www/nginx-devel: Update to 1.31.5
Changes with nginx 1.31.5 02 Sep
2026
*) Feature: control API.
*) Feature: predicate locations.
*) Feature: the ngx_http_json_module.
*) Feature: the "client_body_early_read" directive.
*) Bugfix: use-after-free might occur in a worker process if
proxying
with buffering was used and an error occurred while sending the
response to an HTTP/2 client.
*) Bugfix: a worker process might not exit or "accept4() failed (9:
[13 lines not shown]
www/{nginx,nginx-devel,freenginx}: 3rd-party modules management
Chase the www/nginx-module-njs update to 1.0.1, which contains
security fixes. Bump PORTREVISION so the packages pick up the new
module.
Sponsored by: Netzkommune GmbH
www/nginx-module-njs: Update to 1.0.1
This release contains security fixes: an access control bypass in
js_access when an asynchronous request body continuation threw an
exception, a worker process crash when reading Response.statusText, a
heap buffer overflow in XML exclusive canonicalization and a stack
buffer overflow when exporting large RSA keys to JWK in WebCrypto.
Upstream has not assigned CVE numbers.
Changes: https://nginx.org/en/docs/njs/changes.html
Sponsored by: Netzkommune GmbH
devel/libnjs: Update to 1.0.1
This release contains security fixes: a heap buffer overflow while
parsing namespace prefix lists in XML exclusive canonicalization and a
stack buffer overflow when exporting RSA keys larger than 4096 bits to
JWK in WebCrypto. Upstream has not assigned CVE numbers.
Changes: https://nginx.org/en/docs/njs/changes.html
Sponsored by: Netzkommune GmbH
lang/njs: Update to 1.0.1
This release contains security fixes: a heap buffer overflow while
parsing namespace prefix lists in XML exclusive canonicalization and a
stack buffer overflow when exporting RSA keys larger than 4096 bits to
JWK in WebCrypto. Upstream has not assigned CVE numbers.
Changes: https://nginx.org/en/docs/njs/changes.html
Sponsored by: Netzkommune GmbH
biology/py-macs2: Remove
MACS2 is dead upstream, with no plans to make it compatible with
cython 3.x or other newer dependencies. Though the port was
set to expire in another month, I'm removing it now to stop wasting
package building resources. It has not been buildable for some time.
(cherry picked from commit 08256be5a8582d2a23383495dc6a1ab477da3f97)