icewm: update to 4.1.0
New Features
- Mouse-controlled window movement: Added new mousemove command to
icesh for starting mouse-controlled movement of windows
- ignoreUserTime window option: New winoptions setting to ignore
wm_user_time and startup_id
- Xcursor support: Smart guessing of cursor x/y-hotspot and support
for Xcursor theme
- System cursor theme fallback: Uses system cursor themes when icewm
theme doesn't define cursors
- Enhanced gdk-pixbuf support: Support for themed cursors for
gdk-pixbuf without libXpm
- Better mouse pointer scaling: Prefer libXrender for scaling YPixmap
Improvements
- Documentation enhancements in icesh and icewm-keys manpages
- Improved cursor handling with better XPM support
- Image mask preservation as alpha when loading 24-bit images with
[12 lines not shown]
fish: update to 4.9.3
4.9.3:
more darwin bug fixes
4.9.2:
bug fixes for darwin
4.9.1:
- On non-default keyboard layouts, fish executed bindings for
physical keys instead of only bindings for the layout’s key. For
example, on the Dvorak layout, typing s would insert ; because
there is a default binding for ;
- When typing space to accept a character entered via certain IMEs,
fish would insert a space instead of the desired character, which
has been fixed
- On macOS terminals, keys like option-l would execute bindings for
alt-l instead of the historical behavior of inserting a character
(like @ on a German layout)
[33 lines not shown]
py-diff-cover: updated to 10.6.0
10.6.0
refactor: harmonize linters to use ruff as the sole linter and formatter
Switch over to uv
Trying to avoid re-locking
Add --minimum-change feature flag to diff-cover and diff-quality
py-gmpy2: updated to 2.3.2
Changes in gmpy2 2.3.2
* Fix processing defaults for e/E format types precision. (skirpichev)
* Support PyPy3.12. (skirpichev)
py-pyspnego: updated to 0.12.4
0.12.4 - 2026-10-06
* Fix SSPI acceptor with explicit `Password` or `KerberosKeytab` credentials failing with `SEC_E_LOGON_DENIED` when the username is in the UPN form `user at REALM`
* The `pszPrincipal` value is no longer passed to `AcquireCredentialsHandle`, it was set to the SPN for acceptors but does not control the acceptor identity
* Fix `spnego.server(credentials=..., protocol="negotiate", options=NegotiateOptions.use_negotiate)` to pass the credentials to the Kerberos and NTLM acceptor contexts it creates
* On Windows the Kerberos acceptor had no credential to accept with and was dropped from the mech list, leaving only NTLM
* Fix SPNEGO acceptor to echo the Kerberos OID the initiator offered as the `supportedMech`
* Windows initiators list the MS Kerberos OID `1.2.840.48018.1.2.2` ahead of the standard OID and reject a `NegTokenResp` that does not echo it
* The MS Kerberos OID and the pre RFC draft OID `1.3.5.1.5.2` are treated as aliases of Kerberos when matching the mech list and `supportedMech`, matching MIT krb5
* The acceptor no longer requests a `mechListMIC` when the initiator listed a Kerberos alias first as the optimistic mech was the one selected
* Use `socket.gethostname()` rather than `socket.getfqdn()` for the `DnsComputerName` in the NTLM acceptor `CHALLENGE` message
* `socket.getfqdn()` does a DNS lookup which can block for a few seconds when DNS is not set up for the host
* Fix the SSPI `negotiated_protocol` and `session_key` properties failing with a `TypeError` before the first step
* `negotiated_protocol` returns the protocol requested, or `None` for `negotiate`, like the GSSAPI and Python Negotiate proxies
* `session_key` raises `NoContextError` like the GSSAPI proxy
py-cramjam: updated to 2.13.0
2.13.0
ci: build wheels with cibuildwheel, including Pyodide
Fix missing packaging license and repo for crates.io
add riscv64 manylinux build
Safe resizing a Buffer that's in use
Track buffer protocol views
Hold source's buffer export for copy=False Buffers
Faster BytesType extraction
bugfix: zlib encoder using gzip codec
tailscale: update to 1.104.1
All:
- WireGuard packet buffering uses less memory while waiting for peer
handshakes.
- WireGuard packet queue depth scales with CPU core count, reducing
peak memory usage under heavy traffic.
Linux:
- Client-side netmap caching improves start up speed and connectivity
when the Tailscale control plane is unreachable.
- WireGuard allocates a single packet buffer for batched I/O,
improving throughput and reducing memory usage.
- An issue that could prevent traffic over IPv6 link-local addresses
from flowing through direct and Tailscale Peer Relay connections is resolved.
- An issue preventing Linux desktop detection from working on Wayland
environments is resolved.
Darwin:
- Client-side netmap caching improves start up speed and connectivity
[16 lines not shown]
chat/ejabberd: Update to 26.07
## Version 26.09
#### Core
- Add `force` value to `auth_external_user_exists_check` option
- Add XEP-0158 SHA-256 hashcash CAPTCHA challenge ([#4594](https://github.com/processone/ejabberd/pull/4594))
#### Modules
- `mod_auth_fast`: Make sure that fast tokens can be used only with method that they were created for
- `mod_invites`: don't apply overuse limit if `max_invites` is `infinity` ([#4615](https://github.com/processone/ejabberd/pull/4615))
- `mod_invites`: don't crash in `get_invite_by_invitee_t` if `reset_token` present ([#4620](https://github.com/processone/ejabberd/pull/4620))
- `mod_invites`: now that Conversations is for free we remove Yaxim ([#4621](https://github.com/processone/ejabberd/pull/4621))
- `mod_mix`: Make access_create rule be applied when creating channel
- `mod_mqtt`: Add lower limits for pre-auth packets
- `mod_register`: After changing password disallow password change on currently authenticated sessions
[12 lines not shown]
chat/matrix-synapse: Update to 1.161.0
Tested on NetBSD 10 amd64 with 2026Q3 environment.
Packaging changes:
- use maturin's tool.mk, to get the part that respects MAKE_JOBS
- patch mio, which had a pre-NetBSD10 type for kevent.udata, a
latent bug apparently exposed by a new libc crate, but fixable on
its own merits by code inspection.
# Synapse 1.162.0 (2026-09-29)
## Features
- Raise default room version to "12". Contributed by @jason-famedly @famedly. ([\#20130](https://github.com/element-hq/synapse/issues/20130))
- Limit the number of end-to-end encryption one-time keys stored per device to 500 per algorithm, rejecting uploads which would exceed the limit with a `400 Bad Request`. ([\#20162](https://github.com/element-hq/synapse/issues/20162))
- Add support for configuring a `username` for Redis connections, for Redis 6+ ACL authentication. ([\#20187](https://github.com/element-hq/synapse/issues/20187))
- Add a rate limit on the client profile lookup endpoints, configurable via `rc_profile`. ([\#20218](https://github.com/element-hq/synapse/issues/20218))
www/monolith: update to 2.11.2
v2.11.2
- separate GUI binary to compliment CLI
v2.11.1
- concurrent retrieval of remote assets
- libssl is no longer a required dependency
v2.11.0
- MHTML output format (-m CLI flag)
- -D / --create-dirs CLI flag to automatically create non-existing directories
- bugfixes related to unwrapping of NOSCRIPT elements
- proper escaping of </script> tags within embedded JS
- fixed a bug related to not sending all Cookies
- webmanifest now gets embedded into the document
- SVG symbols no longer can embed the entire image
- properly handle module and importmap script types
sysutils/mirador: update to 1.21.0
1.21.0 - 2026-10-08
Changed
The Windows build carries the default config with the same line endings as every other build. It used to embed the file as the build machine's checkout wrote it, which on Windows is CRLF, so --print-config and the first-run config differed from macOS and Linux for no reason in the code. The repository now asks for LF everywhere. A config already on disk is untouched, and edits keep whatever endings it has.
Every dialog punches its title into the border. The w picker's PANELS and a prompt's label — ADD A CLOCK, WEATHER LOCATION, AGENDA FILE — were laid on the border bare, where the theme picker, the key map and every panel draw ┤TITLE├. All four dialogs now draw it the same way, and one too narrow for its title cuts it with … rather than letting the corner take the closing ├.
Fixed
An absurd pomodoro length is refused instead of overflowing. The three [pomodoro] lengths were checked only for being above zero, and the panel turns minutes into seconds unchecked, so a hand-edited length too large for that sum crashed a debug build and gave a release build a phase of some other length nobody wrote. Like the weather, markets and news refresh settings, each now stops at a year, and a config past it is refused with the key named.
--migrate-config no longer overwrites an earlier backup. It copied the original to config.toml.bak whether or not that name was taken, so the config a --reset-config had set aside there, or an earlier migration's backup, was replaced for good. It now takes the next free number, as the resets do.
The error for a key from an older version points at --migrate-config exactly when the migration would fix the file. The error kept its own list of those keys, and the list had three of the four the migration fixes, so a pre-0.1.0 [notes] side_by_side_min_width was told to read --print-config instead. It went by the key's name alone, where the migration also needs the right table, so forecast_days under [clocks] was sent to a migration that then refused it. And it promised an update in place wherever the key matched, though the migration writes nothing when the result would still not load: a forecast_hours added beside the stale forecast_days was refused as a duplicate. The error now asks the migration about the line the parser stopped on and whether it would finish. When it would, the error says what it will change; when it would not, it says what the line becomes and the first problem that stops the migration, by line.
The theme picker draws the theme it is previewing on a short terminal. Its list kept a twelve-row window in a dialog sixteen rows tall, so on a terminal under sixteen rows the foot of the window was cut, footer first, and End or ↓ previewed a theme whose name was nowhere on screen. The list now scrolls within the rows the terminal leaves it, as the w picker's does, the footer gives way to nothing but the row of the theme being previewed, and a page moves as far as the rows drawn.
A dialog's keys drop whole on a narrow terminal, and Esc goes last. The w and t pickers drew their key rows at full width and the terminal cut them wherever the edge fell — Esc put with no back, and narrower still the keep hint whole and Esc gone without a mark. The key map's row dropped from the end, so a narrow one said how to reload and not how to leave, and a prompt on a screen under twenty columns measured its help for the twenty it asked for. Every dialog's keys now drop whole, the way out last, and Esc on its own and still too wide ends in …, as a prompt's help already did.
The w picker says when it has cut a message. The line under its list gives way to what was just refused or why the config could not be written, and most of those are longer than the dialog's forty columns — the edited config does not describe the requested layout — so the terminal cut them at every size, with nothing to show the rest was missing. They now end in …, and so does the usual line on a narrow terminal.
One refresh of the watchlist asks for each symbol once. An r, or an added symbol, while the markets panel waited out the minute it leaves between rounds was answered by the next round and then again a minute later, so it cost two requests a symbol against a source that blocks by address. Removing a symbol also threw away an r pressed just before it, and the board waited out the whole interval instead.
The markets panel copies its board when a price lands, not every frame. It cloned every quote with its intraday series once a second, for numbers that change once a minute, and redrew each sparkline from the whole series. Both happen when a quote lands now. A quote also keeps at most a thousand intraday prices, averaged down rather than cut: the request asks for 78, and nothing stopped an answer carrying two million.
A long task or note list builds only the rows on screen. Every task and every note in the list was turned into a row on every frame, through an index of the whole store rebuilt each time, for a panel that drew the twenty that fit. Scrolling, the selection and clicks are as they were.
[94 lines not shown]
sysutils/lla: update to 0.6.6
[0.6.6] - 2026-10-07
Added
lla --license prints the full MIT license embedded in the executable,
including Windows releases. Windows usage documentation and release smoke
checks cover the license and all five supported completion shells.
Fixed
Shell completion generation now prints scripts to stdout by default for Bash,
Fish, Zsh, PowerShell, and Elvish. Use --output or --path to save a script
to a file.