NetBSD/src AyD4Dpslib/libc/stdio fgetln.3

   lib/libc/stdio/fgetln.3: fix trivial formatting typo

   Trivial whitespace fix to turn
        getline(3), ferror(3), fgets(3), fopen(3), fparseln(3,) putc(3)
   into
        getline(3), ferror(3), fgets(3), fopen(3), fparseln(3), putc(3)
VersionDeltaFile
1.18+2-2lib/libc/stdio/fgetln.3
+2-21 files

NetBSD/pkgsrc Y9JIE0ygraphics/jbigkit distinfo, graphics/jbigkit/patches patch-ab patch-aa

   graphics/jbigkit: fix build

   Provide a libtool tag so that libtool doesn't have to infer a source language
VersionDeltaFile
1.8+6-6graphics/jbigkit/patches/patch-ab
1.6+6-6graphics/jbigkit/patches/patch-aa
1.12+3-3graphics/jbigkit/distinfo
+15-153 files

NetBSD/pkgsrc-wip 0170fe8webhookd TODO

webhookd: Add reference to CVE-2026-59157
DeltaFile
+2-0webhookd/TODO
+2-01 files

NetBSD/pkgsrc-wip 46ee202suricata TODO

suricata: Add reference to recent CVEs
DeltaFile
+5-1suricata/TODO
+5-11 files

NetBSD/pkgsrc-wip 0fe8d42libks TODO

libks: Add reference to recent CVE
DeltaFile
+2-0libks/TODO
+2-01 files

NetBSD/pkgsrc-wip 1466125oras TODO

oras: Add reference to recent CVEs
DeltaFile
+1-1oras/TODO
+1-11 files

NetBSD/pkgsrc-wip 3e7a105hoverfly TODO

hoverfly: Add reference to recent CVEs
DeltaFile
+2-1hoverfly/TODO
+2-11 files

NetBSD/pkgsrc rUSjenjdoc CHANGES-2026

   doc: Updated www/R-webfakes to 1.5.0
VersionDeltaFile
1.6132+2-1doc/CHANGES-2026
+2-11 files

NetBSD/pkgsrc 1Nne2eWwww/R-webfakes Makefile distinfo

   R-webfakes: update to 1.5.0.

   Build fix.

   # webfakes 1.5.0

   * New `keep_alive_timeout_ms` option in `server_opts()` to configure the
     idle timeout of keep-alive connections. The default is 5000 ms, up from
     the underlying CivetWeb default of 500 ms (#114).

   * Handler functions may now declare a `locals` argument, in which case
     webfakes passes `app$locals` to it directly, without having to access
     it through `req$app$locals` (#112).

   * webfakes now builds on platforms where `ar` does not writes a symbol
     index by default (@barracuda156, #121).

   * webfakes now parses HTTP date headers (e.g. `Date`, `Last-Modified`,
     `Expires`) correctly regardless of the user's `LC_TIME` setting

    [20 lines not shown]
VersionDeltaFile
1.6+4-4www/R-webfakes/distinfo
1.6+4-2www/R-webfakes/Makefile
+8-62 files

NetBSD/pkgsrc deE4kDsdoc CHANGES-2026 TODO

   doc: Updated math/R-XML to 3.99.0.24
VersionDeltaFile
1.27930+3-2doc/TODO
1.6131+2-1doc/CHANGES-2026
+5-32 files

NetBSD/pkgsrc hcizx5Kmath/R-XML Makefile distinfo

   R-XML: update to 3.99.0.24.

   Fix build against libxml2 2.15.

   ============ entries from Ivan Krylov ============

   Version 3.99-0.24
        Fixed obsolete attribute names in structure() calls
        Removed links that started failing URL checks
        The DTD introspection interface is now defunct

   Version 3.99-0.23
        Fixed issues detected by 'rchk'
        Replaced the use of non-API 'Rf_findVarInFrame' with 'eval'

   Version 3.99-0.22
        Disabled DTD introspection API

   ============ entries from CRAN ============

    [4 lines not shown]
VersionDeltaFile
1.20+4-4math/R-XML/distinfo
1.34+2-3math/R-XML/Makefile
+6-72 files

NetBSD/pkgsrc hpD4OZvemulators/qemu Makefile

   qemu: disable the ParavirtualizedGraphics (pvg) driver on macOS 27

   The driver got broken by Apple's changes and there is no upstream fix yet.

   Side note: Claude was able to cook up a patch but it is tainted and would
   not comply with upstream's nor TNF's policy so you will not find it here.
VersionDeltaFile
1.414+6-1emulators/qemu/Makefile
+6-11 files

NetBSD/pkgsrc qmvdcs0security/nettle distinfo, security/nettle/patches patch-config.make.in patch-Makefile.in

   security/nettle: build fix

   provide the libtool tag for compile and link phases, so that libtool
   doesn't try to infer anything
VersionDeltaFile
1.15+5-5security/nettle/patches/patch-Makefile.in
1.4+3-3security/nettle/patches/patch-config.make.in
1.35+3-3security/nettle/distinfo
+11-113 files

NetBSD/src gtQrljJdoc CHANGES 3RDPARTY

   new bind
VersionDeltaFile
1.2250+3-3doc/3RDPARTY
1.3295+2-1doc/CHANGES
+5-42 files

NetBSD/src szWH4hZcommon/lib/libc/arch/mips/atomic membar_ops.S

   mips membar_ops.S: Cite more evidence Octeon doesn't reorder loads.
VersionDeltaFile
1.15+29-4common/lib/libc/arch/mips/atomic/membar_ops.S
+29-41 files

NetBSD/src 5DcC9Cgdistrib/sets/lists/base shl.mi, distrib/sets/lists/debug shl.mi

   bump libdns
VersionDeltaFile
1.1050+3-3distrib/sets/lists/base/shl.mi
1.414+2-2distrib/sets/lists/debug/shl.mi
+5-52 files

NetBSD/src ON3ZASgexternal/mpl/bind/dist/lib/dns rdatalist.c stats.c, external/mpl/bind/dist/lib/isccfg kaspconf.c

   merge changes between bind-9.20.27 and bind-9.20.29
VersionDeltaFile
1.3+525-573external/mpl/bind/dist/tests/isc/dnsstream_utils_test_data.h
1.24+337-141external/mpl/bind/dist/lib/dns/validator.c
1.12+167-126external/mpl/bind/dist/lib/dns/stats.c
1.31+122-136external/mpl/bind/dist/lib/ns/query.c
1.10+40-165external/mpl/bind/dist/lib/dns/rdatalist.c
1.13+102-76external/mpl/bind/dist/lib/isccfg/kaspconf.c
+1,293-1,217243 files not shown
+3,162-2,203249 files

NetBSD/src 6QdcGjuexternal/mpl/bind/dist/bin/tests/system/rollover tests_rollover_algo_ksk_zsk_reconfig.py tests_rollover_csk_roll2.py, external/mpl/bind/dist/doc/changelog changelog-9.20.29.rst

   Import bind-9.20.29 (previous was 9.20.27)

   BIND 9.20.29
   Security Fixes
   [CVE-2026-19668] Prevent excessive CPU use validating crafted DNSSEC
   responses. a0a61dba9e
     A malicious authoritative server could serve a securely delegated zone
     whose DS and DNSKEY records carry many distinct key tags but no valid
     match, forcing a validating resolver into excessive key-tag matching
     and high CPU use for every query. BIND now bounds this work with the
     per-query validation limit (max-validations-per-fetch). [GL #5349]

   [CVE-2026-19033] Require a TSIG on every message of incoming zone
   transfers. 9404cd2b8c
     BIND 9 used to accept TSIG-signed zone transfers in which some messages
     were unsigned, and processed those messages before the next signature
     could vouch for them. It now requires a TSIG on every message of an
     incoming AXFR or IXFR; all modern nameserver already sign every message,
     so no change is expected in practice. [GL #6062]

    [327 lines not shown]
VersionDeltaFile
1.1.1.2+524-572external/mpl/bind/dist/tests/isc/dnsstream_utils_test_data.h
1.1.1.22+336-140external/mpl/bind/dist/lib/dns/validator.c
1.1+454-0external/mpl/bind/dist/bin/tests/system/rollover/tests_rollover_csk_roll1.py
1.1+443-0external/mpl/bind/dist/doc/changelog/changelog-9.20.29.rst
1.1+430-0external/mpl/bind/dist/bin/tests/system/rollover/tests_rollover_csk_roll2.py
1.1+381-0external/mpl/bind/dist/bin/tests/system/rollover/tests_rollover_algo_ksk_zsk_reconfig.py
+2,568-7121,201 files not shown
+19,252-9,3871,207 files

NetBSD/src gbOcu3xsys/arch/mips/include asm.h

   mips/asm.h: Tidy typography of SYNC_PLUNGER comment block.

   And fix a misquoted register number to make it make sense.

   The CN78XX manual's typography got all screwed up; the CN50XX manual
   is clearer (and maybe we should just quote from that one instead but
   whatever).
VersionDeltaFile
1.80+11-7sys/arch/mips/include/asm.h
+11-71 files

NetBSD/src 1EVf6tvsys/arch/mips/include asm.h

   mips/asm.h: Add some citations for MFC0_HAZARD.

   No functional change intended, comment only.
VersionDeltaFile
1.79+47-2sys/arch/mips/include/asm.h
+47-21 files

NetBSD/pkgsrc-wip 8431799libks PLIST

libks: Remove +x bits

PLIST does not need to be executable.
DeltaFile
+0-0libks/PLIST
+0-01 files

NetBSD/pkgsrc-wip 0a0bcabllama.cpp TODO

llama.cpp: Add reference to CVE-2026-86317
DeltaFile
+1-1llama.cpp/TODO
+1-11 files

NetBSD/pkgsrc-wip bdfc9d1gnome-tweaks TODO

gnome-tweaks: Add reference to CVE-2026-74859
DeltaFile
+3-0gnome-tweaks/TODO
+3-01 files

NetBSD/src qa5Vuj0usr.sbin/npf/npfctl npf_build.c

   improve table load error in npf

   an EEXIST should clearly state already defined and a load failure should
   also clearly be stated. do not class all error returns under EEXIST
   since npf_table_insert can return other errors aside EEXIST.
VersionDeltaFile
1.64+6-2usr.sbin/npf/npfctl/npf_build.c
+6-21 files

NetBSD/src paYjKCXdoc CHANGES 3RDPARTY

   new unbound
VersionDeltaFile
1.2249+4-4doc/3RDPARTY
1.3294+2-1doc/CHANGES
+6-52 files

NetBSD/src BJ2pYRadistrib/sets/lists/base shl.mi, distrib/sets/lists/debug shl.mi

   bump libunbound
VersionDeltaFile
1.413+2-2distrib/sets/lists/debug/shl.mi
1.1049+2-2distrib/sets/lists/base/shl.mi
+4-42 files

NetBSD/src OJ4x8gZexternal/bsd/unbound/dist config.sub config.guess, external/bsd/unbound/dist/services authzone.c

   merge changes between unbound 1.25.1 and 1.26.1
VersionDeltaFile
1.7+465-108external/bsd/unbound/dist/services/authzone.c
1.10+215-37external/bsd/unbound/dist/util/netevent.c
1.18+35-3external/bsd/unbound/include/config.h
1.5+18-0external/bsd/unbound/lib/libunbound/unbound.expsym
1.10+11-6external/bsd/unbound/dist/config.guess
1.9+6-5external/bsd/unbound/dist/config.sub
+750-1591 files not shown
+752-1617 files

NetBSD/src fayiV3Bexternal/bsd/unbound/dist/doc Changelog, external/bsd/unbound/dist/testdata dns64_dnssec.rpl sub_ds_deepcopy.rpl

   Import unbound-1.26.1 (previous was unbound-1.25.1)

   Unbound 1.26.1
   ==============
   This release has a number of security fixes.
   The release is signed with the OpenPGP software signing key that is
   in use since Jan 1st 2026:
   User ID: NLnet Labs releases signing key G2 releases at nlnetlabs.nl
   Key ID: A144 323D EAAC DF45
   Fingerprint: 2310 1869 0C4D 903E F419  146A A144 323D EAAC DF45

   The key is available from https://nlnetlabs.nl/signing-keys .
   This release consolidates security fixes for issues reported over
   a period of time. There are fixes for CVE-2026-77860, CVE-2026-77955,
   CVE-2026-78227, CVE-2026-80225, CVE-2026-81634, CVE-2026-81642,
   CVE-2026-82717, CVE-2026-82720 and CVE-2026-85501.

   Bug Fixes
   Fix CVE-2026-81642, Heap buffer overflow and possible Remote Code

    [325 lines not shown]
VersionDeltaFile
1.1.1.12+3,895-3,821external/bsd/unbound/dist/util/configlexer.c
1.1.1.12+2,223-2,141external/bsd/unbound/dist/util/configparser.c
1.1+1,202-0external/bsd/unbound/dist/testdata/edns_nsid_repeat.rpl
1.1+676-0external/bsd/unbound/dist/testdata/sub_ds_deepcopy.rpl
1.1+609-0external/bsd/unbound/dist/testdata/dns64_dnssec.rpl
1.1.1.12+577-0external/bsd/unbound/dist/doc/Changelog
+9,182-5,962275 files not shown
+24,458-7,671281 files

NetBSD/pkgsrc GOROJAGdoc CHANGES-2026

   doc: Updated www/drupal11 to 11.4.7
VersionDeltaFile
1.6130+2-1doc/CHANGES-2026
+2-11 files

NetBSD/pkgsrc OR1iOqwwww/drupal11 Makefile distinfo

   www/drupal11: update to 11.4.7

   This is security update.

   11.4.5 (2026-08-06)

   This is a patch (bugfix) release of Drupal 11 and is ready for use on
   production sites. Learn more about the latest version of Drupal.

        https://www.drupal.org/project/drupal/releases/11.4.5

   11.4.6 (2026-09-03)

   This is a patch (bugfix) release of Drupal 11 and is ready for use on
   production sites. Learn more about the latest version of Drupal.

        https://www.drupal.org/project/drupal/releases/11.4.6

   11.4.7 (2026-09-16)

    [12 lines not shown]
VersionDeltaFile
1.6+32-24www/drupal11/PLIST
1.6+4-4www/drupal11/distinfo
1.13+2-2www/drupal11/Makefile
+38-303 files