NetBSD/pkgsrc afMiJE8 — doc CHANGES-2026

   Updated security/flawfinder, devel/py-mocket
VersionDeltaFile
1.6789+3-1doc/CHANGES-2026
+3-11 files

NetBSD/pkgsrc jcGho2n — devel/py-mocket Makefile distinfo

   py-mocket: updated to 3.14.5

   3.14.5

   Pinning right version for typing-extensions
   Preserve encoded query parameters in recorded requests
VersionDeltaFile
1.21+4-4devel/py-mocket/distinfo
1.21+2-2devel/py-mocket/Makefile
+6-62 files

NetBSD/pkgsrc xsNUWnz — security/flawfinder distinfo Makefile

   flawfinder: updated to 2.0.20

   2.0.20
     Fix unlikely vulnerabilities (involving malicious filenames/text
     in analyzed systems) and implement various improvements
   * Fix security vulnerabilities found by Gemini:
     - Terminal injection in standard output: apply strip_controls() to
       level and category in show().
     - Terminal injection in CSV output: apply strip_controls() to all
       untrusted fields in show_csv() (category, name, warning,
       suggestion, note, context_text).
     - XML injection in SonarQube output: use quoteattr() for all XML
       attributes in output_sonar().
     - Defense-in-depth: restrict setattr in Hit.__init__ to an allowlist
       of known keys used by rule definitions, countering pickle attacks.
       We previously warned to not load untrusted pickle files, but
       completely preventing attacks is better.
     - Shell injection in CI/CD file entrypoint.sh:
       quoted args with "$@" and moved output filename to

    [86 lines not shown]
VersionDeltaFile
1.3+8-7security/flawfinder/PLIST
1.32+7-6security/flawfinder/Makefile
1.13+4-4security/flawfinder/distinfo
+19-173 files

NetBSD/pkgsrc jn6dMho — doc CHANGES-2026

   Updated devel/py-click-repl, devel/py-cachetools
VersionDeltaFile
1.6788+3-1doc/CHANGES-2026
+3-11 files

NetBSD/pkgsrc FMfLUCQ — devel/py-cachetools Makefile distinfo

   py-cachetools: updated to 7.2.1

   v7.2.1 (2026-10-05)

   - Improve error handling for ``RRCache.popitem()`` when the cache is
     empty.
   - Minor style and documentation improvements.
   - Update CI environment.


   v7.2.0 (2026-09-16)

   - Deprecate use of ``cache=None`` to suppress caching with the
     ``@cached`` decorator.
   - Add support for Python 3.15.
   - Minor test improvements.
   - Minor documentation updates.
VersionDeltaFile
1.41+4-4devel/py-cachetools/distinfo
1.42+3-3devel/py-cachetools/Makefile
+7-72 files

NetBSD/pkgsrc kraErYm — devel/py-click-repl Makefile distinfo

   py-click-repl: updated to 0.4.1

   0.4.1
   Guard click-repl import when stdin is unavailable
VersionDeltaFile
1.7+4-4devel/py-click-repl/distinfo
1.7+2-2devel/py-click-repl/Makefile
+6-62 files

NetBSD/pkgsrc kqOVCQC — doc CHANGES-2026

   Updated devel/py-rpds-py, sysutils/py-borgmatic
VersionDeltaFile
1.6787+3-1doc/CHANGES-2026
+3-11 files

NetBSD/pkgsrc gnQFWT0 — sysutils/py-borgmatic Makefile distinfo

   py-borgmatic: updated to 2.1.10

   2.1.10
   Unknown changes
VersionDeltaFile
1.3+10-1sysutils/py-borgmatic/PLIST
1.3+4-4sysutils/py-borgmatic/distinfo
1.3+3-3sysutils/py-borgmatic/Makefile
+17-83 files

NetBSD/pkgsrc G94yBCx — devel/py-rpds-py Makefile cargo-depends.mk

   py-rpds-py: updated to 2026.9.1

   2026.9.1
   Unknown changed
VersionDeltaFile
1.29+25-25devel/py-rpds-py/distinfo
1.20+7-7devel/py-rpds-py/cargo-depends.mk
1.32+2-2devel/py-rpds-py/Makefile
+34-343 files

NetBSD/pkgsrc 4yP0SxO — www/firefox128 distinfo Makefile, www/firefox128/patches patch-gfx_wr_webrender_src_texture__cache.rs

   Fix build of firefox128 with latest rust

   (Based on changed in firefox140)

   Approved by ryo
VersionDeltaFile
1.1+29-0www/firefox128/patches/patch-gfx_wr_webrender_src_texture__cache.rs
1.41+2-2www/firefox128/Makefile
1.23+2-1www/firefox128/distinfo
+33-33 files

NetBSD/pkgsrc OvYuVdd — doc CHANGES-2026

   Updated www/py-jwcrypto, www/py-uvicorn, net/py-scp
VersionDeltaFile
1.6786+4-1doc/CHANGES-2026
+4-11 files

NetBSD/pkgsrc jM8pklC — net/py-scp Makefile distinfo

   py-scp: updated to 0.16.2

   0.16.2 (2026-10-06)

   - Catch `EOFError` from `channel.close()` that happens sporadically on some devices
   - Check erroneous server path on download
VersionDeltaFile
1.18+4-4net/py-scp/distinfo
1.23+3-3net/py-scp/Makefile
+7-72 files

NetBSD/pkgsrc Wzsl1Pq — www/py-uvicorn Makefile distinfo

   py-uvicorn: updated to 0.54.0

   0.54.0

   Send metadata after the response body

   uvicorn 0.54.0 adds response trailers and 103 Early Hints to its experimental HTTP/2 implementation through zttp.

   uv add uvicorn==0.54.0 "zttp>=0.0.34"
   Send HTTP/2 response trailers. The ASGI http.response.trailers extension lets applications send metadata, such as checksums, after the response body. Clients must send TE: trailers to receive them. Multiple trailer messages are combined before completing the response.
   HTTP/2 remains experimental and opt-in. Enable it with --http zttp --http2. Upgrade-based h2c and WebSockets over HTTP/2 remain unsupported.

   Hint at resources before the final response

   Send 103 Early Hints over HTTP/2. Applications can use the ASGI http.response.early_hint extension to send resource hints before the final response. Each supplied link becomes a separate Link header.
VersionDeltaFile
1.18+10-1www/py-uvicorn/PLIST
1.63+4-4www/py-uvicorn/distinfo
1.72+2-2www/py-uvicorn/Makefile
+16-73 files

NetBSD/pkgsrc fGmjihL — www/py-jwcrypto Makefile distinfo

   py-jwcrypto: updated to 1.6.1

   1.6.1

   This release fixes CVE-2026-92091, a low security issue that may result in a Denial of Service on malformed JWK keys
VersionDeltaFile
1.13+4-4www/py-jwcrypto/distinfo
1.17+2-2www/py-jwcrypto/Makefile
+6-62 files

NetBSD/pkgsrc ySKyItg — doc CHANGES-2026

   Updated devel/py-typer, devel/py-utils
VersionDeltaFile
1.6785+3-1doc/CHANGES-2026
+3-11 files

NetBSD/pkgsrc XJsc21m — devel/py-utils distinfo Makefile

   py-utils: updated to 4.1.0

   4.1.0

   Keep UniqueList membership in sync when replacing an indexed item, and leave membership unchanged when the index is out of range, contributed
   Keep UniqueList membership in sync for slice assignment, extend, pop, remove, clear, += and *=, so extend and += no longer add duplicates and removed values can be added again.
   Accept one-shot iterables in UniqueList slice assignment, allow a slice to reuse the values it replaces, and reject a slice that repeats a value.
   Make copy.copy and copy.deepcopy of a UniqueList return a working copy with its own membership.
   Leave UniqueList membership unchanged when insert fails, and answer in for an unhashable value the way a list does.
   Make CastedDict and LazyCastedDict load from pickle on every protocol, including pickles written by 4.0.1, and stop copy.copy and copy.deepcopy from casting the stored values a second time.
   Cast what setdefault and |= store in a CastedDict or LazyCastedDict. A None default is stored as it is.
   Cast the key of a LazyCastedDict once when it is stored. It was cast twice.
   Let keyword arguments win over the mapping in update and the constructor of the casted dicts, as dict does.
   Make != the opposite of == for SliceableDeque, and compare unequal to a set when an item is unhashable.
   Remove the iterable of mappings from the DictUpdateArgs type alias. The code never accepted that shape.
   Log the traceback in Logged.exception(), and name the caller in every record of Logged instead of logger.py. Code that passed stacklevel=2 to work around the wrong caller now points one frame too high.
   Stop Logurud from crashing on a message with a brace in it. A message without arguments is logged as written, so braces that were doubled to avoid the crash now show doubled.
   Keep the value of a class that combines Logged or Logurud with a type such as int or str.
   Use the whole match in to_int and to_float for a pattern without a group, and never return a negative power from scale_1024.

    [14 lines not shown]
VersionDeltaFile
1.20+6-6devel/py-utils/Makefile
1.18+4-4devel/py-utils/distinfo
+10-102 files

NetBSD/pkgsrc NP6JdIw — devel/py-typer Makefile distinfo

   py-typer: updated to 0.27.3

   0.27.3

   Fixes

   Escape terminal control characters in error messages.
VersionDeltaFile
1.14+4-4devel/py-typer/distinfo
1.14+3-3devel/py-typer/Makefile
+7-72 files

NetBSD/pkgsrc KTPFgL4 — doc CHANGES-2026

   Updated net/openvpn, databases/py-peewee, textproc/py-orjson, textproc/py-tomli
VersionDeltaFile
1.6784+5-1doc/CHANGES-2026
+5-11 files

NetBSD/pkgsrc 5xhe8uT — doc CHANGES-2026

   doc: Updated net/dnscontrol to 5.3.1
VersionDeltaFile
1.6783+2-1doc/CHANGES-2026
+2-11 files

NetBSD/pkgsrc fgEme1J — net/dnscontrol Makefile go-modules.mk

   dnscontrol: Update to 5.3.1

   Changelog
   Provider-specific changes:
   1aed32f: fix(p/BUNNYDNS): return the zone's nameservers and ignore apex NS records (#4970) (@jfexyz)
   Bug fixes:
   094cc35: fix: report IMPORT_TRANSFORM of a non-existent domain instead of crashing (#4969) (@SulimanAbdulrazzaq)
   CI/CD:
   de420a9: build(deps): bump alpine from 3.24.1 to 3.24.2 (#4960) (@dependabot[bot])
   c06740b: build(deps-dev): bump @commitlint/cli from 21.2.2 to 21.2.3 (#4962) (@dependabot[bot])
   91b19cd: build(deps-dev): bump prettier from 3.9.6 to 3.9.9 (#4961) (@dependabot[bot])
   Refactoring:
   2e501ac: refactor: Reduce unused "metadata" parameters in provider initializations (#4959) (@TomOnTime)
VersionDeltaFile
1.15+354-372net/dnscontrol/distinfo
1.16+117-123net/dnscontrol/go-modules.mk
1.51+1-1net/dnscontrol/Makefile
+472-4963 files

NetBSD/pkgsrc tZJmOwb — textproc/py-tomli Makefile distinfo

   py-tomli: updated to 2.5.0

   2.5.0

   Added

   Binary wheels for Python 3.15

   Fixed

   Set nested inline array/table limit to 400 to fix mypyc generated binaries crashing unrecoverably in constrained environments (e.g. worker thread in a python:3.13-alpine image)
VersionDeltaFile
1.12+4-4textproc/py-tomli/distinfo
1.20+2-2textproc/py-tomli/Makefile
+6-62 files

NetBSD/pkgsrc PRwdGh5 — textproc/py-orjson Makefile cargo-depends.mk

   py-orjson: updated to 3.13.0

   3.13.0 - 2026-08-17

   Changed

   - No longer publish PyPI wheels for Windows x86/i686.

   Added

   - Serialize new Python 3.15 built-in type `frozendict` identical to
   `dict` (PEP 814).
VersionDeltaFile
1.26+31-37textproc/py-orjson/distinfo
1.20+9-11textproc/py-orjson/cargo-depends.mk
1.30+3-3textproc/py-orjson/Makefile
+43-513 files

NetBSD/pkgsrc 5AWayHe — databases/py-peewee Makefile distinfo

   py-peewee: updated to 4.5.3

   4.5.3

   * JSON path keys on Postgres are rendered inline (`data->>'key'`,
     `'{"a","b"}'::text[]`) instead of as bound parameters, so `GROUP BY` and
     `ORDER BY` on a JSON lookup work under psycopg3, which binds each occurrence
     of a key as a distinct parameter. Applies to the core `JSONField` and to
     `playhouse.postgres_ext`.
   * `Cast()` and other wrapped nodes over a plain value no longer break result
     row processing.
   * A write query with a `RETURNING` clause now runs again on every explicit
     `execute()` call (like a write query without one). Iterating the query still
     reads the result of the last execution. Previously repeated `execute()`
     calls returned the cached result without running the query.
   * Fix regression in model select `.exists()`
VersionDeltaFile
1.109+4-4databases/py-peewee/distinfo
1.144+2-2databases/py-peewee/Makefile
+6-62 files

NetBSD/pkgsrc bJKtm1c — net/openvpn Makefile.common distinfo, net/openvpn-acct-wtmpx distinfo

   openvpn: updated to 2.7.8

   Overview of changes in 2.7.8

   Security fixes
   - Check for NULL-Bytes in certificate subjects - refuse all such certificates
     now as "invalid" (CVE-2026-84790).
   - TLS handshake with tls-crypt-v2: do not try to add a wrapped client key
     if no key material is available (client bug in response to an ill-behaving
     server).
     (No CVE assigned as "a malicious server can stop the client from working
      properly" is not considered a CVE-worthy security issue according to the
      CRA guidelines)
   - options: fix unsigned underflow when clearing domain_search_list
     (CVE-2026-88964)
   - win32: stop cmd.exe from expanding variables in quoted arguments
     (CVE-2026-84256)

   Bug fixes

    [51 lines not shown]
VersionDeltaFile
1.84+4-4net/openvpn/distinfo
1.56+4-4net/openvpn-nagios/distinfo
1.59+4-4net/openvpn-acct-wtmpx/distinfo
1.53+2-2net/openvpn/Makefile.common
+14-144 files

NetBSD/pkgsrc gvkiOLY — doc CHANGES-2026

   doc: Updated mail/ruby-mime-types-data to 3.2026.1006
VersionDeltaFile
1.6782+2-1doc/CHANGES-2026
+2-11 files

NetBSD/pkgsrc p04fo5P — mail/ruby-mime-types-data Makefile distinfo

   time/ruby-tzinfo-data: update to 1.2026.6

   3.2026.1006 (2026-10-06)

   * Updated registry entries from the IANA media registry and provisional
     media registry and the Apache Tika media registry as of the release date.
VersionDeltaFile
1.58+4-4mail/ruby-mime-types-data/distinfo
1.56+2-2mail/ruby-mime-types-data/Makefile
+6-62 files

NetBSD/pkgsrc PvauLXp — doc CHANGES-2026

   doc: Updated www/palemoon to 35.0.2
VersionDeltaFile
1.6781+3-1doc/CHANGES-2026
+3-11 files

NetBSD/pkgsrc 5bx96Qp — www/palemoon-gtk3 Makefile

   palemoon-gtk3: Reset PKGREVISION for update.
VersionDeltaFile
1.10+1-2www/palemoon-gtk3/Makefile
+1-21 files

NetBSD/pkgsrc 47QCqiX — doc CHANGES-2026

   doc: Updated www/php-ja-wordpress to 7.0.7
VersionDeltaFile
1.6780+2-1doc/CHANGES-2026
+2-11 files

NetBSD/pkgsrc hSUYT5h — www/palemoon Makefile Makefile.common

   palemoon: Update to 35.0.2. New minor release.

        v35.0.2 (2026-10-06)

      This is a performance, bugfix and security release.

      Changes/fixes:
        * Disabled the new :has() CSS implementation by default for performance
          reasons. See implementation notes.
        * Added a preference for handling of improper form element placement in
          HTML. See implementation notes.
        * Fixed several application crashes.
        * Backported an upstream libvpx VP8 decoder fix.
        * Fixed an issue in the BigInt implementation for specific JavaScript
          calls failing.
        * Fixed a potentially exploitable memory leak.
        * Security issues addressed: CVE-2026-100822, CVE-2026-100783,
          CVE-2026-100773 (DiD), CVE-2026-96869 (DiD) and CVE-2026-100791.

   Build tested on CentOS 7 and NetBSD.
VersionDeltaFile
1.49+10-10www/palemoon/distinfo
1.12+3-3www/palemoon/Makefile.common
1.56+1-2www/palemoon/Makefile
+14-153 files