sysutils/broot: update to 1.60.2
v1.60.2
- fix some combinations being wrongly interpreted for input on some terminals (eg shift-r with kitty keyboard protocol enabled on ghostty/mac was interpreted as just a 'r')
- preview of CRLF (Windows style) text files no longer shows a replacement char at the end of every line - Fix #1216
- :copy_line no longer copies the end of line characters
- PSD images are no longer previewed
- content search no longer reports false matches in .bz2, .xz, .zst and .br files
- nerdfont icons for TOML and YAML files - Thanks @noahkawaguchi
v1.60.1
- the official macOS binary now includes the clipboard feature (:copy_path, :copy_line, :input_paste)
- a verb redefined with the name of an existing one no longer makes typing a prefix of that name ambiguous
- on macOS, the trash listing verbs (:open_trash, etc.) are no longer offered, as they couldn't work there
- paths containing shell special characters (globs, $, parentheses, etc.) are now quoted in commands executed by the shell function - Fix #595
- the terminal title no longer shows paths quoted
- fix double-click not opening the file when the tree is scrolled - Fix #150
- git statuses are no longer missing in subdirectories when broot is launched from a subdirectory of the repository
- the diff preview is shown for a modified file given as launch argument
[2 lines not shown]
shells/oh-my-posh: update to 31.4.0
Bug Fixes
- config: honor segment cache while streaming (1ff660a), closes #7882
- git: bare repo .Upstream holds raw remote list, not the tracking branch (9fa688e), closes #7799
- pwsh: count wrapped rows for ExtraPromptLineCount (2b37f96), closes #7881
- segments: coerce non-string key/value option values instead of panicking (4013b4a)
- strava: show the skiing icon for nordic and alpine skis (a8f56ab)
- template: trust markup in var values and cross-segment text (36a80f6), closes #7858
Features
- agents: add stop hooks for CI quality checks (1a3d860)
png: update to 1.6.59.
Version 1.6.59 [September 28, 2026]
Fixed CVE-2026-46675 (medium severity):
Use-after-free of zlib input in `png_read_end` after incomplete zTXt, iTXt
or iCCP decompression.
(Reported independently by Ze Sheng and
<JasonHonKL at users.noreply.github.com>.)
Fixed a regression introduced in version 1.6.47 that caused libpng to reject
hIST chunks in their correct position, after PLTE.
(Contributed by Yuki Sekiguchi.)
Prevented a double free of `png_struct` members after an allocation failure.
(Contributed by Anthony Hurtado.)
Applied fixes and updates to the CMake build.
Adopted the REUSE Specification for licensing the CI files.
pcre2: update to 10.49.
Version 10.49 28-September-2026
-------------------------------
1. (GHSA-r9hj-j2rw-4q3m) Security fix to prevent an out-of-bounds write with
arbitrary data. Applications are only affected if using the
pcre2_jit_stack_create() and pcre2_jit_stack_assign() APIs to provide a growable
JIT stack, and then matching against a pattern with unusually high JIT stack
usage, such as a large number of capturing groups.
The implications of an out-of-bounds write could include arbitrary code
execution.
The issue is not a regression and affects releases 10.48 and earlier.
ccache.mk: Mark gmake as circular
ccache3 has used gmake to build for a very long time, but it was not
marked as a circular dependency. Resolves build failure under bob
when PKGSRC_COMPILER has ccache.
net/py-suds: Add py-suds version 1.2.0
Suds is a lightweight SOAP-based web service client for Python
licensed under LGPL.
Although the original `suds` package stopped releasing versions after
`0.4`, many (but not all) other open source projects moved to a
maintained fork known as "suds-jurko". This is a community fork of
that fork that is releasing packages under the main `suds` package
name (and `suds-community` for consistency until version 2.x of this
package).
py-urwid: update to 4.1.7.
4.1.7
Make Text's line translation cache safe for concurrent readers by @penguinolog in #1338
4.1.6
New features 🗹
Implement synchronised output by @penguinolog in #1333
Bug fixes 🕷
Preserve focus when deleting negative-step slices by @jakezwang in #1329
Documentation 🕮
Fix screenshot generation and re-generate screenshots by @penguinolog in #1326
[5 lines not shown]
py-soupsieve: update to 2.10.
NEW: Support Python 3.15.
NEW: Add new ignore option to API methods that allows the specification of specific pseudo-classes to be
ignored.
NEW: Tighten restrictions such that namespaces and custom objects must always be a Mapping, previously lists
of tuples were also allowed.
NEW: Use a singleton for null selectors internally via called Null of type SelectorNull.
NEW: For performance, Soup Sieve will no longer try and coerce bad attribute values to useable strings.
NEW: Add NOCACHE flag that can be used to disable caching optimizations selectors and possibly other future
caching optimizations. Provided for disabling and also disabling if issues are found with the new caching approach.
FIX: Improve performance of ~ for various cases by employing caching.
FIX: Improve performance of nth-* family of selectors in certain scenarios by employing caching.
FIX: Ensure custom is properly passed down from API functions to compilation.