NetBSD/pkgsrc PiSA90mdoc CHANGES-2026

   Updated lang/python310, lang/py310-html-docs, lang/nodejs
VersionDeltaFile
1.1536+4-1doc/CHANGES-2026
+4-11 files

NetBSD/pkgsrc oxEnBkllang/nodejs PLIST distinfo, lang/nodejs/patches patch-deps_v8_third__party_abseil-cpp_absl_debugging_internal_elf__mem__image.cc

   nodejs: updated to 25.8.0

   25.8.0

   Notable Changes

   - build, doc: use new api doc tooling (flakey5)
   - (SEMVER-MINOR) sqlite: add limits property to DatabaseSync (Mert Can Altin)
   - (SEMVER-MINOR) src: add C++ support for diagnostics channels (RafaelGSS)
   - (SEMVER-MINOR) src,permission: add --permission-audit (RafaelGSS)
   - (SEMVER-MINOR) test_runner: expose worker ID for concurrent test execution (Ali Hassan)
VersionDeltaFile
1.98+13-4lang/nodejs/PLIST
1.314+5-5lang/nodejs/distinfo
1.4+3-3lang/nodejs/patches/patch-deps_v8_third__party_abseil-cpp_absl_debugging_internal_elf__mem__image.cc
1.344+2-2lang/nodejs/Makefile
+23-144 files

NetBSD/pkgsrc VHvLGzMlang/py310-html-docs distinfo Makefile, lang/python310 distinfo Makefile

   python310 py310-html-docs: updated to 3.10.20

   Python 3.10.20

   Security

   gh-144125: BytesGenerator will now refuse to serialize (write) headers that are unsafely folded or delimited; see verify_generated_headers. (Contributed by Bas Bloemsaat and Petr Viktorin in gh-121650).
   gh-143935: Fixed a bug in the folding of comments when flattening an email message using a modern email policy. Comments consisting of a very long sequence of non-foldable characters could trigger a forced line wrap that omitted the required leading space on the continuation line, causing the remainder of the comment to be interpreted as a new header field. This enabled header injection with carefully crafted inputs.
   gh-143925: Reject control characters in data: URL media types.
   gh-143919: Reject control characters in http.cookies.Morsel fields and values.
   gh-143916: Reject C0 control characters within wsgiref.headers.Headers fields, values, and parameters.
   gh-142145: Remove quadratic behavior in xml.minidom node ID cache clearing. In order to do this without breaking existing users, we also add the ownerDocument attribute to xml.dom.minidom elements and attributes created by directly instantiating the Element or Attr class. Note that this way of creating nodes is not supported; creator functions like xml.dom.Document.documentElement() should be used instead.
   gh-137836: Add support of the “plaintext” element, RAWTEXT elements “xmp”, “iframe”, “noembed” and “noframes”, and optionally RAWTEXT element “noscript” in html.parser.HTMLParser.
   gh-136063: email.message: ensure linear complexity for legacy HTTP parameters parsing. Patch by Bénédikt Tran.
   gh-136065: Fix quadratic complexity in os.path.expandvars().
   gh-119451: Fix a potential memory denial of service in the http.client module. When connecting to a malicious server, it could cause an arbitrary amount of memory to be allocated. This could have led to symptoms including a MemoryError, swapping, out of memory (OOM) killed processes or containers, or even system crashes.
   gh-119452: Fix a potential memory denial of service in the http.server module. When a malicious user is connected to the CGI server on Windows, it could cause an arbitrary amount of memory to be allocated. This could have led to symptoms including a MemoryError, swapping, out of memory (OOM) killed processes or containers, or even system crashes.
   gh-119342: Fix a potential memory denial of service in the plistlib module. When reading a Plist file received from untrusted source, it could cause an arbitrary amount of memory to be allocated. This could have led to symptoms including a MemoryError, swapping, out of memory (OOM) killed processes or containers, or even system crashes.


    [10 lines not shown]
VersionDeltaFile
1.36+4-4lang/python310/distinfo
1.23+4-4lang/py310-html-docs/distinfo
1.44+2-3lang/python310/Makefile
1.21+2-2lang/py310-html-docs/Makefile
1.21+2-2lang/python310/dist.mk
+14-155 files

NetBSD/pkgsrc cShszRJdoc CHANGES-2026

   Updated lang/python31[12], lang/py31[12]-html-docs
VersionDeltaFile
1.1535+5-1doc/CHANGES-2026
+5-11 files

NetBSD/pkgsrc YGZczgUlang/py311-html-docs distinfo Makefile, lang/python311 distinfo Makefile

   python311 py311-html-docs: updated to 3.11.15

   Python 3.11.15

   Security

   gh-144125: BytesGenerator will now refuse to serialize (write) headers that are unsafely folded or delimited; see verify_generated_headers. (Contributed by Bas Bloemsaat and Petr Viktorin in gh-121650).
   gh-143935: Fixed a bug in the folding of comments when flattening an email message using a modern email policy. Comments consisting of a very long sequence of non-foldable characters could trigger a forced line wrap that omitted the required leading space on the continuation line, causing the remainder of the comment to be interpreted as a new header field. This enabled header injection with carefully crafted inputs.
   gh-143925: Reject control characters in data: URL media types.
   gh-143919: Reject control characters in http.cookies.Morsel fields and values.
   gh-143916: Reject C0 control characters within wsgiref.headers.Headers fields, values, and parameters.
   gh-142145: Remove quadratic behavior in xml.minidom node ID cache clearing. In order to do this without breaking existing users, we also add the ownerDocument attribute to xml.dom.minidom elements and attributes created by directly instantiating the Element or Attr class. Note that this way of creating nodes is not supported; creator functions like xml.dom.Document.documentElement() should be used instead.
   gh-137836: Add support of the “plaintext” element, RAWTEXT elements “xmp”, “iframe”, “noembed” and “noframes”, and optionally RAWTEXT element “noscript” in html.parser.HTMLParser.
   gh-136063: email.message: ensure linear complexity for legacy HTTP parameters parsing. Patch by Bénédikt Tran.
   gh-136065: Fix quadratic complexity in os.path.expandvars().
   gh-119451: Fix a potential memory denial of service in the http.client module. When connecting to a malicious server, it could cause an arbitrary amount of memory to be allocated. This could have led to symptoms including a MemoryError, swapping, out of memory (OOM) killed processes or containers, or even system crashes.
   gh-119452: Fix a potential memory denial of service in the http.server module. When a malicious user is connected to the CGI server on Windows, it could cause an arbitrary amount of memory to be allocated. This could have led to symptoms including a MemoryError, swapping, out of memory (OOM) killed processes or containers, or even system crashes.
   gh-119342: Fix a potential memory denial of service in the plistlib module. When reading a Plist file received from untrusted source, it could cause an arbitrary amount of memory to be allocated. This could have led to symptoms including a MemoryError, swapping, out of memory (OOM) killed processes or containers, or even system crashes.


    [10 lines not shown]
VersionDeltaFile
1.16+4-4lang/py311-html-docs/distinfo
1.24+4-4lang/python311/distinfo
1.44+3-3lang/python311/Makefile
1.16+2-2lang/py311-html-docs/Makefile
1.16+2-2lang/python311/dist.mk
+15-155 files

NetBSD/pkgsrc PIM5HmGlang/py312-html-docs distinfo Makefile, lang/python312 distinfo Makefile

   python312 py312-html-docs: updated to 3.12.13

   Python 3.12.13

   Security

   gh-144125: BytesGenerator will now refuse to serialize (write) headers that are unsafely folded or delimited; see verify_generated_headers. (Contributed by Bas Bloemsaat and Petr Viktorin in gh-121650).
   gh-143935: Fixed a bug in the folding of comments when flattening an email message using a modern email policy. Comments consisting of a very long sequence of non-foldable characters could trigger a forced line wrap that omitted the required leading space on the continuation line, causing the remainder of the comment to be interpreted as a new header field. This enabled header injection with carefully crafted inputs.
   gh-143925: Reject control characters in data: URL media types.
   gh-143919: Reject control characters in http.cookies.Morsel fields and values.
   gh-143916: Reject C0 control characters within wsgiref.headers.Headers fields, values, and parameters.
   gh-142145: Remove quadratic behavior in xml.minidom node ID cache clearing. In order to do this without breaking existing users, we also add the ownerDocument attribute to xml.dom.minidom elements and attributes created by directly instantiating the Element or Attr class. Note that this way of creating nodes is not supported; creator functions like xml.dom.Document.documentElement() should be used instead.
   gh-137836: Add support of the “plaintext” element, RAWTEXT elements “xmp”, “iframe”, “noembed” and “noframes”, and optionally RAWTEXT element “noscript” in html.parser.HTMLParser.
   gh-136063: email.message: ensure linear complexity for legacy HTTP parameters parsing. Patch by Bénédikt Tran.
   gh-136065: Fix quadratic complexity in os.path.expandvars().
   gh-119451: Fix a potential memory denial of service in the http.client module. When connecting to a malicious server, it could cause an arbitrary amount of memory to be allocated. This could have led to symptoms including a MemoryError, swapping, out of memory (OOM) killed processes or containers, or even system crashes.
   gh-119452: Fix a potential memory denial of service in the http.server module. When a malicious user is connected to the CGI server on Windows, it could cause an arbitrary amount of memory to be allocated. This could have led to symptoms including a MemoryError, swapping, out of memory (OOM) killed processes or containers, or even system crashes.
   gh-119342: Fix a potential memory denial of service in the plistlib module. When reading a Plist file received from untrusted source, it could cause an arbitrary amount of memory to be allocated. This could have led to symptoms including a MemoryError, swapping, out of memory (OOM) killed processes or containers, or even system crashes.


    [5 lines not shown]
VersionDeltaFile
1.14+4-4lang/py312-html-docs/distinfo
1.17+4-4lang/python312/distinfo
1.34+3-3lang/python312/Makefile
1.14+2-2lang/python312/dist.mk
1.14+2-2lang/py312-html-docs/Makefile
+15-155 files

NetBSD/pkgsrc 59vYOundoc CHANGES-2026

   Updated www/nginx, www/nginx-devel
VersionDeltaFile
1.1534+3-1doc/CHANGES-2026
+3-11 files

NetBSD/pkgsrc C1Ugyszwww/nginx distinfo Makefile, www/nginx-devel distinfo Makefile

   nginx nginx-devel: updated to 1.28.2 and 1.29.5

   nginx-1.28.2 stable and nginx-1.29.5 mainline versions have been released, with
   a fix for the SSL upstream injection vulnerability (CVE-2026-1642).
VersionDeltaFile
1.4+11-11www/nginx-devel/patches/patch-conf_nginx.conf
1.139+7-11www/nginx/distinfo
1.131+8-8www/nginx-devel/distinfo
1.189+2-7www/nginx/Makefile
1.166+2-3www/nginx-devel/Makefile
1.49+2-2www/nginx-devel/options.mk
+32-422 files not shown
+35-458 files

NetBSD/pkgsrc 5aaHXKBdoc CHANGES-2026

   Updated graphics/py-tifffile, databases/py-sqlalchemy
VersionDeltaFile
1.1533+3-1doc/CHANGES-2026
+3-11 files

NetBSD/pkgsrc MfukVtPdatabases/py-sqlalchemy distinfo Makefile

   py-sqlalchemy: updated to 2.0.48

   2.0.48

   engine

   [engine] [bug]

   Fixed a critical issue in Engine where connections created in conjunction with the DialectEvents.do_connect() event listeners would receive shared, mutable collections for the connection arguments, leading to a variety of potential issues including unlimited growth of the argument list as well as elements within the parameter dictionary being shared among concurrent connection calls. In particular this could impact do_connect routines making use of complex mutable authentication structures.
VersionDeltaFile
1.84+4-4databases/py-sqlalchemy/distinfo
1.97+2-2databases/py-sqlalchemy/Makefile
+6-62 files

NetBSD/pkgsrc 0eCgNdqgraphics/py-tifffile distinfo Makefile

   py-tifffile: updated to 2026.3.3

   2026.3.3

   - Pass 5137 tests.
   - Do not convert TVIPS pixel sizes to m.
   - Support writing packed integers with imagecodecs > 2026.1.14.
   - Support reading ccitt compressed images with imagecodecs > 2026.1.14.
VersionDeltaFile
1.60+4-4graphics/py-tifffile/distinfo
1.68+2-2graphics/py-tifffile/Makefile
+6-62 files

NetBSD/pkgsrc f1kyY1hnet/tigervnc Makefile distinfo, net/tigervnc/patches patch-CMakeLists.txt

   tigervnc: disable googletest dependency

   gets rid of unneeded dependency
VersionDeltaFile
1.8+10-7net/tigervnc/patches/patch-CMakeLists.txt
1.87+1-2net/tigervnc/Makefile
1.31+2-1net/tigervnc/distinfo
+13-103 files

NetBSD/pkgsrc xeBrNFBgraphics/flameshot Makefile

   flameshot: remove stale PKGCONFIG_OVERRIDE
VersionDeltaFile
1.7+1-3graphics/flameshot/Makefile
+1-31 files

NetBSD/pkgsrc j0ob1F8doc CHANGES-2026

   doc: added graphics/qt6-qt-color-widgets, updated graphics/flameshot
VersionDeltaFile
1.1532+3-1doc/CHANGES-2026
+3-11 files

NetBSD/pkgsrc IGnolWbgraphics Makefile

   graphics: +qt6-qt-color-widgets
VersionDeltaFile
1.1113+2-1graphics/Makefile
+2-11 files

NetBSD/pkgsrc 8B26LTvgraphics/flameshot Makefile PLIST

   flameshot: update to 13.3.0

   New in version 13:
   Package maintainers can compile out the update checker using -DDISABLE_UPDATE_CHECKER.
   The pixelation feature has been replaced with a new "secure" implementation that only uses pixels outside of the area to be redacted.
   Pinned images can now be rotated.
   A grim based screenshot adapter has been added to work with more wlroots Wayland compositors. Users can enable this in settings.
   Users can symmetrically resize (holding Shift) and preserve aspect ratio (using Ctrl) while resizing.
   Pinned images can have a transparency effect applied.
   A grid can be optionally enabled via the sidebar, and users can have their annotations snap to grid.
   SingleApplication dependency has moved to KdSingleApplication to work around a Qt SharedMemory bug.
   New dateformat of %d-%m-%Y has been added.
   New option to prompt user before exiting has been added to config.
   JPEG quality option has been added.
   Enable saving HEIF/HEIC when supported by 3rd party plug-ins.
   Kde-connect share integration. (needs more testing)
   Add Shortcut to Cancel current selection using CtrlBackspace
   Pinned images now have window titled flameshot-pin.
   Separate tool size for the tools.

    [11 lines not shown]
VersionDeltaFile
1.6+12-9graphics/flameshot/Makefile
1.2+9-0graphics/flameshot/PLIST
1.2+4-4graphics/flameshot/distinfo
+25-133 files

NetBSD/pkgsrc A4hghuMgraphics/qt6-qt-color-widgets Makefile

   g/c stale comment
VersionDeltaFile
1.2+1-3graphics/qt6-qt-color-widgets/Makefile
+1-31 files

NetBSD/pkgsrc vUaW0Wqgraphics/qt6-qt-color-widgets PLIST Makefile

   graphics/qt6-qt-color-widgets: import qt6-qt-color-widgets-3.0.0

   Color dialog that is more user-friendly than the default QColorDialog.
VersionDeltaFile
1.1+51-0graphics/qt6-qt-color-widgets/PLIST
1.1+29-0graphics/qt6-qt-color-widgets/Makefile
1.1+14-0graphics/qt6-qt-color-widgets/buildlink3.mk
1.1+5-0graphics/qt6-qt-color-widgets/distinfo
1.1+1-0graphics/qt6-qt-color-widgets/DESCR
+100-05 files

NetBSD/pkgsrc A7mEzmmdoc CHANGES-2026

   doc: Updated net/deskflow to 1.26.0
VersionDeltaFile
1.1531+2-1doc/CHANGES-2026
+2-11 files

NetBSD/pkgsrc 0K6tiTaprint/zathura buildlink3.mk

   print/zathura: set BUILDLINK_API_DEPENDS.zathura>=2026.02.22

   We missed the API and ABI bump at version 0.5.8. The API and ABI versions
   are exposed to zathura plugins, so to be safe adjust the API version to
   match the latest update to zathura-2026.02.22.

   Discussed on tech-pkg.
VersionDeltaFile
1.33+2-3print/zathura/buildlink3.mk
+2-31 files

NetBSD/pkgsrc 7IiHqeqnet/tigervnc Makefile

   tigervnc: needs googletest

   tests/unit/gesturehandler.cxx:27:10: fatal error: gtest/gtest.h
VersionDeltaFile
1.86+2-1net/tigervnc/Makefile
+2-11 files

NetBSD/pkgsrc vJuZXezdoc CHANGES-2026

   doc: Updated print/mupdf to 1.27.2
VersionDeltaFile
1.1530+2-1doc/CHANGES-2026
+2-11 files

NetBSD/pkgsrc mcA4dYtprint/mupdf distinfo Makefile, print/mupdf/patches patch-source_fitz_load-jpx.c patch-Makerules

   print/mupdf: update to mupdf-1.27.2

   Patches updated:

     patches/patch-Makelists:

       "Fix compiling with a pre-c++20 compiler" has been addressed
       by upstream in a similar way, by testing whether USE_ZXINGCPP
       is set.

     patches/patch-source_fitz_stext-search.c:

       Since we don't use the thirdparty libraries from MuPDF, MuPDF
       needs include/mujs/regexp.h from lang/mujs. Please see the
       post-install target in lang/mujs/Makefile.

   List of changes in MuPDF 1.27

     New and updated documentation! Build local HTML and Markdown

    [94 lines not shown]
VersionDeltaFile
1.11+11-11print/mupdf/patches/patch-source_fitz_load-jpx.c
1.3+11-10print/mupdf/patches/patch-Makerules
1.82+9-8print/mupdf/distinfo
1.1+16-0print/mupdf/patches/patch-source_fitz_stext-search.c
1.5+2-13print/mupdf/patches/patch-Makelists
1.139+9-5print/mupdf/Makefile
+58-472 files not shown
+68-558 files

NetBSD/pkgsrc 94pU292doc CHANGES-2026

   doc: Updated lang/mujs to 1.3.9
VersionDeltaFile
1.1529+2-1doc/CHANGES-2026
+2-11 files

NetBSD/pkgsrc 9uEXbmdlang/mujs Makefile distinfo

   devel/mujs: update to mujs-1.3.9

   Briefly discussed on tech-pkg with leot@ and nia@

   pkgsrc changes:

     Install include/mujs/regexp.h which is needed by recent versions of print/mupdf.

   mujs-1.3.9
   ==========

   Commits:
     Bug 709180: Fix simple array check in Array.prototype.sort.
     Bug 709127: Plug memory leak in String.prototype.replace.
     Bug 709128: Avoid undefined behavior for -INT_MIN in js_itoa.
     Avoid UB when computing (unused) pointer from NULL.
     Add "undefined" UB sanitize build target.
     Bug 709124: Guard against malicious Array.prototype.sort comparator.
     Bug 709103: Increase lexbuf capacity counter after realloc (not before).

    [39 lines not shown]
VersionDeltaFile
1.8+8-2lang/mujs/Makefile
1.8+4-4lang/mujs/distinfo
1.4+2-1lang/mujs/PLIST
+14-73 files

NetBSD/pkgsrc NyrJ0mpx11/alacritty Makefile PLIST.App

   alacritty: support building as macOS app bundle
VersionDeltaFile
1.41+17-1x11/alacritty/Makefile
1.1+14-0x11/alacritty/PLIST.App
+31-12 files

NetBSD/pkgsrc HC5I6Nrnet/deskflow PLIST.App

   deskflow: PLIST.App: catch up w/ update
VersionDeltaFile
1.4+2-0net/deskflow/PLIST.App
+2-01 files

NetBSD/pkgsrc oZ2RmXwemulators/qemu PLIST

   qemu: fix PLIST for -doc option. Some files installed unconditionally.
VersionDeltaFile
1.103+3-3emulators/qemu/PLIST
+3-31 files

NetBSD/pkgsrc aF9J0hylang/openjdk11 Makefile

   openjdk11: backport alloca() fix from openjdk17
VersionDeltaFile
1.85+5-1lang/openjdk11/Makefile
+5-11 files

NetBSD/pkgsrc hQiyRtWmail/dbmail Makefile, mail/dbmail/files dbmailhttpd.sh dbmailimapd.sh

   dbmail: ensure pidfile directory exists. Bump
VersionDeltaFile
1.2+11-1mail/dbmail/files/dbmailhttpd.sh
1.4+11-1mail/dbmail/files/dbmailimapd.sh
1.4+11-1mail/dbmail/files/dbmaillmtpd.sh
1.4+11-1mail/dbmail/files/dbmailpop3d.sh
1.2+11-1mail/dbmail/files/dbmailsieved.sh
1.91+4-3mail/dbmail/Makefile
+59-86 files