NetBSD/pkgsrc tkacTGxdoc CHANGES-2026

   Updated security/libksba, security/gnupg2
VersionDeltaFile
1.3011+3-1doc/CHANGES-2026
+3-11 files

NetBSD/pkgsrc ReIGVrNsecurity/gnupg2 distinfo Makefile

   gnupg2: updated to 2.5.20

   Noteworthy changes in version 2.5.20 (2026-05-13)

   * New and extended features:

     - gpgsm: Implement GCM encryption.  Note that decryption works
       since version 2.3.2.
     - gpgsm: New option --attribute and server command SETATTR to
       include arbitrary signed or unsigned attributes into a signature.
       Enable only with libksba 1.7.0 or later.
     - gpgsm: Introduce system attribute _signingCertificateV2.

   * Bug fixes:

     - gpg: Fix wrong assertion failure which could very rarely occur
       during key signature checking.
     - gpg: Consider certify-only keys for revocation signature check.
     - gpgsm: Fix possible double free in the CMS parser.

    [13 lines not shown]
VersionDeltaFile
1.97+4-4security/gnupg2/distinfo
1.176+2-2security/gnupg2/Makefile
+6-62 files

NetBSD/pkgsrc 5Pi1G1Ksecurity/libksba distinfo Makefile

   libksba: updated to 1.8.0

   Noteworthy changes in version 1.8.0 (2026-05-13) [C24/A16/R0]

   * New function ksba_cms_get_attribute.
   * Support building of unsigned attributes with
      ksba_cms_add_attribute.
VersionDeltaFile
1.36+4-4security/libksba/distinfo
1.49+2-2security/libksba/Makefile
+6-62 files

NetBSD/pkgsrc GB30kAcdoc CHANGES-2026

   Updated devel/py-pydantic[-core]
VersionDeltaFile
1.3010+3-1doc/CHANGES-2026
+3-11 files

NetBSD/pkgsrc izXzY8udevel/py-pydantic distinfo Makefile, devel/py-pydantic-core distinfo Makefile

   py-pydantic-core py-pydantic: updated to 2.13.4

   v2.13.4 (2026-05-06)

   Packaging

   Bump libc from 0.2.155 to 0.2.185
   Adapt pydantic-core linker flags on macOS

   Fixes

   Preserve RootModel core metadata
VersionDeltaFile
1.35+7-7devel/py-pydantic-core/distinfo
1.37+4-4devel/py-pydantic/distinfo
1.41+3-3devel/py-pydantic/Makefile
1.37+2-2devel/py-pydantic-core/Makefile
1.23+1-1devel/py-pydantic-core/cargo-depends.mk
+17-175 files

NetBSD/pkgsrc B34wIhodoc CHANGES-2026

   Updated graphics/opencolorio, graphics/openimageio
VersionDeltaFile
1.3009+3-1doc/CHANGES-2026
+3-11 files

NetBSD/pkgsrc 2YEUrAYgraphics/openimageio distinfo PLIST

   openimageio: updated to 3.1.13.1

   Release 3.1.13.1 and 3.1.13.0 (May 3, 2026) -- compared to 3.1.12.0

   IBA: Add FLIP perceptual image difference metric as an experimental feature, including ImageBufAlgo::experimental::FLIP_diff() C++ API, Python ImageBufAlgo.FLIP_diff(), and oiiotool --flipdiff command (requires --experimental flag). Also introduces oiiotool --experimental flag to enable features not yet part of the stable API.
   fmath.h: degrees() and radians() are now constexpr.
   ImageSpec: get_string_attribute() now correctly converts non-string attributes to string
   bmp: Correctly handle the combination of greyscale + RLE compression
   dds: Corruption protection: validate resolution and guard against integer overflow
   dpx: Several safety fixes for corrupt DPX files: integer overflow protection in buffer size calculations, span-based pointer safety, and use of check_open() for resolution/channel validation
   heif: Fix incorrect tracking of current subimage
   iinfo: Better error handling and propagation, especially from --hash; fix return code when a file could not be read
   jpeg: Be more flexible with corrupt IPTC blocks; use "imageinput:strict" to control whether a bad block is skipped silently or fails the whole file
   jpeg2000: Guard against integer overflow in buffer size computation
   rla: Harden against corrupted files: guard against RLE buffer overruns and improve seek robustness
   sgi: Better detection of corrupt RLE info that could overflow
   softimage: Multiple hardening fixes against corrupted input: prevent RLE buffer overruns
   targa: Protection against corrupt, mis-sized palette; fix misunderstanding of non-zero palette start index
   tiff: Care with missing rowsperstrip

    [8 lines not shown]
VersionDeltaFile
1.42+4-4graphics/openimageio/distinfo
1.19+3-3graphics/openimageio/PLIST
1.130+2-3graphics/openimageio/Makefile
+9-103 files

NetBSD/pkgsrc Xkha9GUgraphics/opencolorio distinfo Makefile

   opencolorio: updated to 2.5.2

   2.5.2

   This is a bug-fix and security release that addresses CVE-2026-42450 and the other issues described below. It is ABI compatible with 2.5.1.

   CVE-2026-42450 affects all prior OCIO 1.x and 2.x versions.
VersionDeltaFile
1.18+4-4graphics/opencolorio/distinfo
1.21+2-2graphics/opencolorio/Makefile
+6-62 files

NetBSD/pkgsrc IWnl0vIdevel/meson build.mk

   meson: allow supplying an argument to the build target

   The default was empty, so do _not_ default to the pkgsrc BUILD_TARGET
   by default.
VersionDeltaFile
1.33+4-2devel/meson/build.mk
+4-21 files

NetBSD/pkgsrc LJ0dsNDdoc TODO

   doc/TODO: + erlang-29.0.
VersionDeltaFile
1.27255+2-2doc/TODO
+2-21 files

NetBSD/pkgsrc psaASCNdevel/qt6-qtwayland distinfo

   qt6-qtwayland: do the update
VersionDeltaFile
1.22+4-4devel/qt6-qtwayland/distinfo
+4-41 files

NetBSD/pkgsrc 0OMbc6xfilesystems Makefile

   sort
VersionDeltaFile
1.63+2-2filesystems/Makefile
+2-21 files

NetBSD/pkgsrc AJMDu7ydoc CHANGES-2026

   doc: Updated sysutils/intel-microcode-netbsd to 20260512
VersionDeltaFile
1.3008+2-1doc/CHANGES-2026
+2-11 files

NetBSD/pkgsrc GhddAXCsysutils/intel-microcode-netbsd PLIST distinfo

   Update sysutils/intel-microcode-netbsd to 20260512

   ### Purpose

   - Security updates for INTEL-SA-01420
   - Update for functional issues. Refer to 4th Gen Intel Xeon Scalable Processors Specification Update for details.
   - Update for functional issues. Refer to 5th Gen Intel Xeon Scalable Processors Specification Update for details.
   - Update for functional issues. Refer to Intel Core Ultra 200 V Series Processor for details.
   - Update for functional issues. Refer to Intel Core Ultra Processors (Series 2) for details.
   - Update for functional issues. Refer to Intel Core Ultra Processors (Series 3) for details.
   - Update for functional issues. Refer to Intel Xeon 6700 Series Processors with E-cores for details.
   - Update for functional issues. Refer to Intel Xeon 6900/6700/6500 Series Processors with P-cores for details.
   - Update for functional issues. Refer to Intel Xeon 6700P-B/6500P-B-Series SoC with P-Cores for details.

   ### New Platforms

   | Processor      | Stepping | F-M-S/PI    | Old Ver  | New Ver  | Products
   |:---------------|:---------|:------------|:---------|:---------|:---------
   | PTL 404        | A1       | 06-cc-03/90 |          | 0000011b | Intel Core Ultra Processor (Series 3)

    [16 lines not shown]
VersionDeltaFile
1.34+7-1sysutils/intel-microcode-netbsd/PLIST
1.63+4-4sysutils/intel-microcode-netbsd/distinfo
1.72+2-2sysutils/intel-microcode-netbsd/Makefile
+13-73 files

NetBSD/pkgsrc wQr4DGzcross/ppc-morphos-gcc distinfo, cross/ppc-morphos-gcc/patches patch-libcody_buffer.cc patch-libcody_client.cc

   Make cross/ppc-morphos-gcc compile on Fedora 44
VersionDeltaFile
1.1+273-0cross/ppc-morphos-gcc/patches/patch-libcody_buffer.cc
1.1+173-0cross/ppc-morphos-gcc/patches/patch-libcody_client.cc
1.1+108-0cross/ppc-morphos-gcc/patches/patch-libcody_server.cc
1.1+22-0cross/ppc-morphos-gcc/patches/patch-libcody_cody.hh
1.4+5-1cross/ppc-morphos-gcc/distinfo
+581-15 files

NetBSD/pkgsrc ykSodgvdoc CHANGES-2026

   doc: Updated math/R to 4.5.3
VersionDeltaFile
1.3007+2-1doc/CHANGES-2026
+2-11 files

NetBSD/pkgsrc 9PDztGJmath/R distinfo Makefile

   (math/R) Updated 4.5.2 to 4.5.3, another update may follow,:

   CHANGES IN R 4.5.3:

     UTILITIES:

       * tools/fetch-recommended can be used instead of
         tools/rsync-recommended to fetch recommended packages into R
         sources using curl on systems without rsync or behind firewalls.

     PACKAGE INSTALLATION:

       * C++ standard specifications (CXX_STD = in src/Makevars* and in
         the SystemRequirements field of the DESCRIPTION file) are now
         checked more thoroughly.  Invalid values are still ignored but
         now give a warning, as do contradictory specifications.

       * (Preliminary) support for C++26 has been extended to Windows.


    [51 lines not shown]
VersionDeltaFile
1.117+4-4math/R/distinfo
1.283+4-3math/R/Makefile
1.46+2-1math/R/PLIST
+10-83 files

NetBSD/pkgsrc Y1NX9GCmail/mu distinfo, mail/mu/patches patch-lib_utils_mu-sexp.cc patch-lib_utils_mu-html-to-text.cc

   mu: found another ctype(3) issue...
VersionDeltaFile
1.1+32-0mail/mu/patches/patch-lib_utils_mu-sexp.cc
1.2+11-2mail/mu/patches/patch-lib_utils_mu-html-to-text.cc
1.18+3-2mail/mu/distinfo
+46-43 files

NetBSD/pkgsrc mnYNtU3sysutils/gvfs hacks.mk distinfo

   sysutils/gvfs: fix broken gvfs binary (missing shared object)
VersionDeltaFile
1.2+6-1sysutils/gvfs/hacks.mk
1.29+2-2sysutils/gvfs/distinfo
1.144+2-1sysutils/gvfs/Makefile
+10-43 files

NetBSD/pkgsrc E0Bl6Qnmail/mu distinfo, mail/mu/patches patch-lib_message_mu-labels.cc patch-lib_message_mu-message-part.cc

   mu: found more ctype bugs
VersionDeltaFile
1.1+20-0mail/mu/patches/patch-lib_message_mu-labels.cc
1.1+15-0mail/mu/patches/patch-lib_message_mu-message-part.cc
1.1+15-0mail/mu/patches/patch-lib_mu-query-processor.cc
1.1+15-0mail/mu/patches/patch-lib_utils_mu-utils.cc
1.17+5-1mail/mu/distinfo
+70-15 files

NetBSD/pkgsrc VqNbhmwmail/mu distinfo, mail/mu/patches patch-lib_utils_mu-html-to-text.cc

   mu: fixed ctype(3) issue
VersionDeltaFile
1.1+24-0mail/mu/patches/patch-lib_utils_mu-html-to-text.cc
1.16+2-1mail/mu/distinfo
+26-12 files

NetBSD/pkgsrc bDF3szzdoc CHANGES-2026

   Updated www/py-django[5]
VersionDeltaFile
1.3006+3-1doc/CHANGES-2026
+3-11 files

NetBSD/pkgsrc xb698ABwww/py-django5 distinfo Makefile

   py-django5: updated to 5.2.14

   Django 5.2.14 fixes three security issues with severity “low” in 5.2.13.

   CVE-2026-5766: Potential denial-of-service vulnerability in ASGI requests via file upload limit bypass¶

   ASGI requests with a missing or understated Content-Length header could bypass the FILE_UPLOAD_MAX_MEMORY_SIZE limit, potentially loading large files into memory and causing service degradation.

   As a reminder, Django expects a limit to be configured at the web server level rather than solely relying on FILE_UPLOAD_MAX_MEMORY_SIZE.

   This issue has severity “low” according to the Django security policy.

   CVE-2026-35192: Session fixation via public cached pages and SESSION_SAVE_EVERY_REQUEST¶

   Response headers did not vary on cookies if a session was not modified, but SESSION_SAVE_EVERY_REQUEST was True. A remote attacker could steal a user’s session after that user visits a cached public page.

   This issue has severity “low” according to the Django security policy.

   CVE-2026-6907: Potential exposure of private data due to incorrect handling of Vary: * in UpdateCacheMiddleware¶

    [2 lines not shown]
VersionDeltaFile
1.2+4-4www/py-django5/distinfo
1.2+2-2www/py-django5/Makefile
+6-62 files

NetBSD/pkgsrc G2SDHLwwww/py-django distinfo Makefile

   py-django: updated to 6.0.5

   6.0.5

   Django 6.0.5 fixes three security issues with severity “low” and several bugs in 6.0.4.

   CVE-2026-5766: Potential denial-of-service vulnerability in ASGI requests via file upload limit bypass

   ASGI requests with a missing or understated Content-Length header could bypass the FILE_UPLOAD_MAX_MEMORY_SIZE limit, potentially loading large files into memory and causing service degradation.

   As a reminder, Django expects a limit to be configured at the web server level rather than solely relying on FILE_UPLOAD_MAX_MEMORY_SIZE.

   This issue has severity “low” according to the Django security policy.

   CVE-2026-35192: Session fixation via public cached pages and SESSION_SAVE_EVERY_REQUEST

   Response headers did not vary on cookies if a session was not modified, but SESSION_SAVE_EVERY_REQUEST was True. A remote attacker could steal a user’s session after that user visits a cached public page.

   This issue has severity “low” according to the Django security policy.

    [12 lines not shown]
VersionDeltaFile
1.127+4-4www/py-django/distinfo
1.155+2-2www/py-django/Makefile
+6-62 files

NetBSD/pkgsrc d4kx5jidoc CHANGES-2026

   Updated net/samba4, net/freeradius
VersionDeltaFile
1.3005+3-1doc/CHANGES-2026
+3-11 files

NetBSD/pkgsrc 0yFuwCfnet/freeradius PLIST Makefile, net/freeradius-freetds Makefile

   freeradius: updated to 3.2.8

   FreeRADIUS 3.2.8 Wed 20 Aug 2025 12:00:00 UTC urgency=low
   Configuration changes
   * Replace dictionary.infinera with the correct one.
   * Update dictionary.alteon

   Feature improvements
   * Add support for automated fuzzing.  This doesn't affect
     normal operations, but it does allow for testing of the
     RADIUS decoder.
   * Allow tagged attributes to use ":V" as a tag in some cases.
     The tag is then read from the value which is being assigned
     to the attribute.  This functionality is allowed in 'update'
     sections, including 'update' in module configurations.
     See mods-available/ldap for an example.
   * Add kafka module.  See mods-available/kafka.
   * Allow &control:Packet-SRC-IP-Address to be used when
     proxying needs a given source address.

    [47 lines not shown]
VersionDeltaFile
1.42+100-2net/freeradius/PLIST
1.132+2-9net/freeradius/Makefile
1.51+4-5net/freeradius/distinfo
1.17+3-3net/freeradius/Makefile.common
1.32+1-2net/freeradius-sqlite3/Makefile
1.35+1-2net/freeradius-freetds/Makefile
+111-234 files not shown
+115-3010 files

NetBSD/pkgsrc BGLeULSnet/samba4 distinfo Makefile

   samba4: updated to 4.24.2

   Changes since 4.24.1
   * BUG 16038: Samba 4.24 with cups can't get queue and shows errors about
     fetch_share_cache_time
   * BUG 16043: Fix a directory file descriptor leak in vfs_glusterfs that
     caused      unbounded memory growth on the GlusterFS brick with
     persistent SMB2      connections.
   * BUG 16030: Windows Offline Files fails with permission error when directory
     has the read‑only attribute set
   * BUG 15991: samba not triggering mount of zfs snapshot in dataset
     .zfs/snapshots/<snapname> directory
   * BUG 15999: net ads join still fails with multiple DCs
   * BUG 16076: samba-tool shows wrong format specifiers for timestamp
     attributes
   * BUG 14638: restrict anonymous = 2 breaks RODC functionality
   * BUG 15973: smbpasswd can crash winbindd on an AD DC
   * BUG 15995: smbd does not cleanup on disconnect of the transport connection
     on lease break errors

    [9 lines not shown]
VersionDeltaFile
1.125+4-4net/samba4/distinfo
1.215+2-2net/samba4/Makefile
+6-62 files

NetBSD/pkgsrc dTP9dx3doc CHANGES-2026 TODO

   Updated editors/qtcreator
VersionDeltaFile
1.3004+2-1doc/CHANGES-2026
1.27254+1-2doc/TODO
+3-32 files

NetBSD/pkgsrc yngoFUbeditors/qtcreator PLIST distinfo, editors/qtcreator/patches patch-src_app_CMakeLists.txt

   qtcreator: updated to 19.0.1

   Qt Creator version 19.0.1 contains bug fixes.

   General

   Fixed

   * That preferences for newly enabled plugins were only available after restart
   * Various issues with marking the `Preferences` as dirty
   * A possible crash when opening the `About Qt Creator` dialog multiple times
   * That using the keyboard shortcut for `Advanced Find` did not raise the search
     widget
   * Model Context Protocol
       * A crash when using the `quit` action

   Editing

   Fixed

    [16 lines not shown]
VersionDeltaFile
1.10+94-49editors/qtcreator/PLIST
1.16+5-5editors/qtcreator/distinfo
1.4+5-5editors/qtcreator/patches/patch-src_app_CMakeLists.txt
1.48+6-3editors/qtcreator/Makefile
+110-624 files

NetBSD/pkgsrc yGYVz36doc CHANGES-2026

   doc: Updated textproc/gsed to 4.10
VersionDeltaFile
1.3003+2-1doc/CHANGES-2026
+2-11 files