nodejs: updated to 26.11.1
26.11.1 (Current)
- Revert "build: toggle doc-kit verbosity based on V" (Antoine du Hamel)
- Revert "build, doc: move to redesign" (Antoine du Hamel)
- Revert "tools: bump the doc group in /tools/doc with 4 updates" (Antoine du Hamel)
cargo-nextest: updated to 0.9.148
0.9.148
Changed
For setup scripts, slow-timeout no longer accepts on-timeout = "pass", and nextest now reports a configuration error if it is specified. A setup script that times out always fails the run. Previously, this setting was accepted but handled inconsistently: the timed-out script was counted as a failure, but the run was not cancelled.
Internal dependency updates: guppy updated to 0.19.1, and target-spec updated to 3.7.0, updating built-in targets to Rust 1.98.
Fixed
Stress runs now exit with a non-zero code if any iteration failed. Previously, with fail-fast disabled, the exit code reflected only the last iteration, so a stress run with failures in earlier iterations exited with code 0 if the last iteration passed.
Stress runs now always run at least one iteration. Previously, --stress-duration with a very short duration (such as 1ns) could finish without running any tests.
Runs stopped by immediate fail-fast (--max-fail N:immediate) are now treated as failed rather than cancelled. Previously, in stress runs, the summary read 0 passed; cancelled due to test failure and the failing iteration was not counted as failed.
When the global timeout fires with immediate fail-fast enabled, nextest now reports the global timeout as the reason the run was cancelled. Previously, the tests terminated by the timeout counted as failures, so nextest printed a second Cancelling due to test failure line and reported a test failure as the reason.
[11 lines not shown]
net/dnscap: Update dnscap from version 1.4.1 (from 2015) to 2.5.1
Prompted by jperkin's MacOS 27 bulk build results
10+ years of changes are too many to summarise here, but TL;DR is that
+ there are a lot more dependencies (on a lot of archivers/compression
libraries), openssl, and ldns,
+ the package name in pkgsrc is now dnscap2,
+ and dnscap now supports plugins (${PREFIX}/bin/dnscap-rssm-rssac002
is one such).
tinyproxy: have rc.d script create /var/run/tinyproxy if missing
Have the example tinyproxy rc.d script in files/tinyproxy.sh create
the pid directory (@VARBASE@/run/tinyproxy) if it is not present
using start_precmd (e.g. as is done in /etc/rc.d/mdnsd). Needed
for cases where we reboot and /etc/rc.d/clearcritlocal deletes
the old pid directory from /var/run.
flawfinder: updated to 2.0.20
2.0.20
Fix unlikely vulnerabilities (involving malicious filenames/text
in analyzed systems) and implement various improvements
* Fix security vulnerabilities found by Gemini:
- Terminal injection in standard output: apply strip_controls() to
level and category in show().
- Terminal injection in CSV output: apply strip_controls() to all
untrusted fields in show_csv() (category, name, warning,
suggestion, note, context_text).
- XML injection in SonarQube output: use quoteattr() for all XML
attributes in output_sonar().
- Defense-in-depth: restrict setattr in Hit.__init__ to an allowlist
of known keys used by rule definitions, countering pickle attacks.
We previously warned to not load untrusted pickle files, but
completely preventing attacks is better.
- Shell injection in CI/CD file entrypoint.sh:
quoted args with "$@" and moved output filename to
[86 lines not shown]
py-cachetools: updated to 7.2.1
v7.2.1 (2026-10-05)
- Improve error handling for ``RRCache.popitem()`` when the cache is
empty.
- Minor style and documentation improvements.
- Update CI environment.
v7.2.0 (2026-09-16)
- Deprecate use of ``cache=None`` to suppress caching with the
``@cached`` decorator.
- Add support for Python 3.15.
- Minor test improvements.
- Minor documentation updates.
py-scp: updated to 0.16.2
0.16.2 (2026-10-06)
- Catch `EOFError` from `channel.close()` that happens sporadically on some devices
- Check erroneous server path on download
py-uvicorn: updated to 0.54.0
0.54.0
Send metadata after the response body
uvicorn 0.54.0 adds response trailers and 103 Early Hints to its experimental HTTP/2 implementation through zttp.
uv add uvicorn==0.54.0 "zttp>=0.0.34"
Send HTTP/2 response trailers. The ASGI http.response.trailers extension lets applications send metadata, such as checksums, after the response body. Clients must send TE: trailers to receive them. Multiple trailer messages are combined before completing the response.
HTTP/2 remains experimental and opt-in. Enable it with --http zttp --http2. Upgrade-based h2c and WebSockets over HTTP/2 remain unsupported.
Hint at resources before the final response
Send 103 Early Hints over HTTP/2. Applications can use the ASGI http.response.early_hint extension to send resource hints before the final response. Each supplied link becomes a separate Link header.
py-jwcrypto: updated to 1.6.1
1.6.1
This release fixes CVE-2026-92091, a low security issue that may result in a Denial of Service on malformed JWK keys