NetBSD/pkgsrc v81QCuPdoc CHANGES-2026

   Updated www/py-aiohttp-socks, devel/py-awscrt
VersionDeltaFile
1.5418+3-1doc/CHANGES-2026
+3-11 files

NetBSD/pkgsrc u4GciQ7devel/py-awscrt Makefile distinfo

   py-awscrt: updated to 0.36.2

   0.36.2
   submodules update
VersionDeltaFile
1.7+4-4devel/py-awscrt/distinfo
1.8+2-2devel/py-awscrt/Makefile
+6-62 files

NetBSD/pkgsrc 6Fj2Ydnwww/py-aiohttp-socks Makefile distinfo

   py-aiohttp-socks: updated to 0.12.0

   0.12.0

   Dropped support for Python 3.8.
   Bumped python-socks upper bound to <4.0.0.
   The entire codebase is now strictly type-annotated and fully compliant with mypy.
VersionDeltaFile
1.26+4-4www/py-aiohttp-socks/distinfo
1.32+2-2www/py-aiohttp-socks/Makefile
+6-62 files

NetBSD/pkgsrc 99VzsoXdoc CHANGES-2026

   Updated devel/py-ipython, www/py-widgetsnbextension
VersionDeltaFile
1.5417+3-1doc/CHANGES-2026
+3-11 files

NetBSD/pkgsrc l8FzSFFwww/py-widgetsnbextension Makefile distinfo

   py-widgetsnbextension: updated to 4.0.16

   4.0.16
   Unknown changes
VersionDeltaFile
1.11+4-4www/py-widgetsnbextension/distinfo
1.13+2-2www/py-widgetsnbextension/Makefile
+6-62 files

NetBSD/pkgsrc 0WFS9o4devel/py-ipython distinfo Makefile

   py-ipython: updated to 9.16.1

   IPython 9.16

   Summary

   This release contains two security-hardening fixes — HTML-attribute escaping in
   the display objects and closing an arbitrary-code-execution path in completion —
   a new ``cell_meta`` field on
   :class:`~IPython.core.interactiveshell.ExecutionInfo`, several completion, autoreload,
   and path-handling fixes, and two backwards-incompatible changes (``%lsmagic``
   default output and the removal of long-deprecated APIs). It also includes a
   large amount of internal typing, test, and CI modernization.
VersionDeltaFile
1.30+16-19devel/py-ipython/PLIST
1.122+6-5devel/py-ipython/Makefile
1.89+4-4devel/py-ipython/distinfo
+26-283 files

NetBSD/pkgsrc MJ23somdoc CHANGES-2026

   Updated www/py-django-debug-toolbar, www/py-django-treebeard
VersionDeltaFile
1.5416+3-1doc/CHANGES-2026
+3-11 files

NetBSD/pkgsrc Pl7gIagwww/py-django-treebeard Makefile distinfo

   py-django-treebeard: updated to 7.0.1

   7.0.1
   Fixed erroneous no-op when moving MP_Node nodes with node_order_by set.
VersionDeltaFile
1.25+4-4www/py-django-treebeard/distinfo
1.27+2-2www/py-django-treebeard/Makefile
+6-62 files

NetBSD/pkgsrc x6Ga4Rnwww/py-django-debug-toolbar PLIST distinfo

   py-django-debug-toolbar: updated to 7.1.1

   7.1.1 (2026-08-14)

   * Serialize ``TaskResult`` in the Tasks panel to accommodate the storage
     mechanism.
   * Removed whitespace on Task panel's ``kwargs`` column.

   7.1.0 (2026-08-10)

   * Added a Tasks panel that shows tasks queued during the request via
     Django's built-in tasks framework (``django.tasks``, Django 6.0+). On
     older versions of Django, the panel explains that upgrading is required.
   * Fixed the Django version check in the SQL panel test suite for Django's
     boolean parameter handling.
   * Fixed ``show_toolbar_with_docker`` on Docker runtimes such as OrbStack that
     can resolve ``host.docker.internal`` to an address outside the container
     network.
   * Restored the select and explain buttons for queries that run without

    [6 lines not shown]
VersionDeltaFile
1.15+4-4www/py-django-debug-toolbar/distinfo
1.15+4-4www/py-django-debug-toolbar/Makefile
1.10+5-1www/py-django-debug-toolbar/PLIST
+13-93 files

NetBSD/pkgsrc oO6SL3Cdoc TODO CHANGES-2026

   Updated devel/py-uv-dynamic-versioning, textproc/py-sphinx-autodoc-typehints
VersionDeltaFile
1.5415+3-1doc/CHANGES-2026
1.27778+1-2doc/TODO
+4-32 files

NetBSD/pkgsrc g1iDbvttextproc/py-sphinx-autodoc-typehints Makefile distinfo

   py-sphinx-autodoc-typehints: updated to 3.13.2

   3.13.2
   fix: support subscripted type aliases
VersionDeltaFile
1.44+4-4textproc/py-sphinx-autodoc-typehints/distinfo
1.54+2-2textproc/py-sphinx-autodoc-typehints/Makefile
+6-62 files

NetBSD/pkgsrc NQAfOFudevel/py-uv-dynamic-versioning PLIST distinfo

   py-uv-dynamic-versioning: updated to 0.14.1

   0.14.1

   Prek
   chore: remove monkeypatch
   chore: update actions & set permissions
   fix: address license deprecations
   chore: update actions
   chore: update hatchling and others
   ci: update actions
   Audit
   fix: don't use matrix
   docs: pinning build dependencies
   feat: add examples of build-constraint-dependencies
   ci: add integration test
   chore: set build-constraint-dependencies
   Read files as UTF-8 instead of using the locale encoding
   chore: update actions
VersionDeltaFile
1.3+7-9devel/py-uv-dynamic-versioning/Makefile
1.3+4-4devel/py-uv-dynamic-versioning/distinfo
1.3+1-4devel/py-uv-dynamic-versioning/PLIST
+12-173 files

NetBSD/pkgsrc WPOhWmXdoc CHANGES-2026

   Updated www/py-URLObject, www/py-WebOb
VersionDeltaFile
1.5414+3-1doc/CHANGES-2026
+3-11 files

NetBSD/pkgsrc o6vnSJ4www/py-WebOb Makefile distinfo

   py-WebOb: updated to 1.8.11

   1.8.11 (2026-08-02)

   Security Fix

   - The fixes for CVE-2024-42353 and GHSA-fh3h-vg37-cc95 were still
     incomplete: besides removing tab, CR, and LF, ``urllib.parse.urljoin``
     also strips leading and trailing C0 control and space characters from a
     URL before parsing it. A Location value such as
     ``" //www.example.com/test"`` could therefore still be interpreted as a
     protocol-relative URL (and ``" https://www.example.com/test"`` as an
     absolute one), allowing an open redirect.

     WebOb no longer uses ``urllib.parse.urljoin`` and instead ships its own
     implementation of the RFC 3986 reference resolution algorithm,
     ``webob.util.urljoin``, which resolves the URL exactly as given without
     removing any characters. It is now used to make the Location header
     absolute, by ``Request.relative_url``, and by the ``_HTTPMove`` based

    [5 lines not shown]
VersionDeltaFile
1.16+4-4www/py-WebOb/distinfo
1.24+2-2www/py-WebOb/Makefile
+6-62 files

NetBSD/pkgsrc tjibNDhwww/py-URLObject distinfo PLIST

   py-URLObject: updated to 3.0.0

   3.0.0
   Unknown changes
VersionDeltaFile
1.6+6-5www/py-URLObject/Makefile
1.2+5-5www/py-URLObject/PLIST
1.6+4-4www/py-URLObject/distinfo
+15-143 files

NetBSD/pkgsrc SPY0xkFdoc CHANGES-2026

   Updated finance/py-braintree, finance/py-stripe
VersionDeltaFile
1.5413+3-1doc/CHANGES-2026
+3-11 files

NetBSD/pkgsrc 99ZHAODfinance/py-stripe Makefile distinfo

   py-stripe: updated to 15.5.1

   15.5.1 - 2026-08-18

   better document StripeObject's to_dict behavior


   15.5.0 - 2026-08-10

   Add async iteration to v2 list auto-pagination

   Adds async for support to v2 ListObject.auto_paging_iter().
   Surface object property on EventNotification

   Emit Claude Code plugin hint at module load time

   Emits new Claude Code plugin hint when CLAUDECODE or CLAUDE_CODE_CHILD_SESSION environment variables are detected.
   add/adjust event parsing helpers


    [6 lines not shown]
VersionDeltaFile
1.41+13-1finance/py-stripe/PLIST
1.78+4-4finance/py-stripe/distinfo
1.83+2-2finance/py-stripe/Makefile
+19-73 files

NetBSD/pkgsrc ySqqHFdfinance/py-braintree Makefile PLIST

   py-braintree: updated to 4.46.0

   4.46.0

   Add shipping_address_id to Transaction.submit_for_settlement()
   Add phone_number, international_phone to shipping for Transaction.submit_for_settlement()
   Fix path traversal vulnerability in Dispute and Address gateways by validating that IDs used in request paths do not contain path separators or relative-path segments
   Add EmailFormatIsInvalid (92963) and EmailIsTooLong (92964) validation error codes to PayPalAccount
   Prevent OAuthCredentials from exposing access_token and refresh_token in repr() output (e.g. logs and error trackers)
   Add preferred_payment_method_token parameter to ClientToken.generate
VersionDeltaFile
1.72+4-4finance/py-braintree/distinfo
1.35+4-1finance/py-braintree/PLIST
1.73+2-2finance/py-braintree/Makefile
+10-73 files

NetBSD/pkgsrc E29TWDvdoc CHANGES-2026

   Updated net/radsecproxy, net/samba4
VersionDeltaFile
1.5412+3-1doc/CHANGES-2026
+3-11 files

NetBSD/pkgsrc wc01XIlnet/samba4 PLIST Makefile

   samba4: updated to 4.24.6

   Changes since 4.24.5

   o  Ralph Boehme <slow at samba.org>
      * BUG 15978: leases torture test flappy (marked flappy)
      * BUG 16065: Memory leak in DRS when replication fails

   o  Matthias Grandl <matthias.grandl at croit.io>
      * BUG 16176: vfs_ceph_snapshots: smbd panics on snapshot access for a share
        mounted at the CephFS root ("/")

   o  Volker Lendecke <vl at samba.org>
      * BUG 16191: race condition in pthreadpool when forking

   o  Stefan Metzmacher <metze at samba.org>
      * BUG 16065: Memory leak in DRS when replication fails
      * BUG 16077: witness test flappy needs to be fixed
      * BUG 16093: temporary read of unrelated or non-existing memory in s3 dfs

    [16 lines not shown]
VersionDeltaFile
1.130+4-4net/samba4/distinfo
1.65+2-2net/samba4/PLIST
1.221+2-2net/samba4/Makefile
+8-83 files

NetBSD/pkgsrc 1wEWkZtnet/radsecproxy distinfo Makefile

   radsecproxy: updated to 1.11.4

   1.11.4

   Bug Fixes:
   - Fix potential crash when rewrite is too big
   - Fix Message-Authenticator verification for CoA/Disconnect-Request
   - Fix config check error message for rewrite in server block
   - Fix DtlsVersion config
   - Fix MS-MPPE size/alignment check (GHSA-wj29-mxmc-q98c)

   Misc:
   - Explain F-Ticks minimum requirements
VersionDeltaFile
1.21+6-7net/radsecproxy/Makefile
1.15+4-4net/radsecproxy/distinfo
+10-112 files

NetBSD/pkgsrc BYjvS6Xdoc CHANGES-2026

   Updated graphics/graphviz, devel/doxygen, databases/redis
VersionDeltaFile
1.5411+4-1doc/CHANGES-2026
+4-11 files

NetBSD/pkgsrc omQTMKhdatabases/redis Makefile distinfo

   redis: updated to 8.10.1

   Redis 8.10.1    Released Mon 17 Aug 2026 10:00:00 IST

   Update urgency: `SECURITY`: There are security fixes in the release.

   Security fixes

   - (CVE-2026-62356) Miscalculated buffer size in `CMSketch` RDB loading may lead to heap OOB write
   - Out-of-bounds access in TopK heap cleanup path (MOD-15410)
   - Use-after-free in the TLS pending-data list when a command closes another pending connection
   - A malicious RDB payload with an out-of-range `SLOT_INFO` slot id causes memory corruption during RDB loading, which may lead to Remote Code Execution
   - Vector Sets: missing node level validation when loading a vector set from RDB may lead to out-of-bounds access
   - Vector Sets: use-after-free when `VREM` mutates the HNSW graph while background `VSIM` threads are still running
   - Vector Sets: a negative `hnsw_search()` return was treated as a huge unsigned count, reading past the end of the result arrays
   - TLS client certificate authentication bypass: a Common Name containing an embedded NUL byte was truncated, allowing a client to authenticate as another (possibly privileged) ACL user
   - Use-after-free in the blocked-client list when reprocessing a command evicts another client blocked on the same key



    [22 lines not shown]
VersionDeltaFile
1.95+4-4databases/redis/distinfo
1.105+4-2databases/redis/Makefile
+8-62 files

NetBSD/pkgsrc wspkorudevel/doxygen Makefile distinfo, devel/doxygen/patches patch-src_dirdef.cpp

   doxygen: updated to 1.18.0

   1.18.0

   Features

   Doxywizard's GUI and config option documentation are now translated to 8 addition languages (next to English): German, French, Spanish, Russian, Korean, Chinese, Taiwanese, and Japanese.
   From the menu one can switch between languages (doing so will relaunch the application).
   Via the wizard the Doxyfile can also be generated in 8 different languages next to English.
   The expert panel of Doxywizard now has a search field to quickly search for and filter configuration options. [view], [view], [view], [view], [view], [view], [view], [view], [view], [view], [view], [view], and [view]
   Changed doxygen.ico to higher resolution version [view]
   When using the external search engine, icons are used instead of numbers and words for search result types [view], and [view]

   Minor incompatibilities

   Made SOURCE_TOOLTIPS independent of HTML_DYNAMIC_SECTIONS [view]

   Bug fixes
VersionDeltaFile
1.6+9-7devel/doxygen/patches/patch-src_dirdef.cpp
1.89+5-5devel/doxygen/distinfo
1.208+2-2devel/doxygen/Makefile
+16-143 files

NetBSD/pkgsrc OQsJ3L0graphics/graphviz PLIST Makefile

   graphviz: updated to 15.1.1

   15.1.1
   Where are the release notes?
VersionDeltaFile
1.94+4-4graphics/graphviz/distinfo
1.316+2-3graphics/graphviz/Makefile
1.66+1-3graphics/graphviz/PLIST
+7-103 files

NetBSD/pkgsrc Xo4fFIHmultimedia/xine-lib distinfo, multimedia/xine-lib/patches patch-src-input-input__file.c

   port to C23 - avoid func() usage that isn't func(void).

   something made this be built with -std=gnu23 recently, and this is
   the only change it seems to need.

   not bumping pkg revision because it doesn't really change, if it
   already built.
VersionDeltaFile
1.1+27-0multimedia/xine-lib/patches/patch-src-input-input__file.c
1.122+2-1multimedia/xine-lib/distinfo
+29-12 files

NetBSD/pkgsrc FSrMDeBdoc CHANGES-2026

   Updated sysutils/py-borgmatic, graphics/py-svglib, devel/py-syrupy
VersionDeltaFile
1.5410+4-1doc/CHANGES-2026
+4-11 files

NetBSD/pkgsrc KhI0h2cdevel/py-syrupy Makefile distinfo

   py-syrupy: updated to 5.5.3

   5.5.3

   chore(deps): update astral-sh/setup-uv action to v8.3.0
   chore(deps): update astral-sh/setup-uv action to v8.3.1
   chore(deps): update dependency hypothesis to v6.156.2
   chore(deps): update dependency mypy to v2.2.0
   chore(deps): update dependency hypothesis to v6.156.3
   chore: closes 1144
   chore(deps): update astral-sh/setup-uv action to v8.3.2
VersionDeltaFile
1.15+4-4devel/py-syrupy/distinfo
1.16+2-2devel/py-syrupy/Makefile
+6-62 files

NetBSD/pkgsrc DdEsXPngraphics/py-svglib Makefile distinfo

   py-svglib: updated to 2.2.0

   2.2.0 (2026-08-14)

   Tooling and housekeeping

   - Modernized type annotations across `src/svglib/` and `tests/` to use PEP
     585 builtin generics (`list[...]`, `dict[...]`, `tuple[...]`, `set[...]`)
     instead of `typing.List`/`Dict`/`Tuple`/`Set`, and simplified a few
     emptiness/membership checks (`not points` instead of `len(points) == 0`,
     a set literal instead of a list for `in` checks). No behavior change.
   - Silenced a `UserWarning` from `test_convert_pdf_png` that came from
     ReportLab's own `renderPM.drawImage`, not from svglib: it reopens a
     `<image>` file referenced by path and converts it straight to RGB without
     normalizing palette-with-transparency PNGs first, unlike svglib's own
     handling of base64-embedded images. The referenced PNG (a dedicated
     tRNS-chunk test fixture) still renders correctly; there was nothing to fix
     in svglib's output.


    [10 lines not shown]
VersionDeltaFile
1.4+4-4graphics/py-svglib/distinfo
1.5+2-2graphics/py-svglib/Makefile
+6-62 files

NetBSD/pkgsrc D3AfcZFsysutils/py-borgmatic distinfo Makefile

   py-borgmatic: updated to 2.1.7

   2.1.7
   * Add support for the "--quick-stats" flag and the "quick_statistics" option to the "prune"
     action. Borg >= 1.4.5 and < 2 only.
   * For the "bootstrap" action, provide a more helpful error message when borgmatic can't
     determine the latest archive.
   * Add an "archive_hostname" option and a corresponding "--archive-hostname" flag for
     overriding the hostname used for the "{hostname}" placeholder in the "archive_name_format"
     option. Also add an "archive_username" option and corresponding "--archive-username" flag to
     override the "{user}" plaecholder. Both options/flags are Borg 1.4.5+ only.
   * Fix the ZFS hook's overzealous unmounting of snapshot paths when a source dataset is at
     "/".
   * Fix for the "restore" action sometimes failing to find a database dump that was dumped
     with a default port.
   * For the MariaDB and MySQL hooks, add "events", "routines", and "tablespaces" options for
     disabling dumping of scheduled events, stored routines, and tablespaces, respectively.
   * Fix an error from the "diff" action when exclude options are configured.
   * Fix the "repo-create" action to more surgically suppress Borg "Repository does not exist"

    [17 lines not shown]
VersionDeltaFile
1.2+238-67sysutils/py-borgmatic/PLIST
1.2+13-13sysutils/py-borgmatic/Makefile
1.2+4-4sysutils/py-borgmatic/distinfo
+255-843 files