NetBSD/pkgsrc gBHkU0Pdoc CHANGES-2026

   Updated security/pcsc-lite, security/dropbear
VersionDeltaFile
1.3321+3-1doc/CHANGES-2026
+3-11 files

NetBSD/pkgsrc EExHqjisecurity/dropbear/patches patch-src_scp.c

   dropbear: add new patch
VersionDeltaFile
1.1+29-0security/dropbear/patches/patch-src_scp.c
+29-01 files

NetBSD/pkgsrc BxvlxqVsecurity/dropbear distinfo Makefile

   dropbear: updated to 2026.91

   2026.91 - 10 May 2026

   - scp: Fix test for disallowing -r with existing target directory. The logic
     introduced in 2026.90 was incorrect, could also disallow non-recursive
     transfers.

   - scp: Fix regression in 2026.90 building on older glibc or other libc.
     reallocarray() was required, it is no longer needed.

   - Compression is now disabled by default for dbclient. A new -o compression option
     can enable it. DROPBEAR_CLI_COMPRESSION in localoptions.h can change the default.
     Enabling compression can be a security weakness in some
     circumstances, as the size of network traffic may leak information
     about the encrypted data.

   - Added '-Q' argument for dbclient and dropbear to query supported algorithms,
     kex sig cipher mac compress
VersionDeltaFile
1.39+5-4security/dropbear/distinfo
1.47+2-2security/dropbear/Makefile
+7-62 files

NetBSD/pkgsrc QtdJMLTsecurity/pcsc-lite distinfo Makefile

   pcsc-lite: updated to 2.5.0

   2.5.0: Ludovic Rousseau
   27 May 2026
   - Do not limit to 16 readers only
   - Remove support of autotools
   - Fix a crash when rescanning serial configs
   - Fix a memory leak in Polkit
   - tokenparser: avoid a crash with corrupted Info.plist files
   - Some other minor improvements
VersionDeltaFile
1.45+4-4security/pcsc-lite/distinfo
1.57+2-2security/pcsc-lite/Makefile
+6-62 files

NetBSD/pkgsrc 3c5ncp6doc CHANGES-2026

   Updated textproc/py-myst-parser, security/py-google-auth-oauthlib
VersionDeltaFile
1.3320+3-1doc/CHANGES-2026
+3-11 files

NetBSD/pkgsrc dwujuh0security/py-google-auth-oauthlib Makefile distinfo

   py-google-auth-oauthlib: updated to 1.4.0

   1.4.0 (2026-05-06)

   Bug Fixes

   Drop support for Python 3.9
   replace deprecated utcfromtimestamp in google-auth-oauthlib
VersionDeltaFile
1.29+5-5security/py-google-auth-oauthlib/Makefile
1.24+4-4security/py-google-auth-oauthlib/distinfo
+9-92 files

NetBSD/pkgsrc nhfKG6rtextproc/py-myst-parser Makefile distinfo

   py-myst-parser: updated to 5.1.0

   5.1.0 - 2026-05-13

   New Features

   - Add `"alert"` syntax extension for [GFM alerts](https://docs.github.com/en/get-started/writing-on-github/getting-started-with-writing-and-formatting-on-github/basic-writing-and-formatting-syntax#alerts) (e.g. `> [!NOTE]`), see [](syntax/alerts)
   - Add `"gfm_autolink"` syntax extension for [GFM autolinks](https://github.github.com/gfm/#autolinks-extension-), see [](syntax/gfm-autolink)
   - Add `myst_strikethrough_single_tilde` [config option](sphinx/config-options) to allow single tilde (`~`) for strikethrough
   - Add `myst_colon_fence_exact_match` [config option](sphinx/config-options) to require the closing colon fence to have exactly the same number of colons as the opening, see [](syntax/colon_fence)

   Improvements

   - Update [`myst_gfm_only`](sphinx/config-options) mode to use the unified `gfm_plugin`, which now includes GFM autolinks, alerts, and improved strikethrough/tasklist handling
   - Improve MathJax 4 compatibility for Sphinx 9
   - Stop directive-option parsing at colon fences, fixing nested colon fence directives

   Bug Fixes


    [4 lines not shown]
VersionDeltaFile
1.11+8-11textproc/py-myst-parser/Makefile
1.6+4-4textproc/py-myst-parser/distinfo
+12-152 files

NetBSD/pkgsrc mbCbAiEdoc CHANGES-2026

   Updated www/py-tornado, textproc/py-sphinx-issues
VersionDeltaFile
1.3319+3-1doc/CHANGES-2026
+3-11 files

NetBSD/pkgsrc fyXMmTttextproc/py-sphinx-issues distinfo Makefile

   py-sphinx-issues: updated to 6.0.0

   6.0.0 (2026-03-13)

   Backwards-incompatible: Remove implicit extraction of group/project from GitHub URLs in issues_uri. If you relied on setting _only_ issues_uri (e.g. https://github.com/myuser/myproject/issues/{issue}) without also setting issues_github_path or issues_default_group_project, you must now explicitly set one of those options in your conf.py:

   Before:

   issues_uri = "https://github.com/myuser/myproject/issues/{issue}"
   After:

   issues_github_path = "myuser/myproject"
   Support Python 3.10-3.14. 3.9 is no longer supported, as it is EOL.

   Pin lower bound of Sphinx to 8.1.0 (see "Sphinx version support policy above").
VersionDeltaFile
1.7+4-4textproc/py-sphinx-issues/distinfo
1.15+3-3textproc/py-sphinx-issues/Makefile
+7-72 files

NetBSD/pkgsrc Te6HikAwww/py-tornado distinfo Makefile

   py-tornado: updated to 6.5.6

   6.5.6

   Security fixes

   SimpleAsyncHTTPClient now strips the Authorization and Cookie headers from the request when following a redirect to a different origin. This matches the default behavior of CurlAsyncHTTPClient. Applications that need different behavior here can set follow_redirects=False and handle redirects manually. Thanks to [Yannick Wang](https://github.com/noobone123) for being first to report this issue, as well as additional reporters [Kai Aizen](https://github.com/SnailSploit), [HunSec](https://github.com/0xHunSec), and [Thai Son Dinh](https://github.com/sondt99).
   SimpleAsyncHTTPClient now enforces max_body_size on the decompressed size of the response, rather than the compressed size. This prevents a denial-of-service attack via a very large compressed response. Thanks to [Yuichiro Kedashiro](https://github.com/yuui25) for reporting this issue.
   Fixed a bug in the C extension that could have read up to three bytes past the end of an input array. Thanks to [Thai Son Dinh](https://github.com/sondt99) for reporting this issue.
   OpenIDMixin has improved parsing for the check_authentication response. Thanks to [Yannick Wang](https://github.com/noobone123) for reporting this issue.

   Bug fixes

   CurlAsyncHTTPClient has been updated to use non-deprecated APIs, avoiding deprecation warnings with recent versions of pycurl.
VersionDeltaFile
1.36+4-4www/py-tornado/distinfo
1.48+2-2www/py-tornado/Makefile
+6-62 files

NetBSD/pkgsrc zugya01doc CHANGES-2026

   Updated textproc/py-sphinx-autodoc-typehints, net/py-apache-libcloud
VersionDeltaFile
1.3318+3-1doc/CHANGES-2026
+3-11 files

NetBSD/pkgsrc o7fLwITnet/py-apache-libcloud distinfo PLIST

   py-apache-libcloud: updated to 3.9.1

   Changes in Apache Libcloud 3.9.1

   Compute

   - [VSphere] Add verify_ssl option
     Add verify_ssl option, to enable the user to avoid SSL verification explicitly.
   - [OpenStack] Initial Blazar support
     This is an initial implementation of Blazar support in Libcloud. It currently
     supports listing the available leases and hosts.
   - [Azure ARM] Update US GovCloud AD endpoint for AZURE_ARM provider.
   - [OpenStack] Add hypervisor_hostname attribute to OpenStack node.
   - [GCP]  Use the fully-qualified name for the GCP IMDS endpoint.
   - [Azure ARM, Amazon S3] Add signed upload to azure and s3.
   - [RcodeZero]: Fix issue when adding a record where a record with a different type already exists

   DNS


    [8 lines not shown]
VersionDeltaFile
1.16+4-4net/py-apache-libcloud/distinfo
1.14+3-1net/py-apache-libcloud/PLIST
1.22+2-2net/py-apache-libcloud/Makefile
+9-73 files

NetBSD/pkgsrc GwxU5h1textproc/py-sphinx-autodoc-typehints distinfo Makefile

   py-sphinx-autodoc-typehints: updated to 3.10.3

   3.10.3

   Show version in error tracebacks
   Support PEP 695 type statement and python 3.12+ TypeAliasType
   Fix typehints_formatter cache warning
   fix(stubs): resolve type hints for PyO3 native submodules
VersionDeltaFile
1.41+4-4textproc/py-sphinx-autodoc-typehints/distinfo
1.51+2-2textproc/py-sphinx-autodoc-typehints/Makefile
+6-62 files

NetBSD/pkgsrc QAovy0odoc CHANGES-2026

   Added security/cargo-deny; Updated devel/py-test_socket
VersionDeltaFile
1.3317+3-1doc/CHANGES-2026
+3-11 files

NetBSD/pkgsrc RYicU2sdevel/py-test_socket Makefile PLIST

   py-test_socket: updated to 0.8.0

   0.8.0

   Enhancements:

   Block DNS resolution (getaddrinfo, gethostbyname) when sockets are disabled
   Support CIDR network ranges in allow_hosts
   Warn before raising on a blocked socket call
   Cache hostname resolutions during a test run

   Changes:

   Removed support for Python 3.8 and 3.9. Python 3.10 is now the minimum.
   Test against Python 3.13, 3.14, and free-threaded 3.13t/3.14t
   Replaced Poetry with uv
   Added type hints
   Swapped pytest-httpbin for a local test fixture
   Dependency, CI, and development updates
VersionDeltaFile
1.5+4-5devel/py-test_socket/Makefile
1.4+5-4devel/py-test_socket/PLIST
1.3+4-4devel/py-test_socket/distinfo
+13-133 files

NetBSD/pkgsrc QVaic17security Makefile, security/cargo-deny distinfo cargo-depends.mk

   cargo-deny: added version 0.19.8

   cargo-deny is a cargo plugin that lets you lint your project's dependency graph
   to ensure all your dependencies conform to your expectations and requirements.
VersionDeltaFile
1.1+641-0security/cargo-deny/distinfo
1.1+214-0security/cargo-deny/cargo-depends.mk
1.1+17-0security/cargo-deny/Makefile
1.1009+2-1security/Makefile
1.1+2-0security/cargo-deny/PLIST
1.1+2-0security/cargo-deny/DESCR
+878-16 files

NetBSD/src ut0h5Dxbin/sh var.c sh.1

   PR bin/58609 - enable locale var internal manipulation

   sh now recognises the (standard) set of locale variables, and in addition
   to setting up the locale environment to match those in the environment at
   startup (which it has done for ages), now also causes alterations to those
   variables while the shell is running to take immediate effect inside sh,
   which can affect how the shell operates in some limited aspects - previously
   such updates would be passed to exec'd child processes (not subshells)
   if the variables are exported, and not affect the running shell at all.

   See the PR, and the updated sh(1) man page, for details.

   This is a feature enhancement, no pullups (not even to -11) are planned.
VersionDeltaFile
1.91+243-5bin/sh/var.c
1.277+230-7bin/sh/sh.1
1.74+29-37bin/sh/histedit.c
1.17+9-7bin/sh/myhistedit.h
1.63+8-7bin/sh/options.c
1.42+12-2bin/sh/var.h
+531-653 files not shown
+543-749 files

NetBSD/src DtqNrf5sys/dev/ic dwc_eqos.c dwc_eqos_var.h

   eqos: Various performance improvements.

   - Use BUS_DMA_COHERENT for ring descriptors, allowing us to remove
     the descriptor padding (which increased memory usage and bandwidth).
     Be very careful to avoid unnecessary reads and writes of uncached
     memory!
   - Defer TX/RX to a workqueue. This is mostly to help the scheduler, which
     doesn't seem to understand that a CPU busy processing interrupts is
     maybe not the best place to run a process on an otherwise idle system.
VersionDeltaFile
1.44+86-33sys/dev/ic/dwc_eqos.c
1.12+5-1sys/dev/ic/dwc_eqos_var.h
1.11+2-2sys/dev/ic/dwc_eqos_reg.h
+93-363 files

NetBSD/pkgsrc ohyAIE6doc CHANGES-2026

   Updated www/freenginx-devel to 1.31.2
VersionDeltaFile
1.3316+2-1doc/CHANGES-2026
+2-11 files

NetBSD/pkgsrc vZrl8mMwww/freenginx-devel distinfo Makefile

   www/freenginx-devel: update from 1.31.1 to 1.31.2

   Sponsored by:        tipi.work

   <ChangeLog>

   *) Bugfix: a segmentation fault might occur in a worker process if
      nested captures were used in the "rewrite" directive.

   *) Bugfix: the "if" directive incorrectly handled relative paths when
      checking files.

   </ChangeLog>
VersionDeltaFile
1.13+4-4www/freenginx-devel/distinfo
1.15+2-3www/freenginx-devel/Makefile
+6-72 files

NetBSD/src c4JbBsoexternal/mit/xorg/lib/libepoxy Makefile

   libepoxy: Update the pkg-config file for new reality.

   PR pkg/60295 x11/gtk3 does not build on NetBSD/macppc
VersionDeltaFile
1.11+2-2external/mit/xorg/lib/libepoxy/Makefile
+2-21 files

NetBSD/src Pd3syDFbin/sh sh.1

   Whitespace & a wrong word fixed.
VersionDeltaFile
1.276+5-5bin/sh/sh.1
+5-51 files

NetBSD/pkgsrc-wip d328db4terrascan TODO

terrascan: Add reference to recent CVEs
DeltaFile
+2-0terrascan/TODO
+2-01 files

NetBSD/pkgsrc-wip e28d111py-apscheduler TODO

py-apscheduler: Add reference to CVE-2026-31072
DeltaFile
+2-0py-apscheduler/TODO
+2-01 files

NetBSD/pkgsrc-wip bed21dbsipp TODO

sipp: Add reference to CVE-2018-25356
DeltaFile
+1-1sipp/TODO
+1-11 files

NetBSD/pkgsrc SgJ979Pdevel/qt6-qttools distinfo, devel/qt6-qttools/patches patch-src_qdoc_qdoc_src_qdoc_clangcodeparser.cpp patch-src_qdoc_cmake_QDocConfiguration.cmake

   qt6-qttools: support LLVM 22
VersionDeltaFile
1.1+18-0devel/qt6-qttools/patches/patch-src_qdoc_qdoc_src_qdoc_clangcodeparser.cpp
1.1+15-0devel/qt6-qttools/patches/patch-src_qdoc_cmake_QDocConfiguration.cmake
1.26+3-1devel/qt6-qttools/distinfo
+36-13 files

NetBSD/pkgsrc 2TrzFc6doc CHANGES-2026

   Updated multimedia/libde265, security/ccid
VersionDeltaFile
1.3315+3-1doc/CHANGES-2026
+3-11 files

NetBSD/pkgsrc BOf8fyFsecurity/ccid Makefile distinfo

   ccid: updated to 1.8.0

   1.8.0

   Add support of
   - GLSolutions NM61 PC/SC
   - Identiv uTrust FIDO2 Security Key
   - Kensington VeriMark NFC+ USB-C Security Key
   - MARX CryptoTech LP Tokey 3 FIDO
   - mCore Contact-Reader
   - mCore Contactless-Reader
   - mCore DualSlot-Reader
   - Pol Henarejos Pico Fido
   - Pol Henarejos Pico HSM
   - Pol Henarejos Pico OpenPGP
   - Richmond Technologies CO. LLC AEGIS PRO4 Smart Card Reader
   - SCR Prime
   Remove the limitation to 16 readers
   udev: Update rules file to comply with systemd documentation

    [6 lines not shown]
VersionDeltaFile
1.53+14-29security/ccid/Makefile
1.32+4-4security/ccid/distinfo
+18-332 files

NetBSD/pkgsrc 2dIVUZRmultimedia/libde265 distinfo Makefile

   libde265: updated to 1.1.0

   1.1.0

   Added de265_security_limits parameters to limit the maximum image size and memory that libde265 will use during decoding.

   Security fixes

   CVE TBD (GHSA-g2rg-wj66-w594) - Out-of-bounds write in process_reference_picture_set via predicted short-term RPS
   CVE TBD (GHSA-vv8h-932h-7r86) - Heap buffer overflow in de265_image_get_buffer via SPS dimension integer overflow
   CVE TBD (GHSA-g5hj-rf9f-7vxm) - Unbounded memory accumulation via orphaned slice headers in read_slice_NAL
   (GHSA-x27c-jp65-g395) - Quadratic CPU consumption in NAL parser (remove_stuffing_bytes, resize)
VersionDeltaFile
1.17+4-4multimedia/libde265/distinfo
1.21+3-3multimedia/libde265/Makefile
1.6+2-2multimedia/libde265/PLIST
+9-93 files

NetBSD/pkgsrc MjG8XMYdoc CHANGES-2026

   Updated emulators/qemu, sysutils/qemu-guest-agent, devel/py-typer
VersionDeltaFile
1.3314+4-1doc/CHANGES-2026
+4-11 files