nginx: Update to 1.30.4
Changes with nginx 1.30.4 15 Jul 2026
*) Security: heap buffer overflow might occur in a worker process when
using the map directive with regex matching if the map variable was
included in a string expression after a capture affected by this map;
a similar issue might happen when using a non-cacheable variable in a
string expression (CVE-2026-42533).
Thanks to Mufeed VH of Winfunc Research and Maxim Dounin.
*) Security: uninitialized memory access might occur when using unnamed
regex captures with the "slice" directive or background cache update,
which could result in worker process memory disclosure or worker
process termination (CVE-2026-60005).
*) Security: use-after-free might occur when processing a specially
crafted proxied backend response with the ngx_http_ssi_filter_module
(CVE-2026-56434).
Thanks to P4P3R-HAK.
labwc: update to 0.20.1
* 0.20.1
This is a small bug fix release.
Fixed
- Handle titles with no visible characters, for example the left-to-right mark
(‎) @Consolatis [#3630]
- Protect against SIGABRT when TTY switching in unusual circumstances by
ensuring that xdg-shell windows have sensible width and height before trying
to set size on configure. This protects against an edge case experienced when
switching between labwc on one TTY and Xfce on XOrg on another TTY.
@johanmalm @Tamaranch [#3617]
* 0.20.0
This is the first release using wlroots-0.20 and therefore has an increased risk
of teething issues. Many thanks to @Consolatis for leading the effort to port
across [#2956].
[88 lines not shown]
swaylock: update to 1.8.6
swaylock v1.8.6
Constantin (1):
Fix stray character in password buffer after suspend/resume cycle
Sergey Zagursky (1):
main: fix reversed dup2 arguments in daemonize
sway: update to 1.12
Sway 1.12 contains 138 changes from 50 contributors.
This release depends on wlroots 0.20.0. See the wlroots release notes.
New features
- Add support for capturing individual windows.
- Add support for HDR10 when running with the Vulkan renderer.
- Add support for new protocols: color-management-v1, color-representation-v1, xdg-toplevel-tag-v1,
ext-workspace-v1, wl_fixes.
- Add a new --device-primaries to output color_profile to use color primaries advertised in EDID.
- Add support for keypad slide switches.
Changes
- The default configuration file now ships key bindings for playerctl.
- Sway no longer refuses to start on unsupported GPUs (e.g. NVIDIA proprietary drivers).
Instead, it displays an informational message. The message can be disabled via
[8 lines not shown]
wlroots: update to 0.20.2
* wlroots 0.20.2
Félix Poisot (1):
scene: don't send new dmabuf feedback after node disable
Simon Ser (13):
xwayland/selection: stop using VLAs for MIME type atom lists
xwayland: use const pointers for xcb_get_property_value()
xwayland/xwm: fix out-of-bounds strndup() in read_surface_class()
xwayland/xwm: pluralize array variable in read_surface_net_wm_state()
xwayland: stop using xcb_get_property_reply_t.value_len
xwayland/xwm: align WL_SURFACE_ID error message with WL_SURFACE_SERIAL
xwayland/xwm: expand comment about WL_SURFACE_ID event ordering
xwayland/xwm: check whether surface is already associated for WL_SURFACE_ID
xwayland/xwm: check object type in xwm_handle_surface_id_message()
xwayland/xwm: check WM_TRANSIENT_FOR length
[480 lines not shown]
mk: stop passing relro linker flags to compiler
The relro flags are added to LDFLAGS, and that should be sufficient.
Packages not honoring LDFLAGS need to be fixed anyway, and clang
complains about the flags on the compiler command line.
www/chromium: update to 150.0.7871.128
* 150.0.7871.128
This update includes 7 security fixes. Please see the Chrome Security Page for more information.
[N/A][516987782] Critical CVE-2026-15899: Use after free in CameraCapture. Reported by Google on 2026-05-27
[N/A][523750584] Critical CVE-2026-15900: Use after free in GPU. Reported by Google on 2026-06-14
[N/A][533446300] Critical CVE-2026-15901: Use after free in Network. Reported by Google on 2026-07-10
[N/A][522436154] High CVE-2026-15902: Use after free in Cast. Reported by Google on 2026-06-10
[TBD][531503216] High CVE-2026-15903: Out of bounds read and write in V8. Reported by OpenAI Codex Security (amyb) on 2026-07-06
[N/A][532925350] High CVE-2026-15904: Use after free in Ozone. Reported by Google on 2026-07-09
[N/A][532970574] High CVE-2026-15905: Use after free in Aura. Reported by Google on 2026-07-09
* 150.0.7871.124
This update includes 15 security fixes. Please see the Chrome Security Page for more information.
[N/A][517100492] Critical CVE-2026-15764: Use after free in Ozone. Reported by Google on 2026-05-27
[N/A][518007484] Critical CVE-2026-15765: Use after free in Ozone. Reported by Google on 2026-05-29
[N/A][514010477] High CVE-2026-15766: Uninitialized Use in Skia. Reported by Google on 2026-05-17
[43 lines not shown]
textproc/typst: update to 0.15.1
Library
Text
- Updated New Computer Modern fonts to version 8.1.1, fixing a bug where the regular weight of the math
font was still using the old calligraphic letterforms that were supposed to live in stylistic set 6
Math
- Fixed a regression where alignment points did not work correctly when placed within lr / matched delimiters
- Fixed a regression where op elements could be vertically misaligned
Layout
- Fixed a bug where gaps could appear in multi-page lists with number-align / marker-align set to an
alignment with a vertical component
[15 lines not shown]
sysutils/dua-cli: update to 2.38.1
This release fixes a long-standing bug where NO_COLOR=1 would make all styling disapear, including
the selection indicator itself. Now it's usable, finally.
Bug Fixes
- only strip colors when NO_COLOR is enabled
shells/oh-my-posh: update to 29.33.0
v29.33.0
Features
- shell: support vimode segment in fish (302c3df), closes #5438
- spotify: detect ads on macOS and Linux (36a96bb)
v29.32.0
Features
- config: add generic language segment type (e98db08)
emulators/jgenesis: update to 0.13.1
New Features
- (Genesis) Added a new enabled-by-default option to automatically force 6-button controllers into 3-button mode when running a game that has known compatibility issues with 6-button controllers, such as Golden Axe II (#682)
- (PC Engine) Added support for the Turbo Tap (i.e. multiple emulated gamepads, up to 5)
- Holding the rewind and fast forward hotkeys together now rewinds at increased speed, based on the configured fast forward multiplier (#674)
- Added a right click cut/copy/paste menu to the Cheats text edit box (#678)
Improvements
- (Genesis) When the "remove sprite-per-scanline limits" setting is enabled with a game that has known compatibility issues with it (read: Sonic 1), the emulator now shows a message at game boot noting that this may cause glitches
- I did this instead of forcing it off because it does reduce sprite flickering during gameplay; it just also causes a major glitch on the title screen, unfortunately
- (32X) SH-2 invalid memory address accesses are no longer logged to console by default; on Windows, this fixes potential slowdown in games that frequently access invalid addresses, e.g. Pitfall: The Mayan Adventure
- When mapping gamepad analog triggers to inputs, it should no longer be possible to accidentally map "trigger released" to anything (#674)
Fixes
- (Genesis) Fixed the 68000 DIVU/DIVS instructions setting the Z and N flags incorrectly when the division overflows; this fixes Blood Shot sometimes allowing you to see part of a wall that's supposed to be behind you and then freezing (#679)
- (GBA) Improved accuracy of IWRAM open bus emulation, based on the openbuster test ROM (#676)
devel/serie: update to 0.8.1
What's Changed
- Update GitHub Actions workflows by @lusingander in #157
- Add stash user command variable by @lusingander in #160
- Preserve search state on refresh by @lusingander in #161