libpkg: Add CVE name parsing to OSVf parser
Add CVE names parsing to OSVf parser. As there
is no CVE name in OSVf schema. CVE names are extending
database_specific-object. Usage example JSON would be:
...
"database_specific": {
"references": {
"cvename": [
"CVE-2003-0031",
"CVE-2003-0032"
]
}
}
...
tests: Add CVEs to example OSVf JSON
Add CVSs to example OSVf JSON. Currently
they are only for parsing and there is no
further testing are they correct
fix: Update tests to support new updated OSVf Schema
In official OSVf Schema FreeBSD Ecosystem is not FBSD
but FreeBSD. Update correction to test json file and to library
test file.
refactor: Add SPDX license identifier tags to files
Add SPDX license identifier tags to files that are licensed under the
LicenseRef-scancode-bsd-unchanged license
refactor: Add identifier tags to files that are licensed under the MIT
Add SPDX license identifier tags to files that are licensed under the
MIT license
refactor: Add identifier tags to files that are licensed under the ISC
Add SPDX license identifier tags to files that are licensed under the
ISC license
refactor: Add identifier tags to files that are licensed under the BSD-2-Clause
Add SPDX license identifier tags to files that are licensed under the
BSD-2-Clause license.
refactor: Add identifier tags to files that are licensed under the BSD-3-Clause
Add SPDX license identifier tags to files that are licensed under the
BSD-3-Clause license
[libc++][NFC] Simplify duration comparisons a bit (#201788)
The comparisons have been delegated to a class which has been
specialized for the equality case. This has likely been done to avoid
`common_type` if possible. However, `common_type` got a lot cheaper, to
the point where the classes likely do more harm than good.
go: update to 1.26.4 and 1.25.11 (security).
These releases include 3 security fixes following the security policy:
- mime: quadratic complexity in WordDecoder.DecodeHeader
Decoding a maliciously-crafted MIME header containing many invalid
encoded-words could consume excessive CPU.
The MIME decoder now better handles this case.
Thanks to p4p3r (https://hackerone.com/p4p3r_hak) for reporting this issue.
This is CVE-2026-42504 and Go issue https://go.dev/issue/79217.
- net/textproto: arbitrary input are included in errors without any escaping
When returning errors, functions in the net/textproto package would
include its input as part of the error, without any escaping. Note that
said input is often controlled by external parties when using this
[26 lines not shown]
textproc/xan: update to 0.58.0
Breaking
Stopping to serialize moonblade lists either as joined by some separator or JSON. This was awkard, error-prone & potentially lossy. Use the join function manually to format output when required.
As per previous point, dropping xan scrape --sep.
Dropping implicit unary function calls in moonblade pipelines. This feature was not well-known, confusing (an indentifier, could be understood as a call in a pipeline, only if not in first position...), and mostly useless now that moonblade has had a proper dot operator.
xan plot -A/--aggregate does not take an expression anymore but has an automatic selection of two modes: sum and mean. It should also be faster.
Renaming the index function as row_index for clarity.
xan agg -C/--along-columns & -M/--along-matrix & xan groupby -C/--along-columns & -M/--along-matrix will not map current column index to the result of the index() function. The col_index() can be now used instead for this very purpose.
xan window -g/--groupby does not require the file to be sorted anymore. This means using -g/--groupby will now require the whole file to be buffered into memory by the command. The old behavior can still be used through the -S/--sorted flag, thus aligning the xan window command with the rest of the tool.
row_index will now error if the expression has no concept of row index, instead of returning nothing.
xan parallel -z/--compress now take the desired compression (either gzip or zstd).
Retiring the xan grep command in favor of xan search -Z/--fast-parser.
xan tokenize --keep short flag becomes -k instead of -K to harmonize with other commands.
Retiring the xan flatmap command in favor of xan explode -e.
Retiring the xan fuzzy-join command in favor of a consolidated xan join command.
Changing xan from -f txt -c <name> default to line instead of value.
Renaming xan join -L/--prefix-left & -R/--prefix-right short flags to -l & -r respectively to avoid colliding with the added -R/--reverse flag that can be used for merge joins.
[70 lines not shown]
chat/senpai: update to 0.5.0
This large senpai release brings 1 year of features
and bug fixes!
Major features:
- Take a /SCREENSHOT from senpai, uploading it to
your bouncer
- Do an /UPLOAD from your clipboard by pasting an
image with Ctrl+Alt+V
- Customize your keyboard shortcuts with the shortcuts
config directive, see man 5 senpai for details
- Enable lightweight spell-check from your config,
using harper-ls if installed
- Pin/mute channels and users (ignore coming soon),
saved across your bouncer
Minor features:
- irc:// links are now properly handled everywhere!
[77 lines not shown]
audio/ncspot: update to 1.3.4
Maintenance release
Minor updates, including a crash fix when a user tries to add a song to an existing playlist and dependency updates.
What's Changed
Fix crash when adding a song to a playlist by @AnAngryRaven in #1783
chore(toolchain): update by @hrkfdn in #1785
chore(deps): bump the cargo group across 1 directory with 11 updates by @dependabot[bot] in #1787
test: add queue unit tests, fix shuffle append bug by @hrkfdn in #1788
chore(deps): bump chrono from 0.4.43 to 0.4.44 in the cargo group by @dependabot[bot] in #1791
chore(deps): bump the cargo group with 3 updates by @dependabot[bot] in #1792
chore(deps): bump quinn-proto from 0.11.13 to 0.11.14 by @dependabot[bot] in #1794
chore(toolchain): update by @hrkfdn in #1796
chore(deps): bump the cargo group with 3 updates by @dependabot[bot] in #1797
chore(deps): bump rustls-webpki from 0.103.8 to 0.103.10 by @dependabot[bot] in #1798
chore(deps): bump softprops/action-gh-release from 2 to 3 in the github-actions group by @dependabot[bot] in #1807
chore(deps): bump rand from 0.10.0 to 0.10.1 by @dependabot[bot] in #1809
[7 lines not shown]
devel/garden: update to 2.6.0
v2.6.0 Released 2026-03-14
Features:
garden <custom-cmd> now has a -x | --echo option that enables the shell's
native echo mode.
Packaging:
Prebuilt binaries for Apple Darwin aarch64
are now available.
Garden can now be installed directly via
Homebrew on macOS.
The garden-rs/homebrew-garden tap repository has been archived and is no
longer maintained.