780,082 commits found in 43 milliseconds
net/keycloak: Update 26.6.3 => 26.6.4 (8 CVEs)
Release Notes:
https://www.keycloak.org/2026/06/keycloak-2664-released
PR: 296367
Security: CVE-2026-9099
Security: CVE-2026-9083
Security: CVE-2026-9086
Security: CVE-2026-9705
Security: CVE-2026-9795
Security: CVE-2026-9799
Security: CVE-2026-9800
Security: CVE-2026-11800
Sponsored by: UNIS Labs
MFH: 2026Q2
(cherry picked from commit e9dd3d7873620832266a43b81635d2391d6668ed )
net/keycloak: Update 26.6.3 => 26.6.4 (8 CVEs)
Release Notes:
https://www.keycloak.org/2026/06/keycloak-2664-released
PR: 296367
Security: CVE-2026-9099
Security: CVE-2026-9083
Security: CVE-2026-9086
Security: CVE-2026-9705
Security: CVE-2026-9795
Security: CVE-2026-9799
Security: CVE-2026-9800
Security: CVE-2026-11800
Sponsored by: UNIS Labs
MFH: 2026Q2
filesystems/py-libzfs: v2.0.1
This fixes a bug with the ZFSVdev.Replace method.
https://github.com/asomers/py-libzfs/releases/tag/v2.0.1
Sponsored by: ConnectWise
www/tor-browser: Unbreak build
The issue appears to be cbindgen 0.29.4:
https://github.com/mozilla/cbindgen/issues/1165
https://bugzilla.mozilla.org/show_bug.cgi?id=2046162
Obtained from: Martin Filla
PR: 296327
FreeBSD /ports d065826 — databases/rrdtool Makefile, databases/rrdtool/files patch-src_rrd__open.c databases/rrdtool: Fix rrdtool resize on zfs FreeBSD 15
It appears that `posix_fallocate` in FreeBSD 15 now returns `EOPNOTSUPP`
instead of `EINVAL`.
See also:
https://lists.libvirt.org/archives/list/devel@lists.libvirt.org/thread/QZXFLC6E47UDM65GZAFDBZ2DJKIDT7N2/?sort=date
https://github.com/mariadb-corporation/galera/issues/685
PR: 296381
security/stunnel: Update to 5.79
x11/xbitmaps: Update to 1.1.4
Since xbitmaps is arch independent, install .pc file to share/pkgconfig.
https://lists.x.org/archives/xorg-announce/2026-April/003693.html
PR: 296365
Approved by: x11 (arrowd)
Approved by: osa (mentor)
mail/mpop: Update to 1.4.22
Make TLS mandatory.
https://marlam.de/mpop/news/mpop-1-4-22/
PR: 296335
Approved by: osa (mentor)
dns/nsd: Security update 4.14.2 => 4.14.3
Changelog:
https://community.nlnetlabs.nl/t/nsd-4-14-3-security-release/3419
PR: 296375
Approved by: osa, vvd (Mentors, implicit)
MFH: 2026Q2
Security: CVE-2026-12244
Security: CVE-2026-12245
Security: CVE-2026-12246
Security: CVE-2026-12490
(cherry picked from commit 23f1898dd1d8c89b09a6f53108873b8dbedeca3e )
dns/nsd: Security update 4.14.2 => 4.14.3
Changelog:
https://community.nlnetlabs.nl/t/nsd-4-14-3-security-release/3419
PR: 296375
Approved by: osa, vvd (Mentors, implicit)
MFH: 2026Q2
Security: CVE-2026-12244
Security: CVE-2026-12245
Security: CVE-2026-12246
Security: CVE-2026-12490
security/vuxml: Document dns/nsd vulnerabilities
PR: 296375
Approved by: osa, vvd (Mentors, implicit)
misc/py-sagemaker-serve: update 1.14.0 → 1.15.0
devel/cargo-tarpaulin: update 0.35.5 → 0.36.0
math/py-pandas-stubs: New port: Type annotations for pandas
misc/py-sagemaker: update 3.14.0 → 3.15.0
misc/py-sagemaker-train: update 1.14.0 → 1.15.0
sysutils/opa: update 1.18.0 → 1.18.1
shells/starship: update 1.25.1 → 1.26.0
misc/py-sagemaker-mlops: update 1.14.0 → 1.15.0
net/wstunnel: update 10.6.0 → 10.6.1
devel/py-types-pytz: New port: Typing stubs for pytz
misc/py-sagemaker-core: update 2.14.0 → 2.15.0
shells/meka: update 0.29.1 → 0.29.2
misc/py-tritonclient: New port: Python client library and utilities for Triton Inference Server
misc/py-sagemaker-mlflow: New port: SageMaker: AWS Plugin for MLflow with SageMaker
www/qt5-webengine: Schedule for removal before 2026Q4
Qt 5 support is officially over. The Qt5WebEngine is based on very old
Chromium missing numerous security fixes. Using it for web is highly
discouraging.
devel/qt6-tools: Backport upstream patch to support LLVM 22
PR: 295535
www/{pomerium-envoy-custom,pomerium}: update to 1.36.8-p1 / 0.32.9
security/vuxml: Document net/rclone vulnerability
PR: 296192
Approved by: osa, vvd (Mentors, implicit)
net/rclone: Security update 1.74.2 => 1.74.3
Changelog:
https://rclone.org/changelog/#v1-74-3-2026-06-05
PR: 296192
Reported by: Herbert J. Skuhra <herbert at gojira.at>
Approved by: Ralf van der Enden <tremere at cainites.net> (maintainer)
Approved by: osa, vvd (Mentors, implicit)
Tested by: Vladimir Druzenko <vvd at FreeBSD.org>
MFH: 2026Q2
Security: CVE-2026-49980
(cherry picked from commit 6064d1dd6addbc89d9ac2c6c5df7494b6c7f6cee )