NetBSD/pkgsrc ayd7qfw — doc CHANGES-2026

   Updated devel/cargo-nextest, lang/nodejs
VersionDeltaFile
1.6793+3-1doc/CHANGES-2026
+3-11 files

NetBSD/pkgsrc itcB7RE — lang/nodejs Makefile distinfo, lang/nodejs/patches patch-deps_histogram_src_hdr__histogram.c patch-common.gypi

   nodejs: updated to 26.11.1

   26.11.1 (Current)

   - Revert "build: toggle doc-kit verbosity based on V" (Antoine du Hamel)
   - Revert "build, doc: move to redesign" (Antoine du Hamel)
   - Revert "tools: bump the doc group in /tools/doc with 4 updates" (Antoine du Hamel)
VersionDeltaFile
1.15+7-7lang/nodejs/patches/patch-common.gypi
1.333+5-6lang/nodejs/distinfo
1.362+2-2lang/nodejs/Makefile
1.2+1-1lang/nodejs/patches/patch-deps_histogram_src_hdr__histogram.c
+15-164 files

NetBSD/pkgsrc mypkGDg — devel/cargo-nextest Makefile cargo-depends.mk

   cargo-nextest: updated to 0.9.148

   0.9.148

   Changed

   For setup scripts, slow-timeout no longer accepts on-timeout = "pass", and nextest now reports a configuration error if it is specified. A setup script that times out always fails the run. Previously, this setting was accepted but handled inconsistently: the timed-out script was counted as a failure, but the run was not cancelled.
   Internal dependency updates: guppy updated to 0.19.1, and target-spec updated to 3.7.0, updating built-in targets to Rust 1.98.

   Fixed

   Stress runs now exit with a non-zero code if any iteration failed. Previously, with fail-fast disabled, the exit code reflected only the last iteration, so a stress run with failures in earlier iterations exited with code 0 if the last iteration passed.

   Stress runs now always run at least one iteration. Previously, --stress-duration with a very short duration (such as 1ns) could finish without running any tests.

   Runs stopped by immediate fail-fast (--max-fail N:immediate) are now treated as failed rather than cancelled. Previously, in stress runs, the summary read 0 passed; cancelled due to test failure and the failing iteration was not counted as failed.

   When the global timeout fires with immediate fail-fast enabled, nextest now reports the global timeout as the reason the run was cancelled. Previously, the tests terminated by the timeout counted as failures, so nextest printed a second Cancelling due to test failure line and reported a test failure as the reason.


    [11 lines not shown]
VersionDeltaFile
1.26+52-58devel/cargo-nextest/distinfo
1.26+16-18devel/cargo-nextest/cargo-depends.mk
1.30+2-2devel/cargo-nextest/Makefile
+70-783 files

NetBSD/pkgsrc bprbZyi — doc CHANGES-2026

   doc: Updated graphics/libvips to 8.18.7
VersionDeltaFile
1.6792+2-1doc/CHANGES-2026
+2-11 files

NetBSD/pkgsrc 71h7bIm — graphics/libvips Makefile distinfo

   libvips: update to 8.18.7.

   Fix test target.

   20/9/26 8.18.7

   - tiffload: copy colormaps on page load [Ada Logics]
   - buildlut: limit output lut size [Ada Logics]
   - tiffload: check for undersized jp2k tiles [Ada Logics]
   - hough_line: improve bounds check [Ada Logics]
   - pdfiumload: check for buffer too small [Ada Logics]
   - tiffload: check rgba settings between directories [Tanto Security]
   - uhdrload: calculate gain map scale factor using round-to-nearest [lovell]
   - jp2ksave: tag as UNTRUSTED [kleisauke]
   - header: only parse EXIF metadata for blob values [Shopify]
   - jp2kload: more size validation [Akokonunes]

   25/8/26 8.18.6


    [170 lines not shown]
VersionDeltaFile
1.3+7-7graphics/libvips/PLIST
1.3+4-4graphics/libvips/distinfo
1.20+4-3graphics/libvips/Makefile
+15-143 files

NetBSD/pkgsrc IY8d0W5 — doc CHANGES-2026

   net/dnscap: note update of package to 2.5.2 (and rename package to dnscap2)
VersionDeltaFile
1.6791+2-1doc/CHANGES-2026
+2-11 files

NetBSD/pkgsrc 9seS2vS — net/dnscap distinfo PLIST, net/dnscap/patches patch-Makefile.in

   net/dnscap: Update dnscap from version 1.4.1 (from 2015) to 2.5.1

   Prompted by jperkin's MacOS 27 bulk build results

   10+ years of changes are too many to summarise here, but TL;DR is that

   + there are a lot more dependencies (on a lot of archivers/compression
     libraries), openssl, and ldns,
   + the package name in pkgsrc is now dnscap2,
   + and dnscap now supports plugins (${PREFIX}/bin/dnscap-rssm-rssac002
     is one such).
VersionDeltaFile
1.7+17-4net/dnscap/Makefile
1.2+18-0net/dnscap/PLIST
1.7+4-5net/dnscap/distinfo
1.3+1-1net/dnscap/patches/patch-Makefile.in
+40-104 files

NetBSD/pkgsrc lYSb7GE — doc CHANGES-2026

   p5-DBD-mysql4 addition, ess update
VersionDeltaFile
1.6790+3-1doc/CHANGES-2026
+3-11 files

NetBSD/pkgsrc GqRugsT — math/ess distinfo Makefile, math/ess/patches patch-lisp_ess-site.el patch-test_ess-test.el

   ess: update to 26.05.0

   14 years worth of updates.
VersionDeltaFile
1.10+24-79math/ess/PLIST
1.1+42-0math/ess/patches/patch-doc_installation.texi
1.40+16-15math/ess/Makefile
1.9+14-6math/ess/distinfo
1.1+17-0math/ess/patches/patch-test_ess-test.el
1.1+15-0math/ess/patches/patch-lisp_ess-site.el
+128-1003 files not shown
+145-1029 files

NetBSD/pkgsrc WZE81vU — devel/rt5 options.mk

   rt5: add a mariadb option
VersionDeltaFile
1.2+5-2devel/rt5/options.mk
+5-21 files

NetBSD/pkgsrc J49SvJr — databases Makefile, databases/p5-DBD-mysql4 distinfo DESCR

   p5-DBD-mysql4: re-add version 4.050nb8 here

   as p5-DBD-mysql>=5 only supports mysql>=8 and not MariaDB.
VersionDeltaFile
1.1+26-0databases/p5-DBD-mysql4/Makefile
1.1+15-0databases/p5-DBD-mysql4/DESCR
1.1+5-0databases/p5-DBD-mysql4/distinfo
1.758+2-1databases/Makefile
+48-14 files

NetBSD/pkgsrc lfm6ZN6 — www/mailman3-web distinfo Makefile, www/mailman3-web/patches patch-pyproject.toml

   mailman3-web: bump the highest version of django claimed to be supported.
VersionDeltaFile
1.1+16-0www/mailman3-web/patches/patch-pyproject.toml
1.12+2-2www/mailman3-web/Makefile
1.6+2-1www/mailman3-web/distinfo
+20-33 files

NetBSD/pkgsrc ku1uwEG — www/py-hyperkitty distinfo Makefile, www/py-hyperkitty/patches patch-pyproject.toml patch-hyperkitty_forms.py

   py-hyperkitty: bump the highest version of django claimed to be supported.
   also fix issue with tag widget rendering properly with Django 5.2
VersionDeltaFile
1.1+34-0www/py-hyperkitty/patches/patch-hyperkitty_forms.py
1.1+16-0www/py-hyperkitty/patches/patch-pyproject.toml
1.5+3-1www/py-hyperkitty/distinfo
1.12+3-1www/py-hyperkitty/Makefile
+56-24 files

NetBSD/pkgsrc EOGPVZm — www/py-postorius distinfo Makefile, www/py-postorius/patches patch-pyproject.toml

   py-postorius: bump the highest version of django claimed to be supported.
VersionDeltaFile
1.1+16-0www/py-postorius/patches/patch-pyproject.toml
1.9+2-2www/py-postorius/Makefile
1.5+2-1www/py-postorius/distinfo
+20-33 files

NetBSD/pkgsrc zcz6hGr — www/tinyproxy/files tinyproxy.sh

   tinyproxy: have rc.d script create /var/run/tinyproxy if missing

   Have the example tinyproxy rc.d script in files/tinyproxy.sh create
   the pid directory (@VARBASE@/run/tinyproxy) if it is not present
   using start_precmd (e.g. as is done in /etc/rc.d/mdnsd).  Needed
   for cases where we reboot and /etc/rc.d/clearcritlocal deletes
   the old pid directory from /var/run.
VersionDeltaFile
1.5+10-1www/tinyproxy/files/tinyproxy.sh
+10-11 files

NetBSD/pkgsrc r2GZW7V — www/py-django-mailman3 distinfo Makefile, www/py-django-mailman3/patches patch-pyproject.toml

   py-django-mailman3: bump the highest version of django claimed to be supported.
VersionDeltaFile
1.1+16-0www/py-django-mailman3/patches/patch-pyproject.toml
1.8+2-2www/py-django-mailman3/Makefile
1.5+2-1www/py-django-mailman3/distinfo
+20-33 files

NetBSD/pkgsrc afMiJE8 — doc CHANGES-2026

   Updated security/flawfinder, devel/py-mocket
VersionDeltaFile
1.6789+3-1doc/CHANGES-2026
+3-11 files

NetBSD/pkgsrc jcGho2n — devel/py-mocket Makefile distinfo

   py-mocket: updated to 3.14.5

   3.14.5

   Pinning right version for typing-extensions
   Preserve encoded query parameters in recorded requests
VersionDeltaFile
1.21+4-4devel/py-mocket/distinfo
1.21+2-2devel/py-mocket/Makefile
+6-62 files

NetBSD/pkgsrc xsNUWnz — security/flawfinder distinfo Makefile

   flawfinder: updated to 2.0.20

   2.0.20
     Fix unlikely vulnerabilities (involving malicious filenames/text
     in analyzed systems) and implement various improvements
   * Fix security vulnerabilities found by Gemini:
     - Terminal injection in standard output: apply strip_controls() to
       level and category in show().
     - Terminal injection in CSV output: apply strip_controls() to all
       untrusted fields in show_csv() (category, name, warning,
       suggestion, note, context_text).
     - XML injection in SonarQube output: use quoteattr() for all XML
       attributes in output_sonar().
     - Defense-in-depth: restrict setattr in Hit.__init__ to an allowlist
       of known keys used by rule definitions, countering pickle attacks.
       We previously warned to not load untrusted pickle files, but
       completely preventing attacks is better.
     - Shell injection in CI/CD file entrypoint.sh:
       quoted args with "$@" and moved output filename to

    [86 lines not shown]
VersionDeltaFile
1.3+8-7security/flawfinder/PLIST
1.32+7-6security/flawfinder/Makefile
1.13+4-4security/flawfinder/distinfo
+19-173 files

NetBSD/pkgsrc jn6dMho — doc CHANGES-2026

   Updated devel/py-click-repl, devel/py-cachetools
VersionDeltaFile
1.6788+3-1doc/CHANGES-2026
+3-11 files

NetBSD/pkgsrc FMfLUCQ — devel/py-cachetools Makefile distinfo

   py-cachetools: updated to 7.2.1

   v7.2.1 (2026-10-05)

   - Improve error handling for ``RRCache.popitem()`` when the cache is
     empty.
   - Minor style and documentation improvements.
   - Update CI environment.


   v7.2.0 (2026-09-16)

   - Deprecate use of ``cache=None`` to suppress caching with the
     ``@cached`` decorator.
   - Add support for Python 3.15.
   - Minor test improvements.
   - Minor documentation updates.
VersionDeltaFile
1.41+4-4devel/py-cachetools/distinfo
1.42+3-3devel/py-cachetools/Makefile
+7-72 files

NetBSD/pkgsrc kraErYm — devel/py-click-repl Makefile distinfo

   py-click-repl: updated to 0.4.1

   0.4.1
   Guard click-repl import when stdin is unavailable
VersionDeltaFile
1.7+4-4devel/py-click-repl/distinfo
1.7+2-2devel/py-click-repl/Makefile
+6-62 files

NetBSD/pkgsrc kqOVCQC — doc CHANGES-2026

   Updated devel/py-rpds-py, sysutils/py-borgmatic
VersionDeltaFile
1.6787+3-1doc/CHANGES-2026
+3-11 files

NetBSD/pkgsrc gnQFWT0 — sysutils/py-borgmatic Makefile distinfo

   py-borgmatic: updated to 2.1.10

   2.1.10
   Unknown changes
VersionDeltaFile
1.3+10-1sysutils/py-borgmatic/PLIST
1.3+4-4sysutils/py-borgmatic/distinfo
1.3+3-3sysutils/py-borgmatic/Makefile
+17-83 files

NetBSD/pkgsrc G94yBCx — devel/py-rpds-py Makefile cargo-depends.mk

   py-rpds-py: updated to 2026.9.1

   2026.9.1
   Unknown changed
VersionDeltaFile
1.29+25-25devel/py-rpds-py/distinfo
1.20+7-7devel/py-rpds-py/cargo-depends.mk
1.32+2-2devel/py-rpds-py/Makefile
+34-343 files

NetBSD/pkgsrc 4yP0SxO — www/firefox128 distinfo Makefile, www/firefox128/patches patch-gfx_wr_webrender_src_texture__cache.rs

   Fix build of firefox128 with latest rust

   (Based on changed in firefox140)

   Approved by ryo
VersionDeltaFile
1.1+29-0www/firefox128/patches/patch-gfx_wr_webrender_src_texture__cache.rs
1.41+2-2www/firefox128/Makefile
1.23+2-1www/firefox128/distinfo
+33-33 files

NetBSD/pkgsrc OvYuVdd — doc CHANGES-2026

   Updated www/py-jwcrypto, www/py-uvicorn, net/py-scp
VersionDeltaFile
1.6786+4-1doc/CHANGES-2026
+4-11 files

NetBSD/pkgsrc jM8pklC — net/py-scp Makefile distinfo

   py-scp: updated to 0.16.2

   0.16.2 (2026-10-06)

   - Catch `EOFError` from `channel.close()` that happens sporadically on some devices
   - Check erroneous server path on download
VersionDeltaFile
1.18+4-4net/py-scp/distinfo
1.23+3-3net/py-scp/Makefile
+7-72 files

NetBSD/pkgsrc Wzsl1Pq — www/py-uvicorn Makefile distinfo

   py-uvicorn: updated to 0.54.0

   0.54.0

   Send metadata after the response body

   uvicorn 0.54.0 adds response trailers and 103 Early Hints to its experimental HTTP/2 implementation through zttp.

   uv add uvicorn==0.54.0 "zttp>=0.0.34"
   Send HTTP/2 response trailers. The ASGI http.response.trailers extension lets applications send metadata, such as checksums, after the response body. Clients must send TE: trailers to receive them. Multiple trailer messages are combined before completing the response.
   HTTP/2 remains experimental and opt-in. Enable it with --http zttp --http2. Upgrade-based h2c and WebSockets over HTTP/2 remain unsupported.

   Hint at resources before the final response

   Send 103 Early Hints over HTTP/2. Applications can use the ASGI http.response.early_hint extension to send resource hints before the final response. Each supplied link becomes a separate Link header.
VersionDeltaFile
1.18+10-1www/py-uvicorn/PLIST
1.63+4-4www/py-uvicorn/distinfo
1.72+2-2www/py-uvicorn/Makefile
+16-73 files

NetBSD/pkgsrc fGmjihL — www/py-jwcrypto Makefile distinfo

   py-jwcrypto: updated to 1.6.1

   1.6.1

   This release fixes CVE-2026-92091, a low security issue that may result in a Denial of Service on malformed JWK keys
VersionDeltaFile
1.13+4-4www/py-jwcrypto/distinfo
1.17+2-2www/py-jwcrypto/Makefile
+6-62 files