flawfinder: updated to 2.0.20
2.0.20
Fix unlikely vulnerabilities (involving malicious filenames/text
in analyzed systems) and implement various improvements
* Fix security vulnerabilities found by Gemini:
- Terminal injection in standard output: apply strip_controls() to
level and category in show().
- Terminal injection in CSV output: apply strip_controls() to all
untrusted fields in show_csv() (category, name, warning,
suggestion, note, context_text).
- XML injection in SonarQube output: use quoteattr() for all XML
attributes in output_sonar().
- Defense-in-depth: restrict setattr in Hit.__init__ to an allowlist
of known keys used by rule definitions, countering pickle attacks.
We previously warned to not load untrusted pickle files, but
completely preventing attacks is better.
- Shell injection in CI/CD file entrypoint.sh:
quoted args with "$@" and moved output filename to
[86 lines not shown]
py-cachetools: updated to 7.2.1
v7.2.1 (2026-10-05)
- Improve error handling for ``RRCache.popitem()`` when the cache is
empty.
- Minor style and documentation improvements.
- Update CI environment.
v7.2.0 (2026-09-16)
- Deprecate use of ``cache=None`` to suppress caching with the
``@cached`` decorator.
- Add support for Python 3.15.
- Minor test improvements.
- Minor documentation updates.
py-scp: updated to 0.16.2
0.16.2 (2026-10-06)
- Catch `EOFError` from `channel.close()` that happens sporadically on some devices
- Check erroneous server path on download
py-uvicorn: updated to 0.54.0
0.54.0
Send metadata after the response body
uvicorn 0.54.0 adds response trailers and 103 Early Hints to its experimental HTTP/2 implementation through zttp.
uv add uvicorn==0.54.0 "zttp>=0.0.34"
Send HTTP/2 response trailers. The ASGI http.response.trailers extension lets applications send metadata, such as checksums, after the response body. Clients must send TE: trailers to receive them. Multiple trailer messages are combined before completing the response.
HTTP/2 remains experimental and opt-in. Enable it with --http zttp --http2. Upgrade-based h2c and WebSockets over HTTP/2 remain unsupported.
Hint at resources before the final response
Send 103 Early Hints over HTTP/2. Applications can use the ASGI http.response.early_hint extension to send resource hints before the final response. Each supplied link becomes a separate Link header.
py-jwcrypto: updated to 1.6.1
1.6.1
This release fixes CVE-2026-92091, a low security issue that may result in a Denial of Service on malformed JWK keys
py-utils: updated to 4.1.0
4.1.0
Keep UniqueList membership in sync when replacing an indexed item, and leave membership unchanged when the index is out of range, contributed
Keep UniqueList membership in sync for slice assignment, extend, pop, remove, clear, += and *=, so extend and += no longer add duplicates and removed values can be added again.
Accept one-shot iterables in UniqueList slice assignment, allow a slice to reuse the values it replaces, and reject a slice that repeats a value.
Make copy.copy and copy.deepcopy of a UniqueList return a working copy with its own membership.
Leave UniqueList membership unchanged when insert fails, and answer in for an unhashable value the way a list does.
Make CastedDict and LazyCastedDict load from pickle on every protocol, including pickles written by 4.0.1, and stop copy.copy and copy.deepcopy from casting the stored values a second time.
Cast what setdefault and |= store in a CastedDict or LazyCastedDict. A None default is stored as it is.
Cast the key of a LazyCastedDict once when it is stored. It was cast twice.
Let keyword arguments win over the mapping in update and the constructor of the casted dicts, as dict does.
Make != the opposite of == for SliceableDeque, and compare unequal to a set when an item is unhashable.
Remove the iterable of mappings from the DictUpdateArgs type alias. The code never accepted that shape.
Log the traceback in Logged.exception(), and name the caller in every record of Logged instead of logger.py. Code that passed stacklevel=2 to work around the wrong caller now points one frame too high.
Stop Logurud from crashing on a message with a brace in it. A message without arguments is logged as written, so braces that were doubled to avoid the crash now show doubled.
Keep the value of a class that combines Logged or Logurud with a type such as int or str.
Use the whole match in to_int and to_float for a pattern without a group, and never return a negative power from scale_1024.
[14 lines not shown]
py-tomli: updated to 2.5.0
2.5.0
Added
Binary wheels for Python 3.15
Fixed
Set nested inline array/table limit to 400 to fix mypyc generated binaries crashing unrecoverably in constrained environments (e.g. worker thread in a python:3.13-alpine image)
py-orjson: updated to 3.13.0
3.13.0 - 2026-08-17
Changed
- No longer publish PyPI wheels for Windows x86/i686.
Added
- Serialize new Python 3.15 built-in type `frozendict` identical to
`dict` (PEP 814).
py-peewee: updated to 4.5.3
4.5.3
* JSON path keys on Postgres are rendered inline (`data->>'key'`,
`'{"a","b"}'::text[]`) instead of as bound parameters, so `GROUP BY` and
`ORDER BY` on a JSON lookup work under psycopg3, which binds each occurrence
of a key as a distinct parameter. Applies to the core `JSONField` and to
`playhouse.postgres_ext`.
* `Cast()` and other wrapped nodes over a plain value no longer break result
row processing.
* A write query with a `RETURNING` clause now runs again on every explicit
`execute()` call (like a write query without one). Iterating the query still
reads the result of the last execution. Previously repeated `execute()`
calls returned the cached result without running the query.
* Fix regression in model select `.exists()`
openvpn: updated to 2.7.8
Overview of changes in 2.7.8
Security fixes
- Check for NULL-Bytes in certificate subjects - refuse all such certificates
now as "invalid" (CVE-2026-84790).
- TLS handshake with tls-crypt-v2: do not try to add a wrapped client key
if no key material is available (client bug in response to an ill-behaving
server).
(No CVE assigned as "a malicious server can stop the client from working
properly" is not considered a CVE-worthy security issue according to the
CRA guidelines)
- options: fix unsigned underflow when clearing domain_search_list
(CVE-2026-88964)
- win32: stop cmd.exe from expanding variables in quoted arguments
(CVE-2026-84256)
Bug fixes
[51 lines not shown]
time/ruby-tzinfo-data: update to 1.2026.6
3.2026.1006 (2026-10-06)
* Updated registry entries from the IANA media registry and provisional
media registry and the Apache Tika media registry as of the release date.
palemoon: Update to 35.0.2. New minor release.
v35.0.2 (2026-10-06)
This is a performance, bugfix and security release.
Changes/fixes:
* Disabled the new :has() CSS implementation by default for performance
reasons. See implementation notes.
* Added a preference for handling of improper form element placement in
HTML. See implementation notes.
* Fixed several application crashes.
* Backported an upstream libvpx VP8 decoder fix.
* Fixed an issue in the BigInt implementation for specific JavaScript
calls failing.
* Fixed a potentially exploitable memory leak.
* Security issues addressed: CVE-2026-100822, CVE-2026-100783,
CVE-2026-100773 (DiD), CVE-2026-96869 (DiD) and CVE-2026-100791.
Build tested on CentOS 7 and NetBSD.