gobgp: Update to 4.10.0
da824d9 GoBGP 4.10.0
723f98c feat: add multi-topology IDs to link descriptor API
a15f873 server: apply AS path option updates without resetting sessions
03eaa74 server: drop the queued outgoing messages on a state change
9470f3d server: drain an InfiniteChannel until its output closes
056eb2e table: don't panic on an rpki condition for an unvalidated path
55fa98f table: skip rejected paths in DropStale and MarkLLGRStaleOrDrop
e37cdd8 table: skip rejected paths when building Drop withdrawals
c4d9e77 server: move the ingress loop checks out of the handleUpdate loop
9b49e3f bfd: use transport local address for BFD
0cc5883 packet/bgp: reject an OPEN message that carries AS 0
e59efa7 docs: say that a neighbor setting wins over the peer group
05ba735 server: make a peer group update reach the peers in the group
b2a5ee1 server: keep the neighbor configuration as the caller passed it
9041a8c config/oc: stop forcing peer-as and min-adv-interval from the group
3e9288d fix(metrics): stop reporting peer gauges as counters
7ad257a table: do not emit an empty AS_PATH segment when merging AS4_PATH
[90 lines not shown]
py-test-mock: updated to 3.16.0
3.16.0
* Fixed ``duplicate_iterators=True`` for async functions spied with ``mocker.spy``.
* Fixed async mock assertion introspection to use awaited arguments instead of the latest call's arguments.
* ``mocker.resetall(return_value=True, side_effect=True)`` now also applies to non-callable mocks, such as those returned by ``mocker.create_autospec(SomeClass, instance=True)``. Previously both arguments were silently ignored for them.
* Added ``SpyType`` for annotating ``mocker.spy`` results.
* Dropped support for EOL Python 3.9.
* Removed handling of ``RuntimeError: stop called on unstarted patcher``, which can no longer occur in the supported Python versions.
* Added support for Python 3.15.
py-pytimeparse: updated to 1.1.9
1.1.9
Py3 only
slurm day clock
remove pipe character from sign regex
remove codecs.open
guard against malformed floats and fix interpret-as-minutes bug
ddns-route53: Update to 2.16.0
Preserve WAN provider failures after successful fallback by @crazy-max in #1440
Avoid reusing log events for WAN provider failures by @bensynapse in #1437
Simplify shutdown lifecycle by @crazy-max in #1377
Add support for OpenBSD architectures by @atmosx in #1382
Bump github.com/alecthomas/kong to 1.16.1 in #1428
Bump github.com/aws/aws-sdk-go-v2 dependencies in #1373
github.com/aws/aws-sdk-go-v2 to 1.47.1
github.com/aws/aws-sdk-go-v2/config to 1.33.6
github.com/aws/aws-sdk-go-v2/credentials to 1.20.6
github.com/aws/aws-sdk-go-v2/service/route53 to 1.70.1
Bump github.com/crazy-max/gonfig to 0.9.0 by @crazy-max in #1448
Bump github.com/dromara/carbon/v2 to 2.6.18 in #1436
Bump github.com/go-playground/validator/v10 to 10.30.5 in #1434
Bump github.com/rs/zerolog to 1.35.1 in #1375
Bump github.com/stretchr/testify to 1.12.1 in #1431
Bump golang.org/x/crypto to 0.52.0 in #1413
Bump golang.org/x/sys to 0.48.0 in #1433
py-djangorestframework: updated to 3.18.3
3.18.3
Bug fixes
Revert return value of order_by_precedence from 3.18.1
3.18.2
Security
GHSA-33wh-fxxf-88vv: Harden content negotiation against large Accept headers
GHSA-3547-9m27-7rxg: Refuse non-text encoding charsets
GHSA-xw6w-gcfp-cf8m: Make TokenProxy deletion actually delete the token
Features
[6 lines not shown]
py-django-filter: updated to 26.2
26.2 (2026-10-03)
* Added testing against Python 3.15.
* Dropped support for Python 3.10.
* LinkWidget will now conditionally escape provided label text.
Filter choices are under developer control, and applications populating them
from user-supplied values, including via ``AllValuesFilter``, must filter
those appropriately, as always. Nonetheless, escaping labels by default
serves as defense-in-depth hardening. Apply ``mark_safe()`` to labels
intended to contain HTML.
aarch64: fix HPFAR_EL2_FIPA defines for various configurations
HPFAR_EL2_FIPA is 36bits long when FEAT_D128 and FEAT_LPA aren't
implemented, i.e. HPFAR_EL2[39:4]
Add HPFAR_EL2_FIPA_LPA for when FEAT_D128 is not implemented and
FEAT_LPA is.
Provide HPFAR_EL2_FIPA_{D128_,LPA_,}BITS for the Faulting Intermediate
Physical Address.
Remove HPFAR_EL2_FIPA_BITSHIFT
samba: update to 4.25.0.
NEW FEATURES/CHANGES
====================
SMB3 Persistent Handles (Experimental)
--------------------------------------
Samba now includes experimental support for SMB3 Persistent Handles,
a fundamental building block for Transparent Failover.
Persistent Handles allow SMB clients to reconnect after a server
restart or outage while retaining valid file handles. Samba persists
all necessary handle state to durable on-disk storage so that open
files can be reconstructed when clients reconnect. This enables
applications that depend on uninterrupted file access, such as virtual
machine storage and clustered database workloads, to tolerate
temporary server failures without having to reopen files.
[200 lines not shown]
httpd(8): Per RFC 3875, set the PWD of child CGI processes to the
location of the script that is being run.
Right now this only works with the -c option (where previously PWD would
have been unset in the child), processes invoked with -C already got a
PWD, and the wrapper script can also handle setting it to something
sensible.
"looks good" mrg
PR bin/58713 httpd: CGIs have wrong cwd
yamusic-tui-git: update to 0.8.0
Upstream changes:
* Theming support (configurable colors and "icons");
* MacOS media control integration;
* UI components toggle;
* Volume indicator;
* Switched to a new rotor API for my wave;
* Various tracklist fixes and pages keybinding;
* Support for HTTP proxy and self-signed SSL certs;
* Parallel initial load and fetching playing track info;
* Liked albums and UI changes for displaying albums;
* Improved search results (now displays all of the artist's albums instead of popular tracks);
* Show artist's albums action;
* Fixed errors in offline mode;
* Fixed mpris:artUrl field for linux media controls;
* Fixed terminal title;
* Fixed playlist controls;
* Fixed rewind.
resterm: Update to 1.13.0
Digest auth
Custom Host headers
WebSocket
CLI exit codes
Fixed
Canceling an SSE stream closes its connection immediately, even if the server is silent. Switching workspaces no longer leaves the old stream open.
Closing or canceling a WebSocket session while a send is in progress no longer reports a send error in place of the close or cancellation.
A WebSocket send that fails before reaching the socket now fails only that send, rather than ending the whole session.
# @ws close 4001 "client done" now sends client done, without the surrounding quotes. Quotes inside the reason are preserved.