conf/INSTALL32_IP3x
+6-22 files

NetBSD/pkgsrc hvJOUO0doc CHANGES-2025 TODO

   Updated net/haproxy, security/py-pip-audit
VersionDeltaFile
1.6996+3-1doc/CHANGES-2025
1.26506+1-2doc/TODO
+4-32 files

NetBSD/pkgsrc yE7cuu9security/py-pip-audit distinfo Makefile

   py-pip-audit: updated to 2.10.0

   2.10.0

   Added

   pip-audit now supports the --osv-url URL flag, which can be used to
   retrieve vulnerabilities from a custom OSV service. This is useful for
   organizations that host their own mirror of the OSV database, or that
   have custom OSV records

   pip-audit now supports the Ecosyste.ms vulnerability service with
   --vulnerability-service=esms

   Changed

   The minimum version of Python is now 3.10

   Fixed

    [6 lines not shown]
VersionDeltaFile
1.34+4-4security/py-pip-audit/distinfo
1.42+4-3security/py-pip-audit/Makefile
1.12+4-1security/py-pip-audit/PLIST
+12-83 files

NetBSD/pkgsrc vtXBGnCnet/haproxy distinfo Makefile, net/haproxy/patches patch-include_haproxy_proxy-t.h

   haproxy: updated to 3.3.0

   3.3.0
   - BUG/MINOR: acme: better challenge_ready processing
   - BUG/MINOR: acme: warning ‘ctx’ may be used uninitialized
   - MINOR: httpclient: complete the https log
   - BUG/MEDIUM: server: do not use default SNI if manually set
   - BUG/MINOR: freq_ctr: Prevent possible signed overflow in freq_ctr_overshoot_period
   - DOC: ssl: Document the restrictions on 0RTT.
   - DOC: ssl: Note that 0rtt works fork QUIC with QuicTLS too.
   - BUG/MEDIUM: quic: do not prevent sending if no BE token
   - BUG/MINOR: quic/server: free quic_retry_token on srv drop
   - MINOR: quic: split global CID tree between FE and BE sides
   - MINOR: quic: use separate global quic_conns FE/BE lists
   - MINOR: quic: add "clo" filter on show quic
   - MINOR: quic: dump backend connections on show quic
   - MINOR: quic: mark backend conns on show quic
   - BUG/MINOR: quic: fix uninit list on show quic handler
   - BUG/MINOR: quic: release BE quic_conn on connect failure

    [10 lines not shown]
VersionDeltaFile
1.138+5-5net/haproxy/distinfo
1.5+3-3net/haproxy/patches/patch-include_haproxy_proxy-t.h
1.147+2-2net/haproxy/Makefile
+10-103 files

NetBSD/pkgsrc 6YLGTQedoc TODO

   doc/TODO: + webkit-gtk-2.50.2.
VersionDeltaFile
1.26505+2-1doc/TODO
+2-11 files

NetBSD/pkgsrc KDVkP12net/czmq Makefile

   czmq: use http (the https certificate is for a different site)
VersionDeltaFile
1.13+2-2net/czmq/Makefile
+2-21 files

NetBSD/pkgsrc 0VAPr9ywww/cvsweb Makefile

   cvsweb: update HOMEPAGE
VersionDeltaFile
1.53+2-3www/cvsweb/Makefile
+2-31 files

NetBSD/src uSBQ0gxsys/arch/evbarm/conf RPI_INSTALL


   Image size changed.  Bump.
VersionDeltaFile
1.15+2-2sys/arch/evbarm/conf/RPI_INSTALL
+2-21 files

NetBSD/pkgsrc 46ynCNKdevel/cvsup-gui-bin Makefile

   cvsup-gui-bin: remove HOMEPAGE that's something completely different now
VersionDeltaFile
1.19+1-2devel/cvsup-gui-bin/Makefile
+1-21 files

NetBSD/pkgsrc MfBt2wPfonts/CutiveFont Makefile

   CutiveFont: update HOMEPAGE
VersionDeltaFile
1.3+2-2fonts/CutiveFont/Makefile
+2-21 files

NetBSD/pkgsrc CSz3kiJmultimedia/mlt-qt5 Makefile, multimedia/mlt-qt6 Makefile

   mlt*: does not work with ninja due to BUILD_DIRS
VersionDeltaFile
1.2+3-1multimedia/mlt-qt5/Makefile
1.2+3-1multimedia/mlt-qt6/Makefile
+6-22 files

NetBSD/pkgsrc e0xDkF4multimedia/mlt Makefile.common

   mlt: set GITHUB_PROJECT, so downloads work for mlt-qt*
VersionDeltaFile
1.2+2-1multimedia/mlt/Makefile.common
+2-11 files

NetBSD/pkgsrc xIWnVOsdoc CHANGES-2025

   Updated sysutils/nabud to 1.4.1
VersionDeltaFile
1.6995+2-1doc/CHANGES-2025
+2-11 files