NetBSD/pkgsrc eCBpymydoc CHANGES-2026

   Updated www/py-starlette, www/py-jwcrypto
VersionDeltaFile
1.5620+3-1doc/CHANGES-2026
+3-11 files

NetBSD/pkgsrc 28ApdLVwww/py-jwcrypto PLIST distinfo

   py-jwcrypto: updated to 1.5.9

   1.5.9

   Add ML-DSA post-quantum signature support (RFC 9964)
   Support fully specified algorithms per RFC 9864
   Skip unknown kty in JWKSet import per RFC 7517 §5
   Reject non-empty encrypted key in bare ECDH-ES
   Limit dot splits during JWE and JWS parsing
VersionDeltaFile
1.15+4-5www/py-jwcrypto/Makefile
1.11+4-4www/py-jwcrypto/distinfo
1.5+4-1www/py-jwcrypto/PLIST
+12-103 files

NetBSD/pkgsrc WDtjEYXwww/py-starlette PLIST distinfo

   py-starlette: updated to 1.6.0

   1.6.0 (August 8, 2026)

   Added

   * Add `max_body_size` to `Starlette` and route classes
   * Expose `http.response.debug` information via response extensions
VersionDeltaFile
1.18+8-7www/py-starlette/Makefile
1.17+4-4www/py-starlette/distinfo
1.3+4-1www/py-starlette/PLIST
+16-123 files

NetBSD/pkgsrc s5Sm3lzdoc CHANGES-2026

   doc: Updated net/pptp to 1.7.1nb2
VersionDeltaFile
1.5619+2-1doc/CHANGES-2026
+2-11 files

NetBSD/pkgsrc UATN6Ffnet/pptp distinfo Makefile, net/pptp/patches patch-ah

   pptp: honor CFLAGS and LDFLAGS

   Bump PKGREVISION.
VersionDeltaFile
1.4+17-6net/pptp/patches/patch-ah
1.13+2-2net/pptp/distinfo
1.24+2-2net/pptp/Makefile
+21-103 files

NetBSD/pkgsrc bfhhZVbmeta-pkgs/bulk-test-go Makefile

   bulk-test-go: Update Terraform/OpenTofu dependencies

   Build all Terraform and OpenTofu versions and adjust DEPENDS for
   providers that have now version suffixes in PKGNAME and PKGPATH.

   Noticed via pkgsrc-bulk@ and thanks to <jperkin>!
VersionDeltaFile
1.17+16-7meta-pkgs/bulk-test-go/Makefile
+16-71 files

NetBSD/pkgsrc tQTHQfidoc CHANGES-2026

   Updated math/py-pythran, devel/py-gitpython
VersionDeltaFile
1.5618+3-1doc/CHANGES-2026
+3-11 files

NetBSD/pkgsrc FqlymVrdevel/py-gitpython Makefile distinfo

   py-gitpython: updated to 3.1.60

   3.1.60

   Security fixes for

   * https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-g5vv-9gxw-82hx
   * https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-whh4-5q6c-9v3x
   * https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-239g-whfq-7xj9
VersionDeltaFile
1.33+4-4devel/py-gitpython/distinfo
1.37+2-2devel/py-gitpython/Makefile
+6-62 files

NetBSD/pkgsrc aSt70lxmath/py-pythran distinfo Makefile

   py-pythran: updated to 0.19.0

   0.19.0

   * Improve numpoy expression combiners
   * Improve range-value analysis
   * Match numpy upgrades
   * CPython 3.15 compatibility
   * Update pocketfft requirements
   * Update xsimd requirements
   * Bump C++ dependency to C++17
   * Use clang-tidy to lint pythonic codebase
   * Remove obsolete pythonic code
   * Improve compatibility with 32bit architectures
VersionDeltaFile
1.13+44-26math/py-pythran/PLIST
1.29+7-11math/py-pythran/Makefile
1.18+4-4math/py-pythran/distinfo
+55-413 files

NetBSD/pkgsrc fTsrrgpdoc CHANGES-2026

   Updated devel/py-stevedore, converters/py-simplejson
VersionDeltaFile
1.5617+3-1doc/CHANGES-2026
+3-11 files

NetBSD/pkgsrc eZbyy8Uconverters/py-simplejson Makefile distinfo

   py-simplejson: updated to 4.1.2

   Version 4.1.2 released 2026-08-26

   * Fix control character error position when content precedes the control char
     https://github.com/simplejson/simplejson/pull/379
   * Report the offending char, not the backslash, for invalid \X escapes
     https://github.com/simplejson/simplejson/pull/380
   * Handle non-finite Decimals like floats in the encoder
     https://github.com/simplejson/simplejson/pull/381
   * Parse failures due to trailing commas are now reported consistently
     across implementations
     https://github.com/simplejson/simplejson/pull/382
VersionDeltaFile
1.48+4-4converters/py-simplejson/distinfo
1.61+2-2converters/py-simplejson/Makefile
+6-62 files

NetBSD/pkgsrc dbhYHFTdevel/py-stevedore Makefile distinfo

   py-stevedore: updated to 5.9.1

   5.9.1

   * docs: Add guide on conflict resolution
   * Fix conflict\_resolver with DriverManager
   * ruff: Use more explicit name for "UP" checks
VersionDeltaFile
1.22+4-4devel/py-stevedore/distinfo
1.30+2-2devel/py-stevedore/Makefile
+6-62 files

NetBSD/pkgsrc 6aXLrYxdoc pkg-vulnerabilities

   doc: fix incorrect patterns for PKGNAME

   From audit by Showta Ishizaki in PR 60609.

   (Patch applied and unnecessary lines removed.)
VersionDeltaFile
1.783+89-94doc/pkg-vulnerabilities
+89-941 files

NetBSD/pkgsrc LgGd3AOdoc pkg-vulnerabilities

   doc: comment out REJECTED CVEs

   Audited by Showta Ishizaki in PR 60608.
VersionDeltaFile
1.782+75-72doc/pkg-vulnerabilities
+75-721 files

NetBSD/pkgsrc rgPVYCYdoc CHANGES-2026

   Updated emulators/qemu, sysutils/qemu-guest-agent
VersionDeltaFile
1.5616+3-1doc/CHANGES-2026
+3-11 files

NetBSD/pkgsrc NQJ8Q8hemulators/qemu version.mk distinfo, sysutils/qemu-guest-agent Makefile

   qemu: updated to 11.1.1

   11.1.1
   Bug fixes
VersionDeltaFile
1.1+39-0emulators/qemu/Makefile.common
1.412+2-34emulators/qemu/Makefile
1.14+2-28sysutils/qemu-guest-agent/Makefile
1.256+4-4emulators/qemu/distinfo
1.19+1-1emulators/qemu/version.mk
+48-675 files

NetBSD/pkgsrc l75wHhGsecurity/libgcrypt Makefile

   libgcrypt: fix for error: operand size mismatch for 'vsm4rnds4'
VersionDeltaFile
1.126+3-1security/libgcrypt/Makefile
+3-11 files

NetBSD/pkgsrc K9piZ0Nnet/terraform-provider-null Makefile, net/terraform-provider-vultr Makefile

   terraform-provider-*: fix path to wip
VersionDeltaFile
1.72+2-2net/terraform-provider-vultr/Makefile
1.73+2-2net/terraform-provider-null/Makefile
+4-42 files

NetBSD/pkgsrc OEwExagdoc CHANGES-2026

   doc: Updated meta-pkgs/xfce4 to 4.20.0nb19
VersionDeltaFile
1.5615+2-1doc/CHANGES-2026
+2-11 files

NetBSD/pkgsrc 7nlkisvdoc CHANGES-2026

   doc: Updated meta-pkgs/lxqt to 2.4.0nb2
VersionDeltaFile
1.5614+2-1doc/CHANGES-2026
+2-11 files

NetBSD/pkgsrc kCC5iCrmeta-pkgs/lxqt Makefile

   lxqt: bump for pcmanfm-qt 2.4.1
VersionDeltaFile
1.50+3-3meta-pkgs/lxqt/Makefile
+3-31 files

NetBSD/pkgsrc fN6oiLbdoc CHANGES-2026

   doc: Updated sysutils/pcmanfm-qt to 2.4.1
VersionDeltaFile
1.5613+2-1doc/CHANGES-2026
+2-11 files

NetBSD/pkgsrc O4jNe2qsysutils/pcmanfm-qt PLIST Makefile, sysutils/pcmanfm-qt/patches patch-CMakeLists.txt patch-pcmanfm_desktopwindow.cpp

   pcmanfm-qt: update to 2.4.1

   pkgsrc does not include the change "Set desktop screen explicitly on
   Wayland", since it requires a newer version of plasma6-layer-shell-qt
   than pkgsrc carries presently and Wayland isn't really supported yet.

   pcmanfm-qt-2.4.1 / 2026-08-26
   ==============================
    * Close tabs without close buttons by middle clicking with Qt >= 6.11.
    * Workaround for a bad behavior of wlroots.
    * Removed the redundant translations CMake file.
    * Set desktop file name.
    * Removed `<normaloff>` from ui files.
    * Updated fsf address.
VersionDeltaFile
1.1+24-0sysutils/pcmanfm-qt/patches/patch-pcmanfm_desktopwindow.cpp
1.1+16-0sysutils/pcmanfm-qt/patches/patch-CMakeLists.txt
1.21+6-4sysutils/pcmanfm-qt/distinfo
1.57+2-3sysutils/pcmanfm-qt/Makefile
1.14+2-1sysutils/pcmanfm-qt/PLIST
+50-85 files

NetBSD/pkgsrc kqxBoFjmultimedia/libmatroska Makefile

   multimedia/libmatroska: Use https for MASTER_SITES

   Via http MASTER_SITES, the tarball is not available.
VersionDeltaFile
1.55+2-2multimedia/libmatroska/Makefile
+2-21 files

NetBSD/pkgsrc KgzA4Scinputmethod/fcitx distinfo, inputmethod/fcitx/patches patch-tools_cli_txt2mb.c patch-src_im_pinyin_sp.c

   fctix: add missing ctype abuse fix patches

   Two patches from the netbsd-11 ctype-abuse fixes of 2025-12-07 were
   listed in distinfo r1.8 but apparently never committed.
    https://mail-index.netbsd.org/pkgsrc-changes/2025/12/07/msg335023.html

   This should fix bulk build on NetBSD 11.0 hosts, and
   should be pulled up to pkgsrc-2026Q2.
VersionDeltaFile
1.1+30-0inputmethod/fcitx/patches/patch-src_im_pinyin_sp.c
1.1+22-0inputmethod/fcitx/patches/patch-tools_cli_txt2mb.c
1.10+3-1inputmethod/fcitx/distinfo
+55-13 files

NetBSD/pkgsrc 3IqvYs4doc CHANGES-2026

   doc: Added net/opentofu112 version 1.12.6
VersionDeltaFile
1.5612+2-1doc/CHANGES-2026
+2-11 files

NetBSD/pkgsrc SFHihGudoc CHANGES-2026

   doc: Updated devel/nss to 3.128
VersionDeltaFile
1.5611+2-1doc/CHANGES-2026
+2-11 files

NetBSD/pkgsrc fAVCbwWdevel/nss Makefile distinfo

   nss: update to 3.128.

   Changes in NSS 3.128

   - Bug 2063360 - Rejoin the table cells the conversion wrapped mid-construct.
   - Bug 2063360 - Generate heading anchors and stop the headings linking to themselves.
   - Bug 2063360 - Unlink the self-linking headings in the release notes.
   - Bug 2063360 - Point documentation cross-references at the dashed anchors.
   - Bug 2063360 - Fix doc-lint in the release process.
   - Bug 2066375 - Make fuzz tasks selectable with try syntax.
   - Bug 2066375 - Build Cryptofuzz in its own CI task.
   - Bug 2066604 - fix EC public key encoding in sftk_PutPubKey.
   - Bug 2066183 - set CKA_ID on imported private keys.
   - Bug 2017925 - Hash prfs need to be evaluated for indicators.
   - Bug 2066327 - rename libcrux gyp target.
   - Bug 2066415 - Update BoGo tests to disable ML_DSA Default test.
   - Bug 2065354 - unify the two clang-format docker images.
   - Bug 2056265 - -trust-cert for TLS BoGo tests.
   - Bug 2056235 - DTLS1.2/1.3 - silently discard invalid records.

    [30 lines not shown]
VersionDeltaFile
1.215+4-4devel/nss/distinfo
1.301+2-2devel/nss/Makefile
+6-62 files

NetBSD/pkgsrc a4iIHx1net Makefile

   net: Add opentofu112
VersionDeltaFile
1.1661+2-1net/Makefile
+2-11 files

NetBSD/pkgsrc P0bONX7net/opentofu112 PLIST DESCR, net/opentofu112/patches patch-provider__source.go

   net/opentofu112: import opentofu112-1.12.6

   OpenTofu is an OSS tool for building, changing, and versioning
   infrastructure safely and efficiently. OpenTofu can manage existing and
   popular service providers as well as custom in-house solutions.

   The key features of OpenTofu are:

   * Infrastructure as Code: Infrastructure is described using a
     high-level configuration syntax. This allows a blueprint of your
     datacenter to be versioned and treated as you would any other code.
     Additionally, infrastructure can be shared and re-used.
   * Execution Plans: OpenTofu has a "planning" step where it generates
     an execution plan. The execution plan shows what OpenTofu will do
     when you call apply. This lets you avoid any surprises when
     OpenTofu manipulates infrastructure.
   * Resource Graph: OpenTofu builds a graph of all your resources, and
     parallelizes the creation and modification of any non-dependent
     resources. Because of this, OpenTofu builds infrastructure as

    [9 lines not shown]
VersionDeltaFile
1.1+3,312-0net/opentofu112/distinfo
1.1+1,104-0net/opentofu112/go-modules.mk
1.1+27-0net/opentofu112/Makefile
1.1+26-0net/opentofu112/DESCR
1.1+16-0net/opentofu112/patches/patch-provider__source.go
1.1+2-0net/opentofu112/PLIST
+4,487-01 files not shown
+4,488-07 files