security/clamav: update to 1.4.6
1.4.6 (2026-08-07)
ClamAV 1.4.6 is a patch release with the following fixes:
- [CVE-2026-20345](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-20345):
Fixed an indexing error while converting GPT partition names that could
read or write beyond a stack-allocated partition entry.
This issue affects ClamAV 0.98.2 through 1.5.3.
The fix is included in 1.4.6 and 1.5.4.
Thank you to Atuin - Automated Vulnerability Discovery Engine, Tianchu Chen
of Tencent Xuanwu Lab for identifying this issue.
- [CVE-2026-20339](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-20339):
Fixed an integer overflow in the PESpin unpacker that could allocate an
undersized buffer and then write beyond it while rebuilding a PE file.
[62 lines not shown]
audio/fasttracker2: Update to 2.22
Changes since 2.21:
v2.22 - 19.07.2026
* Fixed: The "All files" mode in Disk Op. had consistency issues
when changing the Disk Op. item.
* Fixed a bug where exiting text editing mode with the enter/return
key could cause a sample trigger to happen afterwards. This also
applied to certain System Request dialogs.
audio/din: Update to 65
Changes since 64.2:
DIN Is Noise 65:
* fixed crash of DIN64.2 if the whole beat pattern is cut into memory!
/*
flip
flips beat pattern between start/end vertex about
vertical axis
*/
/*
Beater editor now accesible via Menu on all instruments
*/
* improved Polyrhythm plugin
* improved write-svg command
that writes curve seen in any curve editor into an svg file
[2 lines not shown]
palemoon: Update to 34.3.2
- A large security audit of over 200 sec bugs in Mozilla land has been
performed, with the vast majority not being applicable to our code base
(primarily e10s/IPC bugs).
- Implemented the URL.Parse() JavaScript convenience function.
Disable NLS to ensure build consistency (and match the current PLIST)
This fixes the build when NLS is configured, because the PLIST does not
currently have any of the NLS files listed. If NLS is required for this
package, additional work will need to be done on the NLS option and
subsequent PLIST entries.
ugrep: updated to 7.8.4
7.8.4
MinGW portability, tested MinGW-w64 UCRT64 with MSYS2 GCC 16.1; note: make test skips the directory recursive searches due to lack of MinGW symlink handling.
fail fast when DFA position sets exceed complexity limits
py-pip: update to 26.2.1.
26.2.1 (2026-08-04)
Bug Fixes
Reallow keyring installed in a (non-activated) virtual environment
to be be used via the import provider method while installing
build dependencies. (#14227)
26.2 (2026-07-29)
Deprecations and Removals
Newly published packages will no longer be immediately visible
to pip if the index uses caching. To install a newly published
package, use --refresh-package. (#13680)
Drop support for detecting legacy, non-PEP 405, virtualenv (<
[124 lines not shown]